Assets
Build and maintain the systems inventory that connects ownership, data classification, risk, and findings.
Assets
The asset register at /assets describes the technology and information-bearing resources in your
compliance scope: cloud resources, repositories, devices, applications, services, environments, databases,
and other systems you depend on or protect.
Why the page exists
An asset register gives controls, risks, findings, and evidence a concrete scope. “We patch systems” is hard to evaluate without knowing which systems exist; “this finding affects production database A, owned by team B” can be assigned, treated, and evidenced.
Asset inventories support common expectations in ISO 27001 asset management, SOC 2 system-description and risk processes, and privacy accountability. Frameworks differ, but all benefit from knowing where important systems and data reside.
Where assets come from
- Integrations discover provider resources and maintain source/external identifiers and metadata.
- Manual creation covers assets a connector cannot see or that represent a logical business system.
- Later syncs update provider-backed records; manually maintained context should be reviewed for drift.
An integration can show what its API exposes, not whether the resource is in audit scope or how your business uses it. Classification and accountable ownership remain organizational decisions.
What you can record
- name and description
- type, platform, source, and provider external ID
- owner (an organization member or personnel record)
- confidentiality, integrity, and availability classifications
- retention statement
- linked risk
- structured provider metadata
The directory can be searched and filtered by ownership status, source, type, confidentiality, and owner. It also groups related assets and surfaces unowned or unclassified inventory.
Recommended workflow
- Connect authoritative infrastructure, identity, code, and device sources.
- Add missing logical systems manually only where that improves the operating model.
- Normalize duplicates rather than treating each provider row as a separate business service.
- Assign an owner who can make lifecycle and risk decisions.
- Classify confidentiality, integrity, and availability based on business impact.
- Link the most relevant risk and use findings to show observed weaknesses.
- Review unowned, unclassified, stale, and newly discovered assets on a regular cadence.
Relationships
- Personnel: asset ownership can resolve through a personnel record or account. The person's directory detail then shows linked assets.
- Risks: an asset can carry a linked risk, grounding the risk scenario in a real target.
- Findings: security findings can be linked to an affected asset for triage and remediation.
- Evidence and controls: integration evidence about an asset can support controls, but the asset record itself is primarily inventory and scope.
- Privacy: the privacy data map models systems, datasets, and processing activities. It complements the security asset register; one does not automatically replace the other.
A discovered resource is not automatically in scope, and an absent resource is not proof that it does not exist. Document connector coverage and reconcile the register against architecture and procurement.