Plumb
Track
Live demo
Assets
Vendors
+ New risk
Board
Register
Evidence
Governance
Controls
SoA
RMF
Compliance
Obligations
POA&M
Plan
Audit
Coverage
Appetite
Dashboard
Trends
Heatmap
Report
Integrity
Clock
FIPS 199
Standards
Authority
Guide
Playbook
π Brief
Calendar
API / PlumbWatch
Acting as
GRC
Risk System
New asset
Add something you need to protect — a system, database, application or data store.
What is an asset?
Name
Type
which type?
System context
(which environment is this, and is the data real? — drives an honest FIPS 199 categorization)
Environment
Production
Staging
Lab
Data
Synthetic / disposable only
(no real PII, no live mission)
FIPS 199 security categorization
FIPS 199 ↗
guide
(optional now — impact of a loss of Confidentiality / Integrity / Availability; can be set later)
Confidentiality
β not categorized β
Low
Moderate
High
Why this level?
Integrity
β not categorized β
Low
Moderate
High
Why this level?
Availability
β not categorized β
Low
Moderate
High
Why this level?
Criticality
(floor = the FIPS 199 high-water mark of C/I/A [
FIPS 199
]; escalate higher only with a documented
business-criticality
reason [
NIST SP 800-34 — Business Impact Analysis
]
what's a BIA? ↗
)
low
medium
high
critical
Why this criticality?
see examples
(required — explain the rating at any level; tick any factors that apply)
— primary reason for this criticality —
Matches the FIPS 199 high-water mark (no business escalation)
Directly generates revenue (financial impact)
Severe reputational / brand impact if compromised
Low tolerable downtime β customers or operations depend on availability (BIA)
Legal / regulatory obligation (GDPR, HIPAA, PCI DSS, SOX)
Holds regulated or sensitive data (PII, PHI, cardholder, secrets)
Single point of failure β many systems or users depend on it
Holds credentials or controls access to other systems
Slow or difficult to recover or replace (long RTO)
Safety-of-life or physical impact
Other β see rationale
Location
Owner
Description
Create asset