Asset inventory
“What we protect” — the first step of GRC (the Identify function). Inventory your assets, classify them by criticality, then log risks against them and cover them with policies. Every risk should point at one of these.
0
Assets
0
Critical
0
High
0
Medium
0
Low
Why start here?
Before anything else, a security program lists what it owns and cares about — servers, databases, apps, data. You can't defend what you haven't named. This is the very first thing every framework asks for: the NIST Cybersecurity Framework → Identify function (ID.AM, Asset Management) NIST CSF: Identify and CIS Controls v8 → Controls 1 & 2 (Inventory of Enterprise Assets and Software) CIS Controls 1 & 2.
| ID | Asset | Type | Location | Criticality | FIPS 199 | Owner | Open risks | |
|---|---|---|---|---|---|---|---|---|
| No assets yet — add the systems, databases and data you need to protect. | ||||||||