Assets
Last checked on
Assets lists the devices, systems, applications, data stores and other things your organisation relies on, with an owner, a provider, how critical each one is and whether it holds personal or sensitive data.
Why this protects your organisation
You can only protect what you know about. If nobody knows that an old test server still holds a copy of the customer database, nobody patches it or deletes it. An asset list with an owner for each item tells you where an incident could do damage and who should act. Annex A control 5.9 of ISO 27001 expects you to know what information you have and where it lives, and to give each item an owner.
Steps
- Open Assets in the Organisation group.
- Click New Asset.
- Fill in the Name and choose the Kind. Criticality starts at Normal; change it if needed.
- Choose an Owner from People, and fill in the Provider and Environment if they apply.
- Switch on Contains personal data or Contains sensitive data where relevant, and click Create.
- For a new system, choose Set up system tasks in its row to create the follow-up tasks.
- When an asset is no longer used, choose Retire, enter the Retirement date and click Submit.
The list shows each asset's Name with its description, the Kind, the Owner, the Provider, the Environment, the Criticality, whether it Contains personal data or Contains sensitive data, and its Status. You can filter on Kind, Criticality and Owner.
The fields
- Kind Device, System, Application, Data store, Service, Account, Location or Other.
- Owner The person who answers for this asset: who decides on access and makes sure it is maintained.
- Provider Who delivers it, for example your cloud host or the vendor of a SaaS tool. This is free text; the suppliers themselves are recorded under Suppliers.
- Environment Where it lives, for example production, test or office.
- Criticality Low, Normal, High or Critical. Use it to decide where to look first when something goes wrong.
- Acquired on When you bought or took it into use.
Tasks
An asset's page has a Tasks section with the tasks linked to it. Set up system tasks creates the tasks from the task templates, such as recording who gets access and how the system is backed up. With Create task you add a follow-up of your own.
If it does not work
I do not see New Asset, Retire or Set up system tasks
These actions require edit rights for the Organisation module. Owners and members have them; an advisor only when the workspace owner has granted them. Only owners and members can delete an asset.
A retired asset is still in the list
That is intended. A retired asset stays visible with the status Retired on and its date, so you can always see what you used and when it stopped.
The list shows fewer assets than I expect
Check whether a filter on Kind, Criticality or Owner is active, and clear it.
The Owner list is empty
Owners are chosen from People. Add the person there first.
Screens this is about
- Assets