GASP AICF

Search controls and profiles

Search by control ID, name, domain or profile

GOV-014 Asset Inventory

Tier 1+ProviderDeployerGPAI Model ProviderManaged Service Provider

Description

An inventory of information assets and their associated processing systems is maintained with designated owners for each asset. Each asset carries a criticality rating derived from the services that depend on it, set at defined points in its lifecycle and reviewed when its dependencies or its use change. The inventory is updated when assets are added, modified or decommissioned, and reviewed at defined intervals.

Rationale

Controls cannot be applied to assets the organisation does not know about, so the inventory is the prerequisite for classification, access control and risk scoping. Ownership says who decides about an asset; criticality says how much the organisation loses if it fails, which is the input recovery prioritisation, tier assignment and incident triage all need and none of them can derive from an owner name. Deriving the rating from dependent services rather than from the asset's own importance keeps it from being a self-assessment.

Applicability (9 profiles)

SaaS AI Providerstablerequiredcore
Enterprise AI Deployerstablerequiredcore
GPAI Model Providerstablerequiredcore
High-Risk Provider (EU)stablerequiredcore
Public Body Deployer (EU)stablerequiredcore
DORA ICT Provider (EU)stablerequiredcore
HIPAA Business Associate (US)stablerequiredrole duty

164.310(d)(2)(iii) asks for a record of the movements of hardware and electronic media and the person responsible for each. GOV-014 records an owner and a lifecycle state, which is not a movement log.

NIS2 Cloud Provider (EU)stablerequiredcore

Framework Mappings (17)

DCS-06Assets Classificationinformative
GRC-05Information Security Programinformative
DCS-06Assets Classificationinformative
GRC-05Information Security Programinformative
HIPAA-164.308.a.1.ii.ARisk Analysisinformative
HIPAA-164.308.a.7.ii.EApplications and Data Criticality Analysisinformative
HIPAA-164.310.d.1Device and Media Controlsinformative
HIPAA-164.310.d.2.iiiAccountabilitypartial
5.9Inventory of information and other associated assetsfull
NIS2-Art.21.2.iHuman Resources Security, Access Control and Asset Managementinformative
NIS2-CIR-12.1Asset Classificationinformative
NIS2-CIR-12.4Asset Inventorypartial
NIS2-CIR-5.2Directory of Suppliers and Service Providersinformative
CM-8(1)System Component Inventory | Updates During Installation and Removalfull
PM-5System Inventoryfull
RA-9Criticality Analysispartial
SA-15(3)Development Process, Standards, and Tools | Criticality Analysispartial

Evidence (3)

system_exporttechnicalautomated

Asset inventory listing information assets and processing systems with designated owners, asset classification, and last-reviewed date.

Example: Asset inventory (Vanta / Drata asset register, CMDB in ServiceNow, or maintained spreadsheet) showing: asset ID, asset name, type, owner (named individual or team), classification, and last review date, reviewed within the last 12 months.

Test: Export the asset inventory. Verify: (1) all production systems and critical data stores are represented, (2) each entry has a named owner, (3) the inventory has a last-reviewed date within the defined interval, (4) recently onboarded systems appear, cross-referenced against a sample of infrastructure, (5) decommissioned assets are removed or marked inactive, (6) each entry carries a criticality rating and the date it was last set.

configurationtechnicalautomated

Cloud infrastructure discovery scan or CSPM output confirming that discovered assets match the asset inventory.

Example: Cloud asset inventory export from AWS Config, GCP Asset Inventory, or Azure Resource Graph, dated within the last 30 days, cross-referenceable against the organisation's asset register.

Test: Run or request the latest cloud asset discovery output. Cross-reference a sample of cloud resources against the asset register. Verify: (1) no production cloud assets are absent from the inventory, (2) each cloud asset has a tagged or documented owner, (3) the discovery report is dated within 30 days.

recorddocumentmanual

Criticality assessment records for the assets rated most critical, showing the dependent services the rating rests on and the lifecycle point at which it was set.

Example: Criticality assessments, tier-1 assets, reviewed 2026-06-30

Test: Request the criticality assessments for the most critical assets. Verify: (1) the rating scheme and its levels are defined, (2) each sampled rating names the services that depend on the asset rather than asserting importance, (3) the rating was set at one of the defined lifecycle points rather than retrospectively, (4) an asset whose dependencies changed during the period carries a re-rating, (5) the ratings are consistent with the recovery priorities in the continuity plan.

Questions (3)

boolean

Does your organisation maintain a documented inventory of information assets and processing systems, with designated owners for each asset?

The inventory should include all production systems and critical data stores, show a named owner per asset, and have a last-reviewed date within the defined interval.

select

How does your organisation keep the asset inventory current as assets are added, modified, or decommissioned?

Automated discovery (e.g. CSPM, CMDB sync) with regular reconciliationMandatory update process triggered by change management ticketsPeriodic manual review on a defined scheduleAd hoc updates with no defined processThe inventory is not actively maintained

An automated discovery cross-reference or change-management trigger is the most reliable control. The inventory should match live cloud infrastructure within 30 days.

boolean

Does each asset in your inventory carry a criticality rating derived from the services that depend on it?

Ownership says who decides about an asset; criticality says how much is lost if it fails. Recovery prioritisation, assurance depth and incident triage all need the second and none of them can derive it from an owner name. Answer yes only where every asset carries a rating, not only the ones someone thought to rate.