How do I Approach Asset Identification Within My Information Security Risk Assessment?

|
|
|
PUBLISHED on
20
July
2022
Article Summary

This is a question which comes up time and time again.  Typically, this question is twofold; which assets to include and the depth or granularity.  In this blog, we will look at granularity.

‍

In short, stay high-level where possible.  Your goal, through the risk assessment, is to identify and then manage your risks in terms of confidentially, integrity and availability (CIA).  If you start with an asset list pages long, perhaps by taking an extract from IT’s configuration management database (CMDB), your results are going to be pages long.  With this level of detail, you will find yourself spending a significant amount of time trying to consolidate risks into a manageable number.  You can always go down into additional detail where an asset has a different CIA value.  For example, if you have laptops which store, process or transmit information, then you need to include these in your assessment.  However, you do not need to include every make and model in your assessment or even group laptops by every department.  We should group these by the levels of information they have access to.  So ‘Laptops’ could be used to cover most staff members’ laptops, as they all have access to the same level of information.  You can then use ‘Sensitive Laptops’ for laptops that are used by your senior management team or HR, as these laptops will typically have a higher level of access to information.

By grouping these assets, you reduce the number of duplicated results in your risk assessment and get a more detailed and manageable representation of risk.  Also, if the controls are likely to be deployed consistently across all assets, then there may be no benefit to splitting assets into subcategories. For example, if all laptops will be encrypted and have similar endpoint controls (e.g., antivirus, firewalling), then rating the asset as a worst case will be appropriate.

So, think about what that asset ultimately holds or has access to and approach your asset with that in mind!

Do you need any help with ISO 27001 certificate?

URM can help you achieve ISO 27001 certification
Thumbnail of the Blog Illustration
Information Security
Published on
14/7/2026
The Fundamentals of Risk Management in ISO 27001

URM’s blog explains the risk management requirements in ISO 27001, including identifying ISMS risk, risk assessment and treatment, documentation and more

Read more
Thumbnail of the Blog Illustration
Information Security
Published on
1/2/2024
What is the CIA Security Triad? Confidentiality, Integrity and Availability Explained

URM’s blog explains how the principles of confidentiality, integrity and availability (CIA) can help align your information security controls with best practice

Read more
Thumbnail of the Blog Illustration
Information Security
Published on
3/7/2026
ISO 27001 Clause 8.1: Effective ISMS operational planning and control

URM’s blog explains the requirements of ISO 27001 Clause 8.1 and why it matters, as well as sharing key insights on how to properly implement it in practice.

Read more
We are extremely grateful for the outstanding support the URM Team provided throughout our Cyber Essentials and Cyber Essentials Plus journey. Their professionalism, technical expertise, and pragmatic guidance were key to our successful certification. We would like to call out a personal thanks to our assessor, who was particularly impressive throughout. From the initial assessment through remediation and validation, he demonstrated clear expertise, practical recommendations, and strong communication. This, coupled with his thoroughness, responsiveness, and collaborative approach, made the process efficient for our whole team.
contact US

Let us help you

Let us help you in your compliance journey by completing the form and letting us know how we can best support you.