Cyber Risk Compendium

Asset

Assets are what the organisation wants to protect from harm. Assets come in the form of many different categories, like financials, people, personal data, important intangible assets and technical things like devices, servers or cloud services. The guiding principle in asset management is, that “you can’t protect what you don’t know you have”. Thus, it is important to build an inventory of assets and install processes to both register and protect new assets and dispose of assets in a secure way when they reach end of life.

The importance of an asset is evaluated in a business impact analysis.

Read: A risk is a threat to an asset that makes use of a specific type of vulnerability the asset has (or might have).