Asset Management guide

Classify, value and assess an Asset

Review Asset classification, CIA value, lifecycle and applicable Control context, then initiate the structured Risk workflow.

Asset Manager or Risk Manager Approximately 5–10 minutes Updated 21 September 2026

Review the Asset

Open the Asset record and confirm its classification, CIA value, lifecycle status and ownership. Use the related Control and Risk context to understand how the Asset is governed elsewhere in PurpleWASP.

The asset overview shows value, criticality, lifecycle, control status and whether the asset has been risk assessed.

Use the Asset details workspace

The details panel is organised into Overview, Controls, Vulnerabilities and Activity, with persistent Risk Details alongside the workspace. Use Guide this asset for an in-product walkthrough of the current layout.

Review applicable Controls

PurpleWASP can surface Controls that apply to the Asset context. Where you are authorised to maintain Asset-level implementation, record the current state for that Asset rather than treating the organisation-wide Control status as proof of coverage.

Applicability and implementation are separate. Use Control Management when you need the authoritative organisation Control, broader scope or assurance history.

Review technical exposure where integrations are connected

Open the Vulnerabilities tab to review active findings grouped by provider vulnerability identity. Use Details to inspect description, remediation, CVEs, affected port/service, evidence and lifecycle history. Link selected groups to an existing Risk or create a normal Risk from the selected evidence when a new scenario is required.

Evidence is not automatic Risk creation. A scanner observation supports a Risk decision; the Risk record and assessment remain human-governed.

Maintain lifecycle status

Update the asset when it moves between states such as In Use, In Maintenance or Retired. Lifecycle labels support reporting and help teams identify assets that may need reassessment or retirement activity.

Send the Asset to the Risk Register

1

Confirm the CIA valuation

Risk assessment relies on the asset's confidentiality, integrity and availability value. Complete any missing values first.

2

Select Assess Now

Use the asset action that sends the record to the Risk Register.

3

Confirm the risk record

Open Risk Management and verify that the asset appears for assessment with its inherited value and configured matrix.

The Asset enters the Risk workflow with its current context and becomes available for the appropriate Risk assessment path.

Understand scale changes

When an administrator changes the organisation CIA model, related Asset and Risk values can be recalculated. Treat this as a governance change: review thresholds, reports and high-priority records after the change.

Common problems

Assess Now is unavailable

Complete required classification and CIA values, then confirm that your role can initiate risk assessment.

The asset does not appear in the Risk Register

Refresh the register, clear filters and confirm that the send action completed successfully.