Assets and obligations
Inventory important assets and track requirements outside a framework
Assets and obligations provide context that does not always fit neatly into a framework.
Assets
Section titled “Assets”An asset represents something the organization needs to understand and protect, such as a service, system, repository, device class, or data store. Record business impact and data sensitivity consistently so risk and control decisions can be compared.
Link assets to the controls, measures, risks, and other records that explain how they are protected. An asset inventory is useful only while it reflects the systems the organization actually operates, so assign ownership and review it when architecture changes.
Obligations
Section titled “Obligations”An obligation records a legal, regulatory, contractual, or customer requirement. It is separate from a framework control because the source and wording may be specific to the organization.
Link obligations to:
- controls that satisfy the requirement;
- risks created by noncompliance;
- measures and evidence showing implementation;
- documents that formalize the organization’s response.
Publishing asset and obligation lists creates reviewed snapshots for reporting. Continue to maintain the underlying records as systems and requirements change.