Assets
The inventory the rest of the platform depends on.
What it does
Almost every GRC question eventually resolves to an asset. Which systems are in scope, which vendor touches them, what happens to the business if one is unavailable, and what data class they hold.
Assets holds systems, applications, data stores, infrastructure and physical assets with named ownership, and treats business processes as first-class objects alongside them.
Because one asset record is the same record in Risk, Privacy, Third-Party Risk and Business Continuity, an incident scoped to an asset immediately tells you the vendors, the data categories and the recovery objectives involved.
Asset inventory
Systems, applications, data stores, infrastructure and physical assets, each with a named owner.
Ownership is the field that makes everything else work. An asset with no owner produces findings nobody actions.
AST-0219 · Core Banking
Processes as first-class objects
Business processes with their dependencies, used directly by business impact analysis and by privacy records.
RoPA and BIA both describe processes. Modelling the process once means the privacy team and the continuity team are describing the same thing.
Data classification
A configurable classification taxonomy, aware of Oman's PDPL out of the box.
Classification drives handling requirements. Getting it onto the asset record is what lets a control be applied by class rather than one system at a time.
Asset and vendor map
Which third party touches which asset. Feeds third-party risk directly and scopes incidents instantly.
When a vendor announces a breach, the only question is which of your systems they touch. This map answers it in seconds rather than in a week of emails.
Continuity attributes
Optional recovery time and recovery point objectives recorded on assets and processes.
Continuity planning that does not reference the asset inventory drifts out of date the moment a system is replaced.
RTO 4h · RPO 15m
Roles that live here
- Asset Owner
- IT Director
- Business Continuity Manager
- Data Protection Officer
Drawn from sixteen built-in roles, each scoped along the org tree. Access control
Related frameworks
See Assets on your inventory.
A 45-minute working session focused on the frameworks and requirements that matter to your organization.