This document is under active development and has not been finalized.
Skip to content

Asset Inventory

Purpose

The asset inventory records all information technology systems, components and processes of the BAUER GROUP. It provides the foundation for risk analysis and enables the assignment of protective measures to specific assets.

Asset Categories

Server Systems

AttributeDescription
Hostname / IDUnique identification
TypePhysical / Virtual / Container
LocationData center, provider
Operating systemIncluding version and patch level
PurposeProduction, staging, backup
ResponsibleAssigned administrator
Protection requirementNormal / High / Very High

Network Components

  • Firewalls with ruleset version and last review date
  • Switches and routers with firmware version
  • VPN gateways and access points
  • DNS servers and load balancers

Applications

AttributeDescription
Name / VersionApplication with current version
TypeIn-house development / Third-party / SaaS
LicenseLicense type and expiry date
SupportSupport status and contact
Data classificationWhich data classes are processed
DependenciesOther systems, libraries, APIs

Cloud Services

  • Provider with location and legal jurisdiction
  • Contract term and SLAs
  • Data classification of stored data
  • Exit strategy and data portability

Data Assets

ClassificationStorage LocationBackupEncryption
PublicAnyOptionalOptional
InternalAccess-controlledYesIn transit
ConfidentialAccess-controlled + encryptedYes + encryptedAt rest + in transit
Strictly ConfidentialIsolated + encryptedYes + encrypted + offsiteAt rest + in transit + audit

Maintenance Schedule

ActivityInterval
Inventory updateUpon every change (deployment, decommissioning)
Completeness checkSemi-annually
Protection requirement assessmentAnnually or upon change
Responsibility reviewUpon personnel change

Documentation licensed under CC BY-NC 4.0 · Code licensed under MIT