IT Systems Inventory and Configuration Register

A free, client-brandable spreadsheet template created by KAOS Data.

Primary intent

This workbook make a practical documentation, discovery and handover register.

Target users

Individuals, small businesses, client support teams, consultants, and managed service providers.

Most organisations rely on a mixture of computers, servers, network devices, cloud services, applications, data stores, suppliers and administrative accounts. Over time, the information needed to support those systems can become scattered across emails, invoices, vendor portals, personal notes and individual memory.

That becomes a serious problem when something fails, a supplier changes, a staff member leaves, a new support provider takes over, an insurance or due-diligence question must be answered, or systems must be recovered or rebuilt after an incident.

What people forget is that all organisations, big and small, depend wholly on the operation and availability of their data. So, knowing how your systems are configured are vitally important to administer, support and maintain them.

The interconnectivity and interoperability and dependencies of the collections of systems and services may appear to be complex. The best place to start is to collect and centralise that information.

We are not suggesting that IT should be core to any business. The IT infrastructure, however is critical to support the business operation – regardless what the business or organisation does.

The KAOS Data IT Systems Inventory and Configuration Register gives you one structured place to record what exists, how it is configured, who is responsible, how it is accessed, how it is backed up, where supporting evidence is stored and what information is still missing.

DOWNLOAD THE FREE EXCEL TEMPLATE

REQUEST ENHANCEMENTS OR ASSISTANCE

What this register helps you achieve

  • Create a current inventory of systems, services, accounts and important data.
  • Reduce reliance on one person, supplier or support technician holding critical knowledge.
  • Make support and troubleshooting faster by recording ownership, access paths and configuration details.
  • Improve backup and recovery documentation by linking protection plans, recovery objectives and restore-test evidence.
  • Prepare a clearer handover when responsibilities, suppliers or support arrangements change.
  • Track missing information and follow-up actions instead of leaving gaps hidden in free-form notes.

Designed to be maintained and expanded

The workbook uses expandable Excel tables rather than fixed blocks for a predetermined number of servers, providers or accounts. Record one item per row, assign a stable ID and add new rows as the environment grows. Related IDs allow an asset, service, application, backup plan, identity, document and configuration record to be connected without repeating the same information everywhere.

A dashboard summarises register counts, missing ownership, unverified information, overdue reviews, restore-test gaps and whether passwords have been entered without confirmed file encryption.

Client branding with KAOS Data attribution

Enter the client or company name once on the Start Here sheet and it appears throughout the workbook. A client logo can also be displayed across the tabs using a direct HTTPS image link in supported Excel versions. The workbook includes instructions for using an embedded local logo with a linked-picture alternative where an online image is not suitable.

The top-right originator panel identifies KAOS Data and the template version. Please retain the “Original template by KAOS Data” attribution when adapting or redistributing the register. For customised fields, automation, integrations, additional registers or a fully automated local-logo implementation, Contact Us.

What the workbook can document

Client and company profile

Record the registered entity, trading or project name, client reference, organisation type, address, contacts, document ownership, classification, review dates and repository location. Australian identifiers include ABN and ACN fields, plus an optional TFN field and an expandable table for other company-specific information.

TFN caution

Record a Tax File Number only where it is genuinely required and authorised. Treat it as highly sensitive, restrict access and consider keeping it in a separate controlled record when it is not necessary for IT support.

 

Sites and locations

Document offices, homes, branches, data centres, cloud regions and important third-party locations, including ownership, contacts, operating hours, access restrictions and connectivity summaries.

Services and providers

Record internet, telephone, domains, DNS, website hosting, cloud platforms, software subscriptions, certificates, managed support and other external services. Capture provider details, account or tenant IDs, account-management URLs, user portals, administrator or support URLs, contract references, renewal dates, owners and primary login details. Additional website, registrar, hosting and vendor administration accounts can be linked through the Identity & Access register.

Email configuration and accounts

Use the dedicated Email sheet to record domains and providers, tenant or account IDs, IMAP or POP settings, SMTP servers, ports, encryption methods, authentication requirements, username formats, webmail and administration portals, support contacts and notes for MX, SPF, DKIM and DMARC.

A separate email-account table captures addresses, display names, account types, support or provider-account purposes, login IDs, optional passwords, password-manager references, MFA, recovery details, forwarding or delegates, owners, status and review dates.

Assets

Document physical and virtual servers, desktops, laptops, routers, firewalls, switches, wireless access points, NAS devices, storage, printers, UPS units, cloud resources and other important equipment. Capture management URLs, administrator usernames, optional passwords, password-manager references and whether vendor default credentials have been changed.

Applications and data

Record applications, databases, file shares, integrations, websites, platforms and important data sets, together with licensing, hosting, ownership, dependencies, recovery objectives, backup references and support information.

Networks

Document Network devices, LANs, VLANs, subnets, gateways, WAN links, VPNs, Wi-Fi, security zones, DNS, DHCP, related devices and optional Wi-Fi credentials. Use the configuration register for detailed firewall rules, routing, switch settings and system-specific parameters.

