Security inventory #
Overview #
The inventory includes Perimeters, Assets, Threats, Vulnerabilities and Security measures. These catalogs form the context reused by the risk scenarios.
Recommended route #
- Define the scope and its manager.
- Inventory the assets to protect.
- Describe threats and vulnerabilities without duplication.
- Record existing measures and their justified effectiveness.
- Compose the scenarios in the risk register.
Permissions and rules #
All authorized profiles view; Risk manager or higher creates, modifies and deletes. Each relationship is revalidated in the current organization.
Detailed pages #
Perimeters · Assets · Threats · Vulnerabilities · Measures
Inventory governance #
Define an owner per data family, a naming convention, a review frequency and authorized sources. Start small: items actually used in risks are better than a large, outdated catalog.
Quality control #
- each asset belongs to a scope and has a manager;
- threat and vulnerability remain two distinct concepts;
- the severity is justified by a source;
- the effectiveness of a measure is based on proof or a test;
- no object duplicates an existing wording under a minor variant.
Review cycle #
Look for unaccounted for, unused, or old items. Correct the relationships before deletion. After a reorganization, check the scenarios, incidents, continuity, assessments and reports that reuse the inventory.