Asset Management guide

Assess controls and send an asset to risk

Maintain asset control and lifecycle information, then initiate a structured risk assessment from the asset record.

Asset Manager or Risk Manager Approximately 5–10 minutes Updated 27 July 2026

Review the asset

Open the asset record and confirm its classification, CIA value, lifecycle status and ownership. Related controls and risk details are presented in the same workspace.

The asset overview shows value, criticality, lifecycle, control status and whether the asset has been risk assessed.

Update applicable controls

PurpleWASP can present controls that apply to the asset type. Update each control to reflect its current implementation status. These values can influence compliance and the context available to risk assessors.

Maintain lifecycle status

Update the asset when it moves between states such as In Use, In Maintenance or Retired. Lifecycle labels support reporting and help teams identify assets that may need reassessment or retirement activity.

Send the asset to the Risk Register

1

Confirm the CIA valuation

Risk assessment relies on the asset's confidentiality, integrity and availability value. Complete any missing values first.

2

Select Assess Now

Use the asset action that sends the record to the Risk Register.

3

Confirm the risk record

Open Risk Management and verify that the asset appears for assessment with its inherited value and configured matrix.

The asset enters the Risk Register with its current value and becomes available for qualitative or quantitative assessment.

Understand scale changes

When an administrator changes the CIA matrix from 3×3 to 5×5, or back again, asset and risk values recalculate automatically. Treat this as a governance change: review thresholds, reports and high-priority records after the change.

Common problems

Assess Now is unavailable

Complete required classification and CIA values, then confirm that your role can initiate risk assessment.

The asset does not appear in the Risk Register

Refresh the register, clear filters and confirm that the send action completed successfully.