Asset Management
Build the Asset register, consume centrally managed provider data, review technical exposure and supply governed Asset context to Risk, Controls and TPRM.
From identification to connected risk context
Assets are created or imported, classified and valued, enriched by connected technical evidence, and then used in Risk, Control and third-party workflows.
Create manually or import from CSV.
Choose class, category, type, owner and lifecycle.
Complete confidentiality, integrity and availability ratings.
Review applicable organisation Controls and Asset-level implementation.
Review imported technical findings, evidence and vulnerability lifecycle where integrations are connected.
Link selected technical evidence to Risk and maintain relevant third-party dependencies.
Build and use the Asset register
Create dependable Asset data and use it as governed context for the wider platform.
Create and import Assets
Create Assets from scratch or use the CSV import workflow for larger inventories.
Risk contextClassify, value and assess Assets
Maintain lifecycle and Asset Control context, then initiate the appropriate Risk assessment.
Technical exposureConnect vulnerability data and review technical exposure
Configure the provider centrally in Admin → Integrations, inspect grouped findings and evidence, then link selected technical vulnerabilities to Risk.
Plan the rollout and operate the module
Download the practical first-time implementation handbook for this module.
Asset facts are reused across modules
CIA valuation is a starting point for Risk, while taxonomy, vendor references and explicit links also support Control applicability and TPRM discovery.
- Changing the organisation CIA matrix can recalculate related values.
- Asset criticality and CIA value are related but not interchangeable concepts.
- Asset vendor references can be discovered as TPRM candidates rather than automatically becoming third parties.
- Use stable Asset identifiers to reduce duplicates and preserve cross-module links.
- Provider credentials, jobs and scheduling are owned by Integration Management; Asset Management owns the resulting vulnerability-domain records and exposure lifecycle.
- Download the Asset Management First-Time Implementation Handbook for rollout guidance and the Technical Documentation for implementation/operations detail.
No guidance matches that search.