Asset
Also known as: information asset
Anything of value to the organisation that needs protecting - data, systems, devices, people or know-how.
Draft - this entry has not been reviewed yet.
Formal
Any resource the organisation depends on to do its work and whose loss, misuse or disruption would cause harm. Each asset is given an owner and a value, so that risks can be tied to something concrete.
In plain English
Everything you would worry about if your home caught fire - the laptop, the family photos, the house keys, and the one person who knows where everything is kept.
In practice
Before its first risk review, a small accounting firm in Copenhagen lists its client files, its bookkeeping system and the staff laptops - and the one bookkeeper who is the only person who knows how to run payroll.
Technical deep dive
ISO/IEC 27005 distinguishes primary assets, meaning business processes and the information they depend on, from supporting assets such as hardware, software, networks, people, sites and organisational structures, on which the primary assets rely. The distinction matters because value and impact belong to the primary asset, while vulnerabilities usually sit in the supporting ones: a customer database is valuable because of the sales process it serves, but it is breached through an unpatched web server, a misconfigured storage bucket or an administrator's laptop. A risk assessment that lists only servers misses the processes; one that lists only processes cannot be turned into concrete controls.
ISO/IEC 27002:2022 control 5.9 requires an inventory of information and other associated assets, including owners, and controls 5.10 and 5.11 cover acceptable use and the return of assets when people leave. The owner is accountable for classification, access decisions and periodic review; custodians such as IT operations or a cloud provider carry out the day-to-day protection. ISO/IEC 27001:2013 dropped the requirement to identify risks through assets and introduced the risk owner instead, so asset-based identification is now one valid approach among several, with the event-based approach described in ISO/IEC 27005:2022 as the alternative.
In practice the inventory is assembled from several sources: a CMDB or IT asset management tool, endpoint management (MDM/EDR agents), cloud provider APIs, identity providers, network discovery, procurement records and SaaS spend data. CIS Controls v8.1 puts the inventory of enterprise assets and of software assets first and second, on the reasoning that unmanaged assets cannot be patched, monitored or restored. The recurring failure mode is drift: shadow IT, forgotten test environments, dangling DNS records that still point at decommissioned resources and personal cloud accounts used for work. External attack-surface management tools exist precisely to find internet-facing assets the organisation does not know it has.
Several kinds of asset are routinely forgotten. Identities, secrets, API keys and certificates are assets whose loss is often more damaging than losing a server. Knowledge concentrated in one person is a people asset with a single point of failure. Suppliers and data held by processors remain the organisation's responsibility under GDPR Art. 28 even though the organisation does not own the hardware. The asset concept differs from the asset inventory, which is the maintained record, and from the risk, which exists only when a threat, a vulnerability and an impact attach to a specific asset.
What to learn first
Everything this builds on, foundations first.
- CIA triad
- →Asset
Relationships
Sources & further reading
Standards & official texts
- NIST Glossary - Asset · NIST
Course material
- Cyber Security Fast Track - Kursuskompendium, Modul 5
Where this data comes from
This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.
See the review queueSuggest a correction on GitHubThis term as JSON
Mentioned in
Check yourself
Loading…