Help Centre workspace

Asset Management

Build the Asset register, consume centrally managed provider data, review technical exposure and supply governed Asset context to Risk, Controls and TPRM.

Start with the workflow

From identification to connected risk context

Assets are created or imported, classified and valued, enriched by connected technical evidence, and then used in Risk, Control and third-party workflows.

1
Identify

Create manually or import from CSV.

2
Classify

Choose class, category, type, owner and lifecycle.

3
Value

Complete confidentiality, integrity and availability ratings.

4
Control

Review applicable organisation Controls and Asset-level implementation.

5
Observe

Review imported technical findings, evidence and vulnerability lifecycle where integrations are connected.

6
Connect

Link selected technical evidence to Risk and maintain relevant third-party dependencies.

Asset workflows

Build and use the Asset register

Create dependable Asset data and use it as governed context for the wider platform.

Implementation documentation

Plan the rollout and operate the module

Download the practical implementation handbook or the detailed technical reference for this module.

Important operating rules

Asset facts are reused across modules

CIA valuation is a starting point for Risk, while taxonomy, vendor references and explicit links also support Control applicability and TPRM discovery.

  • Changing the organisation CIA matrix can recalculate related values.
  • Asset criticality and CIA value are related but not interchangeable concepts.
  • Asset vendor references can be discovered as TPRM candidates rather than automatically becoming third parties.
  • Use stable Asset identifiers to reduce duplicates and preserve cross-module links.
  • Provider credentials, jobs and scheduling are owned by Integration Management; Asset Management owns the resulting vulnerability-domain records and exposure lifecycle.
  • Download the Asset Management First-Time Implementation Handbook for rollout guidance and the Technical Documentation for implementation/operations detail.