Asset identification within RA

Latest update:
23 Jun
2022

A question which comes up time and time again is ‘How do I approach asset identification within my information security risk assessment’.  Typically, this question is twofold; which assets to include and the depth or granularity.  This week’s top tip will look at granularity.

In short, stay high level where possible.  Your goal, through the risk assessment, is to identify and then manage your risks in terms of confidentially, integrity and availability (CIA).  If you start with an asset list pages long, perhaps by taking an extract from IT’s Configuration Management Database (CMDB), your results are going to be pages long.  With this level of detail, you will find yourself spending a significant amount of time trying to consolidate risks into a manageable number.  You can always go down into additional detail where an asset has a different CIA value.  For example, if you have laptops which store, process or transmit information you need to include these in your assessment.  However, you do not need to include every make and model in your assessment or even group laptops by every department.  We should group these by the levels of information they have access to.  So ‘Laptops’ could be used to cover most staff members laptops as they all have access to the same level of information.  You can then use ‘Sensitive Laptops’ for laptops that are used by your senior management team or HR as these laptops will typically have a higher level of access to information.

By grouping these assets, you reduce the amount of duplicated results in your risk assessment and get a more detailed and manageable representation of risk.  Also, if the controls are likely to be deployed consistently across all assets then there may be no benefit to splitting assets into subcategories.  For example, if all laptops will be encrypted and have similar endpoint controls (e.g. antivirus, firewalling) then rating the asset as a worst case will be appropriate.

So, think about what that asset ultimately holds or has access to and approach your asset granularity with that in mind!

Thumbnail of the Blog Illustration
Information Security
updateD:
20/7/2022
10 Top Tips for Keeping Information Secure When Homeworking

Following on from COVID, working from home is now a standard working practice, but how do we go about it in a secure way. In this blog, we aim to provide 10 top tips to enable you to keep important

Read more
Thumbnail of the Blog Illustration
Information Security
updateD:
11/8/2022
How Secure is Zoom?

Many organisations have had to adapt very quickly to the rapidly changing restrictions brought in across the globe to help combat the spread of COVID-19 and, in a lot of cases, this has meant that...

Read more
Thumbnail of the Blog Illustration
Information Security
updateD:
19/7/2022
How Do You Meet the Asset Management Requirements of IS0 27001?

In order to meet the requirements of ‘Asset management’ A.8 from Annex A of ISO 27001, it is necessary to identify organisational assets and define appropriate protection ...

Read more
"
Very good explanation of ISO 27001 auditing, with real use case experience which is very important for attendees.
Webinar 'ISO 27001 Internal Auditing, the 6 Pillars of Success'
contact US

Let us help you

Let us help you in your compliance journey by completing the form and letting us know how we can best support you.