Asset Inventory (Asset Register)
Definition
A structured record listing every information asset in scope, together with its owner, custodian, physical or logical location, classification level, criticality rating, and relevant dependencies. It is the foundational artefact for risk assessment and audit scope definition.
- Records
- Owner, custodian, location, classification, criticality
- Role
- Foundational artefact for risk assessment and audit scope
- Scope
- Every information asset in the organisation
- Includes
- Dependencies between assets
Common questions
Why do audits stall when the asset register is incomplete?+
Audit scope is normally defined by walking the asset register, so an asset omitted from the register is effectively omitted from the audit and from risk assessment coverage, leaving it unreviewed regardless of how sensitive it actually is.
What is the difference between an asset register and a configuration management database (CMDB)?+
A CMDB tracks technical configuration items and their relationships for IT operations. An asset register is broader and risk-focused, adding ownership, classification level, and criticality rating fields that a CMDB does not always carry, though the two are often kept in sync.
Related terms
- Asset Owner
- The person or role accountable for ensuring an asset is appropriately classified, protected, and reviewed. The owner is typically a business manager...
- Classification Tier
- A label assigned to an asset or data type indicating its sensitivity and the handling rules that apply. Common tiers are Public,...
- Information Asset
- Anything that has value to the organisation by virtue of the information it contains or the information function it performs. Includes data,...
- Threat
- A potential cause of an unwanted incident that could harm an asset. Threats may be natural (flood, fire), environmental (power failure), human...
- Vulnerability
- A weakness in an asset or in a control protecting that asset, which a threat could exploit to cause harm. Examples: an...