Manage assets with Asset Inventory

Rollout of this feature is underway across our platform. It will be broadly available by September 10th.

Akamai’s Asset Inventory provides a centralized dashboard that brings together all your hostnames and APIs, offering a clear view of your assets and their protection coverage.

Asset Inventory serves as a single source of truth for your assets, enabling you to:

  • View all assets in one place to quickly identify security gaps.
  • Use insights from Security Center to understand protection coverage and asset priority, helping you assess and prioritize your remediation efforts.
  • Identify unprotected assets that need protections, so you can address security gaps and achieve full coverage.
  • Quickly add asset protections for assets that are not protected under a security configuration.

Access Asset Inventory

You can access Asset Inventory in two ways:

From Security Center:

  1. Log in to Akamai Control Center.
  2. From the Control Center menu, click Security > Security analytics > Security Center.
  3. From the Security Center menu, click Tools > Asset Inventory.

From Security Hub:

  1. Log in to Akamai Control Center.
  2. From the Control Center menu, click Security > Security analytics > Security Hub.
  3. From the Security Hub menu, click Your Assets.

When you open Asset Inventory, you’ll see a dashboard summarizing key information about your assets, including the number of discovered, unprotected, and partially protected assets.

Click on an asset from the list to view details including protection status and recommended actions to improve security. The next section explains how to use Asset Inventory’s filter options to refine your asset list.

Filter your assets

Asset Inventory lets you filter assets by asset type, protection coverage, priority, security configuration, and OWASP API risk tag.

Pre-defined filters allow you to filter by:

  • Non-hidden assets. Assets that are visible in Asset Inventory. Assets are non-hidden unless explicitly hidden by a user.
  • Critical and high priority assets. Assets with critical or high investigation priority, which is determined by multiple factors, including, but not limited to, an asset’s sensitivity and protection coverage.
  • Hidden assets. Assets that have been explicitly hidden from the Asset Inventory view.
  • Discovered assets. Hostname and/or API assets that have not set up baseline security protections and need protections applied.
  • Shadow APIs. Undocumented or unmanaged API assets that operate outside of formal security insight.

Filter assets by type

You can filter by asset type:

  • All types. Both API and hostname assets.
  • API. API assets only.
  • Hostname. Hostname assets only.

Filter assets by priority

Assets are assigned priority levels based on sensitivity and protection coverage:

  • Low. Largely protected assets; minimal attention needed.
  • Medium. Partially protected assets; improvements recommended.
  • High. Sensitive assets with minimal or no protection; should be protected promptly.
  • Critical. Highly sensitive asset with minimal protection; immediate action required.

Filter assets by protection level

Assets can have one of three protection coverage levels:

  • Not protected. No protection; likely newly discovered and needs to be set up with baseline protections.
  • Partially protected. Some protections in place; recommended actions for improved protection available.
  • Protected. Sufficiently protected; no recommended actions.

Filter assets by security configuration

To filter assets by security configuration:

  1. Click the All security configurations dropdown (default value).
  2. Enter the name(s) of the desired security configuration(s).
  3. Select configurations to filter results. You can filter by all configurations (default) or assets not assigned to a configuration.

Filter assets by OWASP top 10 risks

🚧

Indicators for OWASP API security risks will only appear for APIs that are provided through integration with API Security.

OWASP’s top 10 API security risks highlight common API vulnerabilities and help security teams identify and address threats. In Asset Inventory, you can filter by OWASP top 10 API tags, which are available through integration with API Security.

If API Security detects a vulnerability that matches a supported OWASP compliance framework, the affected asset will display a tag indicating the relevant OWASP top 10 API security risk. For guidance on preventing and mitigating these risks, refer to the related OWASP top 10 documentation.

Manage at-risk assets

To manage assets, click an asset in the list view. A window expands with details on the asset’s protection status. If the asset is at-risk, you’ll see recommended actions to improve its security.

Bulk actions

You can select multiple assets and manage them in bulk. Supported actions depend on the selected assets and include:

  • Hide. Change selected assets from visible (non-hidden) to hidden. This action hides selected assets from Asset Inventory.
  • Unhide. Change selected assets from hidden to visible (non-hidden). This action makes selected assets visible within Asset Inventory.

Did this page help you?