Connect your CMDB and Asset Inventory
You cannot secure or scope what you have not inventoried. TruSecure's CMDB connector pulls asset registers, service criticality and ownership, so applicability questions — including NIS2 entity scope — are answered from the inventory, not from memory.
What the connector pulls
| Source system | What TruSecure pulls | Feeds governance |
|---|---|---|
| Asset register | Servers, network gear, services, SaaS, data stores | Obligation Intelligence · NIS2 applicability |
| Service criticality | Business-impact ratings, dependency mappings | Risk Management · criticality-weighted risk |
| Ownership | System owners, business owners, support groups | Governance workspace · named accountability |
| Lifecycle state | In production, deprecated, decommissioning | Evidence Automation · scope hygiene |
Evidence produced from CMDB and Asset Inventory data
One control test pulled from live CMDB and Asset Inventory state — not a manual export, not a screenshot, but a verified query result with provenance:
- Control tested
- Every production asset has a named system owner
- Inventory source
- CMDB · 2,314 CIs in production state
- Test
- re-perform · CI records vs ownership field
- Sample
- 2,305 owned · 9 with empty owner, 4 stale >180 days
- Result
- fail · 9 unowned CIs escalated to service owners
- Evidence
- CMDB API query · timestamped 2026-08-22T07:19:38Z
- Export
- sealed · sha256:8a4e...2d6c
Setup and scope model
- Read-only, scoped permission
Connector requires read-only access to CI records, relationships, and attributes. No write permissions, no ability to create, merge, or retire configuration items.
- Data filtered by entity
CIs scoped to the entity context. A shared service catalogue across group companies keeps each entity's applicability calculation on its own assets.
- Continuous sync
Applicability recomputes as the inventory changes — a new critical service appears in scope the day the CMDB records it.
Commercial packaging
CMDB and Asset Inventory connectors are part of the paid TruSecure Fabric subscription. The connector itself, the continuous sync, the evidence provenance tracking, and the mapping to NIS2, DORA, ISO 27001, SOC 2 and other frameworks are all included — no per-connector fees, no usage tiers. Pricing is scoped in the conversation, not a price list.
How integration works
A demo with your actual CMDB and Asset Inventory environment shown in preview mode — your data pulling into governance, feeding controls and evidence. Then a Resilience Sprint that configures the connector for production, scopes the entity context, and validates the first evidence pull. No self-serve checkout, no per-connector pricing.
TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.