Use promo code:
CTA20

Expert Advice Community

Guest

Asset register

  Quote
Guest
Guest user Created:   Jul 13, 2019 Last commented:   Jul 13, 2019

Asset register

I have a question about the Asset Inventory. We don’t use any ISO 27001 software (company’s on the market sell and offer). We have a main system for our company (self-programmed) where each information (for example about the asset: employee) is inside. When I try to fill the asset inventory (template you gave us on hand) how detailed does it have to be? For example: if I have the asset: employee - is it enough in the column „description to the value" to give only the path to our system where you can find the employees, or do we have to list each employee inside the template? The same for workstations? Do we have to list each workstation or it is enough to refer to the place in our erp-system?
0 0

Assign topic to the user

ISO 27001 RISK ASSESSMENT TABLE

Implement risk register using catalogues of vulnerabilities and threats.

ISO 27001 RISK ASSESSMENT TABLE

Implement risk register using catalogues of vulnerabilities and threats.

Expert
Rhand Leal Jul 13, 2019

If we would come to the asset „server“ on the asset inventory list - we've got over 6.000 of them. How should we list them?

Answer:

ISO 27001 does not prescribe any level of granularity, so you can adopt the levels you understand that will better fulfill your needs. Considering your examples, you should consider to split assets in details when t hey require different levels of protection and different number of applicable controls.

For example, managers will have access to a higher level of access to information than general employees, so you should consider them as a separate category of asset, to avoid implementing controls related only to them to all employees.

For the case of workstations, you can use categories related to their purpose. For example general workstation and development workstation, including as detailed information of the quantity of each type.

It is important to note that you can reference to other system(s) which contains more detailed information about each asset, so you do not need to replicate information unnecessarily.

This article will provide you further explanation about asset register:
- How to handle Asset register (Asset inventory) according to ISO 27001 https://advisera.com/27001academy/knowledgebase/how-to-handle-asset-register-asset-inventory-according-to-iso-27001/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Jul 13, 2019

Jul 13, 2019

Suggested Topics