Information Asset
Definition
Anything that has value to the organisation by virtue of the information it contains or the information function it performs. Includes data, software, hardware, services, people with specialist knowledge, and intangibles such as reputation. ISO/IEC 27005 defines it as anything that has value and that the organisation is obliged to protect.
- Standard
- ISO/IEC 27005
- Includes
- Data, software, hardware, services, people, reputation
- Field
- Information security risk management
Common questions
Why does the ISO/IEC 27005 definition of information asset extend to people and reputation, not just data and hardware?+
Risk assessment must account for everything whose loss or compromise damages the organisation, and specialist staff knowledge or organisational reputation can be as damaging to lose as a database, so the standard deliberately covers intangible assets alongside physical and digital ones.
How does asset classification feed into a risk identification process?+
Each information asset is inventoried and assigned an owner and a sensitivity or criticality rating, which then determines what threats and vulnerabilities are assessed against it and what level of control is proportionate to protect it.
Related terms
- Asset Inventory (Asset Register)
- A structured record listing every information asset in scope, together with its owner, custodian, physical or logical location, classification level, criticality rating,...
- Asset Owner
- The person or role accountable for ensuring an asset is appropriately classified, protected, and reviewed. The owner is typically a business manager...
- Classification Tier
- A label assigned to an asset or data type indicating its sensitivity and the handling rules that apply. Common tiers are Public,...
- Threat
- A potential cause of an unwanted incident that could harm an asset. Threats may be natural (flood, fire), environmental (power failure), human...
- Vulnerability
- A weakness in an asset or in a control protecting that asset, which a threat could exploit to cause harm. Examples: an...