Information Asset
What is Information Asset?
Any data, system, or resource that has value to the organization and requires protection based on its classification level.
Terms that appear alongside information asset
Each of these is named in at least one of the same controls as information asset. The number is how many controls name both.
- risk assessment 3 shared controls
- asset inventory 3 shared controls
- security officer 3 shared controls
- information security 3 shared controls
- ciso 2 shared controls
- risk reporting 2 shared controls
- configuration management database cmdb 2 shared controls
- risk committee 2 shared controls
Frameworks that govern information asset
What the standards actually require on information asset
Requirements naming information asset across 6 standards, quoted from the control text.
Information assets, including those held by related parties and third parties, must be classified by criticality and sensitivity reflecting the potential impact of an incident on the entity or on depositors, policyholders, beneficiaries and other customers.
CPS234-20 · Information Asset Classification →Restricts physical access to facilities and protected information assets (for example, data center facilities, back-up media storage, and other sensitive locations) to authorized personnel to meet the entity's objectives
SOC2-CC6.4 · Restricts physical access to facilities and protected information assets (for example, data center facilities, back-up media storage, and other sensitive locations) to authorized personnel to meet the entity's objectives →Information assets, systems, and data are inventoried and classified based on sensitivity and criticality.
IS-IV.A.1 · Inventory and Classification of Information Assets →Securely manage information assets within the CDR data environment over their lifecycle, including data loss prevention, controls over CDR data in non-production environments, and information asset lifecycle management.
AUCDR-IS-3 · Securely manage information assets over their lifecycle →Implement Technology Risk Governance + Technology Risk Management Framework + Information Asset Management per MAS TRM Chapters 2 + 3 + 5.
MAS-TRM-Governance-Chapters-2-3-Board-Senior-Management-Risk-Framework-Information-Asset-Management · MAS TRM Governance + Chapters 2-3 + Board + Senior Management + Risk Framework + Information Asset Management →The entity removes access to protected information assets when an individual no longer requires access.
SSAE18-CC6.3 · CC6.3 - Access Removal →Questions people ask about information asset
What is Information Asset?
Why is Information Asset important for compliance?
Which compliance frameworks address Information Asset?
Where can I learn more about Information Asset?
See how Information Asset applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.