markdowneditor

Asset Inventory & Classification

Assets + 4-level classification

ISO y cumplimientoBreveassetinventory

Cómo usar: Foundation of the risk register: you can't assess risk on assets you haven't listed. Classification drives handling rules downstream.

Vista previa

Asset Inventory & Classification

ISO/IEC 27001:2022 A.5.9 (inventory of information + associated assets) + A.5.12 (classification). The inventory is the foundation the risk register is built on.

FieldValue
Document IDDOC-ISMS-012
OwnerAsset management
ReviewQuarterly

Classification scheme (A.5.12)

LevelDefinitionHandling rules
PublicNo harm if disclosednone
InternalMinor harmaccess on need-to-know
ConfidentialSignificant harmencryption, limited access
RestrictedSevere harm/legalstrict controls, audit access

Information assets

IDAssetTypeOwnerLocationClassificationCIA ratingDependencies
IA-01Customer DBData@namecloud regionRestrictedC3 I3 A2srv-01, backup
IA-02Source codeIP@namerepo hostConfidentialC2 I3 A1CI system
IA-03HR recordsData@nameHRIS SaaSRestrictedC3 I2 A1vendor

Associated assets (hardware/software/services)

IDAssetTypeSupportsOwnerLocationNotes
AA-01Production clusterInfrastructureIA-01@opscloud AZredundancy NN
AA-02Laptop fleetHardwarestaff@itdistributedMDM enrolled
AA-03SaaS vendor XServiceIA-03@procexternalcontract ref

Lifecycle tracking

ChangeDateByRecord
Asset added/retired/transferredticket ref

Plantillas relacionadas