Minimum asset record
For each managed asset, capture a stable identifier, owner, service or business function, environment, internet exposure, network zone, operating system or platform, software lifecycle status, critical dependencies, data sensitivity, backup/recovery path, and maintenance window. Cloud workloads and short-lived infrastructure may need tags and automation rather than a traditional CMDB record, but the same context still has to exist somewhere reliable.
Do not require perfect inventory before starting. Establish a minimum viable record, reconcile gaps over time, and measure unmanaged or unknown assets as a program risk. If the scanner finds a host nobody owns, that is both a vulnerability-management problem and an asset-governance problem.