Information asset
An information asset is any data, resource or component in a digital environment that has real value to an organisation, financial, strategic, operational or reputational. It is the unit everything else in security is measured against.
An information asset is any data, resource or component within a digital environment that carries significant value for an organisation, whether that value is financial, strategic, operational or reputational.
Assets can be tangible, such as files, databases, hardware and software, or intangible, such as intellectual property, trade secrets, confidential client information or commercial strategy.
They are exposed to a range of threats, from attack and data theft to unauthorised access, accidental loss and physical disaster, which is why identifying, evaluating and classifying them is the foundation of managing information security rather than a preliminary step to it.
A worked example
In a financial services company, the information assets might include client databases, card numbers, transaction records, the financial management software itself, and the security policies that govern all of it.
The theft of that information would have consequences for reputation and for the continuity of the business, which is why encryption, multi-factor authentication and access control are applied to it specifically rather than uniformly.
That last word is the point. Applying the same protection everywhere costs more and protects less than applying the right protection where the value is, and you cannot do the second without knowing what you have.
The asset and the inventory
This entry defines what an asset is. The asset inventory is the list they are written down in, and having assets is not the same as having them inventoried.
The useful sentence about the inventory is that you cannot defend what is not on the list: the scope of an audit, patching, monitoring and incident response are all resolved against it.
And what turns up when you measure it: almost no organisation has one list, it has several that disagree. The spreadsheet from the last audit, the cloud provider’s console, the endpoint agent’s console, the directory, and the invoice. Each is complete within its own domain and blind outside it, and the gaps between them are exactly where shadow IT lives and where the unpatched things are.
What makes an inventory useful for security is not how many fields it has. It is that every entry has a named owner and a date on which something automatic confirmed it. Anything only a person updates starts ageing on day one.
Classification is the next step: not all assets are worth the same, and that difference is what decides what gets protected first.
The asset is also the unit risk is measured in. A risk analysis begins by identifying them, and a risk model begins by defining which ones count.
Where to read more
ISO/IEC 27001: the standard for an information security management system, in which asset identification and classification are explicit requirements.
NIST guidance on categorising information and information systems, which is the equivalent approach in the US federal framework.