GOV-014 Asset Inventory
Description
An inventory of information assets and their associated processing systems is maintained with designated owners for each asset. Each asset carries a criticality rating derived from the services that depend on it, set at defined points in its lifecycle and reviewed when its dependencies or its use change. The inventory is updated when assets are added, modified or decommissioned, and reviewed at defined intervals.
Rationale
Controls cannot be applied to assets the organisation does not know about, so the inventory is the prerequisite for classification, access control and risk scoping. Ownership says who decides about an asset; criticality says how much the organisation loses if it fails, which is the input recovery prioritisation, tier assignment and incident triage all need and none of them can derive from an owner name. Deriving the rating from dependent services rather than from the asset's own importance keeps it from being a self-assessment.
Applicability (9 profiles)
164.310(d)(2)(iii) asks for a record of the movements of hardware and electronic media and the person responsible for each. GOV-014 records an owner and a lifecycle state, which is not a movement log.
Framework Mappings (17)
| DCS-06 | Assets Classification | informative |
| GRC-05 | Information Security Program | informative |
| DCS-06 | Assets Classification | informative |
| GRC-05 | Information Security Program | informative |
| HIPAA-164.308.a.1.ii.A | Risk Analysis | informative |
| HIPAA-164.308.a.7.ii.E | Applications and Data Criticality Analysis | informative |
| HIPAA-164.310.d.1 | Device and Media Controls | informative |
| HIPAA-164.310.d.2.iii | Accountability | partial |
| 5.9 | Inventory of information and other associated assets | full |
| NIS2-Art.21.2.i | Human Resources Security, Access Control and Asset Management | informative |
| NIS2-CIR-12.1 | Asset Classification | informative |
| NIS2-CIR-12.4 | Asset Inventory | partial |
| NIS2-CIR-5.2 | Directory of Suppliers and Service Providers | informative |
| CM-8(1) | System Component Inventory | Updates During Installation and Removal | full |
| PM-5 | System Inventory | full |
| RA-9 | Criticality Analysis | partial |
| SA-15(3) | Development Process, Standards, and Tools | Criticality Analysis | partial |
Evidence (3)
Asset inventory listing information assets and processing systems with designated owners, asset classification, and last-reviewed date.
Example: Asset inventory (Vanta / Drata asset register, CMDB in ServiceNow, or maintained spreadsheet) showing: asset ID, asset name, type, owner (named individual or team), classification, and last review date, reviewed within the last 12 months.
Test: Export the asset inventory. Verify: (1) all production systems and critical data stores are represented, (2) each entry has a named owner, (3) the inventory has a last-reviewed date within the defined interval, (4) recently onboarded systems appear, cross-referenced against a sample of infrastructure, (5) decommissioned assets are removed or marked inactive, (6) each entry carries a criticality rating and the date it was last set.
Cloud infrastructure discovery scan or CSPM output confirming that discovered assets match the asset inventory.
Example: Cloud asset inventory export from AWS Config, GCP Asset Inventory, or Azure Resource Graph, dated within the last 30 days, cross-referenceable against the organisation's asset register.
Test: Run or request the latest cloud asset discovery output. Cross-reference a sample of cloud resources against the asset register. Verify: (1) no production cloud assets are absent from the inventory, (2) each cloud asset has a tagged or documented owner, (3) the discovery report is dated within 30 days.
Criticality assessment records for the assets rated most critical, showing the dependent services the rating rests on and the lifecycle point at which it was set.
Example: Criticality assessments, tier-1 assets, reviewed 2026-06-30
Test: Request the criticality assessments for the most critical assets. Verify: (1) the rating scheme and its levels are defined, (2) each sampled rating names the services that depend on the asset rather than asserting importance, (3) the rating was set at one of the defined lifecycle points rather than retrospectively, (4) an asset whose dependencies changed during the period carries a re-rating, (5) the ratings are consistent with the recovery priorities in the continuity plan.
Questions (3)
Does your organisation maintain a documented inventory of information assets and processing systems, with designated owners for each asset?
The inventory should include all production systems and critical data stores, show a named owner per asset, and have a last-reviewed date within the defined interval.
How does your organisation keep the asset inventory current as assets are added, modified, or decommissioned?
An automated discovery cross-reference or change-management trigger is the most reliable control. The inventory should match live cloud infrastructure within 30 days.
Does each asset in your inventory carry a criticality rating derived from the services that depend on it?
Ownership says who decides about an asset; criticality says how much is lost if it fails. Recovery prioritisation, assurance depth and incident triage all need the second and none of them can derive it from an owner name. Answer yes only where every asset carries a rating, not only the ones someone thought to rate.