Backups and recovery

Record what is protected, the backup product and method, schedule, retention, destination, offsite and immutable copies, encryption, copy count, recovery point objective, recovery time objective, last successful backup, last restore test, evidence and accountable owner.

Identity and access

Maintain a scalable list of administrator, service, shared, vendor, support and website-management accounts. Record the related system, login URL, username, optional password or vault reference, privilege, MFA, owner, recovery method, review date and status.

Configuration details

Capture system-specific settings as flexible parameter-and-value records linked to the relevant asset, service, application, network or identity. This avoids adding dozens of special columns to every register and makes unusual settings easier to search and maintain.

Documents, diagrams and actions

Link to authoritative diagrams, runbooks, screenshots, configuration exports, contracts, licence records and recovery evidence. Use the diagram canvas for a compact embedded overview and keep the maintainable source file in an approved repository. Record missing information, unsupported systems, security concerns and follow-up work in the Actions register with an owner, priority and target date.

Passwords, credentials and workbook security

Best practice is to store usernames, passwords and other credentials in a reputable password manager and record the vault or item reference in the register. This is the preferred approach because a password manager is designed to create, store and manage strong, unique credentials.

Practical experience also shows that individuals and small businesses may not use a password manager, may leave vendor default passwords unchanged or may lose the only known credential for a router, firewall, NAS, website or provider account. For those situations, the register includes optional username and password fields so essential access information can be documented rather than forgotten.

Before entering any password

Apply Excel file-level password-to-open encryption to the working copy. Store the workbook encryption password outside the workbook, preferably in a reputable password manager. Restrict access to authorised people and use a controlled sharing method. The blank downloadable template is intentionally delivered without a password, so encryption must be applied before private data or secrets are entered.

 

Encrypt the register even when no passwords are stored. It may still contain private company information, internal addresses, provider account details, network ranges, administrative URLs, configuration data and recovery information that should not be publicly accessible.

Worksheet protection or workbook-structure protection can help prevent accidental editing, but it is not a substitute for file-level encryption. File encryption also does not replace access controls, secure sharing, backups, device security or good judgement about what should be stored.

Private keys, API tokens, MFA recovery codes and other high-impact secrets should normally remain in a purpose-built password manager or secrets vault. Record a reference in the spreadsheet unless there is a documented and approved reason to do otherwise.

To Apply Excel file-level password-to-open encryption, open the workbook:

-> File -> Save As -> browse-to-your-save-location -> Tools -> General Options -> Password to open -> enter-your-password -> OK -> Save

What this template is – and is not

This workbook is a documentation, discovery and handover register. It can provide organised source information for support, an audit, a risk review, an insurance questionnaire, a supplier transition, due diligence, business continuity or disaster-recovery planning.

It is not a penetration test, vulnerability assessment, compliance certification, security guarantee, legal opinion or substitute for tested backup and recovery procedures. The quality of the result depends on the accuracy, completeness and ongoing review of the information entered.

How to get started

  1. Download the workbook and save a separate working copy for the client or organisation.
  2. Apply file-level password-to-open encryption before entering private information or credentials.
  3. Enter the client name, logo, document owner, classification, review dates and company details on Start Here.
  4. Begin with Sites, Services and Email, then add Assets, Applications & Data, Networks, Backups, Identity & Access and Configurations.
  5. Use stable IDs so related records can be connected without duplicating information.
  6. Use password-manager references wherever possible. Use optional password fields only after encryption and an access decision.
  7. Link diagrams, runbooks, screenshots and configuration exports from Documents rather than embedding everything in the workbook.
  8. Record missing information and follow-up work in Actions with an accountable owner and target date.
  9. Review the register after material system changes and on an agreed schedule.

Frequently asked questions

Question

Answer

Can I store usernames and passwords in the register?

Yes. Password fields are optional. A reputable password manager and vault reference are preferred, but the workbook supports password capture where that is the practical way to avoid lost or unchanged default credentials. Encrypt the file with a password-to-open before entering any secret.

Should I encrypt the workbook when I do not store passwords?

Yes. The register still contains internal and private information such as network details, administrative URLs, provider accounts, ownership, configuration and recovery data.

How does the client logo appear on every tab?

Enter a direct HTTPS image URL on Start Here for automatic display in supported Excel versions. For a local embedded image, follow the linked-picture instructions in the workbook or contact KAOS Data for a customised implementation.

Can I customise the template?

Yes. Add rows, amend the dropdown lists and adapt the registers to suit the environment. Retain the KAOS Data originator attribution. Contact KAOS Data for larger structural changes, automation or integrations.

Is this a formal IT audit?

No. It is a documentation, discovery and handover register. It can support an audit or review, but it does not provide assurance or certification by itself.

 

DOWNLOAD THE FREE EXCEL TEMPLATE

REQUEST ENHANCEMENTS OR ASSISTANCE

KAOS Data can help you identify systems, collect configuration information, organise supporting evidence and prepare practical documentation for support, handover and recovery. Contact Us to discuss the scope of your environment.

Check out our other Cheat Sheets and Blogs and if you would like us to write a cheat sheet for you, for FREE, (and we find it suitable) Contact Us.