DOC-020 ← Document Portal

Information Asset Register

Central register of systems, data and infrastructure covered by the ISMS
Document Number
DOC-020
Version
▸ 1.0
Status
DRAFT
Issue Date
▸ DD/MM/YYYY
Owner
▸ CISO / IT Administrator
Approved by
▸ Board / CEO
Legal Basis
Art. 21(2) NIS2; ISO/IEC 27001:2022 A.5.9; ISO/IEC 27005
Related Documents
DOC-002 | DOC-010 | DOC-011

1. Register Management Principles

  • Each asset is assigned to an owner responsible for its security and classification.
  • Register updated on every change: addition, removal or significant modification of an asset.
  • Full register review at least once every ▸ [12 months]min. 1×/year.
  • Register serves as input to the risk assessment process (DOC-002/003) and continuity planning (DOC-011).

2. IT System Register

Key IT/OT systems covered by the ISMS – organisation completes for each system

IDSystem nameTypeDescription / Function Data classificationCriticality (1–5) RTORPO Business ownerIT Admin LocationUpdate date
▸ SYS-001 ▸ [e.g. Active Directory] ▸ [IT / OT / Cloud] ▸ [Identity and access management] ▸ [SECRET] ▸ 5 ▸ [e.g. 1h] ▸ [e.g. 15 min] ▸ [First Last Name] ▸ [First Last Name] ▸ [Main server room] ▸ DD/MM/YYYY
▸ SYS-002 ▸ [e.g. ERP / SAP system] ▸ [CONFIDENTIAL]
▸ SYS-003 ▸ [e.g. OT / SCADA system] ▸ OT ▸ [SECRET] ▸ 5
▸ SYS-004

3. Key Data Sets Register

IDDataset nameDescriptionClassification Personal data (GDPR)LocationRetentionOwner
▸ DAT-001 ▸ [e.g. CRM customer data] ▸ CONFIDENTIAL ▸ YES ▸ [database + backup] ▸ [X years]per GDPR / purposes
▸ DAT-002

4. Privileged Account Register

List of accounts with administrative privileges – updated on every change. Access to register: CISO and IT Administrator only.

SystemAccount namePermission typeAssigned toMFALast review date
▸ [Active Directory] ▸ [Domain Administrator] ▸ [Domain Admin] ▸ [First Last Name] ▸ YES (FIDO2) ▸ DD/MM/YYYY

Change History

VersionDateAuthorDescriptionApproved by
▸ 1.0▸ Initial release▸ Board
DOC-020 Information Asset Register | v1.0 | NIS2/ISMS