Asset classification
Grouping assets such as systems, devices and facilities by value, sensitivity and criticality, so that the controls, monitoring and recovery priority each receives match its importance.
Asset classification assigns each asset, whether hardware, software, a facility or a service, to a category that reflects how much it matters to the organisation. The ISC2 outline lists it beside data classification under objective 2.1. The usual inputs are the asset’s value, the sensitivity of the information it stores or processes, and its criticality to operations.
The two classifications are linked but not identical. Data classification labels information; asset classification labels the things that store, process or carry it. A common rule is that an asset takes the level of the most sensitive data it holds, the high water mark principle. US federal practice reaches a similar result through security categorisation: FIPS 199 rates potential impact on confidentiality, integrity and availability as low, moderate or high, and NIST SP 800-60 maps information types to provisional impact levels. Classification depends on a complete asset inventory and on an asset owner who confirms the category.
Exam relevance: questions in this area tend to turn on sequence. An asset cannot be classified until it has been inventoried, and controls cannot be chosen proportionately until it has been classified. Candidates are also expected to recognise that a cheap server holding highly sensitive data takes the level of that data, not of its purchase price.