Asset Management
The asset register is the foundation for risk assessment, vulnerability management and ISO 27001 inventorying — one dataset all three areas share.
One asset register, three purposes.
The asset register holds IT and information assets with individually configurable attributes — from the standard field set to organization-specific custom fields. Every asset can be assigned an owner and traced in detail.
Assets underpin two further registers: the risk register links threat/vulnerability pairs to concrete assets instead of abstract categories, and the vulnerability register tracks remediation status per asset from open to resolved — including an automatic resolution date.
For ISO 27001, the asset register covers the inventory requirement under A.5.9: a complete, current inventory of information assets is the prerequisite for any credible risk assessment under ISO 27005.
What the asset register delivers.
Individual attributes
Organization-specific custom fields can be configured per asset, beyond the standard field set.
Linkage to the risk register
Threat/vulnerability pairs are assigned to concrete assets, not abstract categories.
Vulnerability tracking per asset
Status tracking from open to resolved, with an automatic resolution date.
Ownership per asset
Every record can be assigned an owner — traceable during audits.
Foundation for ISO 27001 A.5.9
A complete inventory of information assets as the prerequisite for risk assessment.
A register that carries other registers.
Assets don't stand alone — they anchor risk and vulnerability assessment.
→ Risk register
Every risk scenario can be linked to concrete, affected assets — making residual risk traceable rather than estimated.
→ Vulnerability management
Vulnerabilities are recorded against the asset and tracked through to resolution.
→ ISO 27001 inventorying
The asset register meets the base requirement under A.5.9 — inventory of information assets.
How Asset Management works.
Record assets
Add manually or import from existing sources — with individual attributes as needed.
Assign ownership
Every asset gets an owner; status changes stay traceable.
Link to risk & vulnerabilities
Asset-related threats and vulnerabilities flow directly into the risk register and remediation tracking.
A core building block for these regimes.
Inventory of information assets under A.5.9 — the foundation of every risk assessment.
Regulation in detail →Asset data feeds concentration-risk analysis and the register of information.
Regulation in detail →Asset visibility as a prerequisite for risk analysis under Art. 21(a).
Regulation in detail →One asset register for risk, vulnerabilities and ISO 27001.
We'll show you how your existing IT inventory can be imported and linked to risk and vulnerability management.