Build an asset inventory
How to build a complete inventory of all assets requiring protection in the “Assets” view: create assets, review the system landscape as a table or tree, and distinguish assets from the data processing systems of the data protection view.
A complete asset inventory is the basis of every ISMS: without an inventory of the assets requiring protection, neither protection requirements nor measures can be determined in a traceable manner. This article shows how to open the “Assets” view, record your assets and distinguish them from data processing systems.
Prerequisites
- Your team has a licence for information security (ISMS).
- You have the permission to view assets (
assets). - To create, edit or delete, you also need the respective appropriate permission.
Open the overview
- Switch the toggle at the top of the “Main navigation” from “DSMS” to “ISMS”. The toggle appears only if your team is licensed for both areas.
- In the left menu, click the category “Control” and then the entry “Assets”.
- Use the toggle at the top right to choose the display: “Table” for the list view with columns, filters and bulk actions, or “Tree” for the hierarchical display based on “Parent asset” and “Subordinate assets”.
Record assets
- Click the “New” button at the top right.
- Select one of the options: “Create asset” for an empty asset, “Load from sample documents” for a pre-filled sample system (for example typical merchandise management, CRM or HR applications), or “Create linked document” to link the new asset to an existing entry as the source.
- Complete the input form and save it.
- Repeat the process until all IT systems, applications, data sets and business processes are recorded.
Review the inventory
- Narrow the list using the “Search term” field, or click “Filter” to expand the filter area – with filters such as “Protection requirements” (“Not rated”, “Normal”, “High”, “Very high”, “Not established”), “Contains AI components” and “Categorisation”.
- The “Protection requirements” column is the central control feature of the information security view. Filter on “Not rated” to find gaps in your inventory.
- Use “Columns” to display additional columns such as “Parent asset”, “Data fields” or “Follow-up on”.
- Save frequently needed filter and sort combinations using the “Views” selection menu. Saved views apply separately to each view.
Distinguishing assets from data processing systems
The views “Assets”, “Data processing systems” and “AI systems” access the same data set but display different subsets:
- “Assets” is the complete set – every recorded system appears here.
- An asset marked using the “Relevant to data protection” field also appears as a “Data processing system” in the data protection view.
- An asset with “Contains AI components” also appears as an “AI system”.
From a regulatory perspective, the asset inventory forms the basis of common standards such as BSI IT baseline protection and ISO/IEC 27001.
Practical tip: create a complete inventory in the assets view first. If you mark an asset as “Relevant to data protection” as soon as personal data is affected, it automatically also appears as a data processing system – there is no need to record it twice. Use the “All my organizations” button at the top right to switch specifically to a subsidiary if you want to review only its system landscape.
Changes and errors may occur. The information in this article has been carefully compiled, but does not claim to be complete or correct.