Intangible asset

An asset with no physical form, such as data, software, intellectual property, trade secrets or reputation, valued by what its loss or disclosure would cost rather than by a price tag.

An intangible asset has value but no physical substance. For a security programme the common examples are information, software and licences, intellectual property such as patents, copyrights and trade secrets, and the organisation’s brand and reputation. Accounting takes a narrower view: IAS 38 defines an intangible asset as an identifiable non-monetary asset without physical substance, which leaves out reputation that cannot be separated from the business. Security practice uses the broader sense, because a breach can damage reputation as well as data. The ISC2 exam outline gives tangible and intangible as its examples under asset inventory in objective 2.3.

The pair to keep straight is intangible and tangible asset. A tangible asset can be counted, tagged and valued at replacement cost; an intangible one often cannot, so its value is usually estimated from the harm its loss or disclosure would cause, and that estimate feeds asset classification and risk analysis. Both belong in the asset inventory with an owner assigned.

Exam relevance: a scenario may ask which asset is most valuable, or how to value an asset that has no purchase price. Candidates are expected to treat data, intellectual property and reputation as assets in their own right, and to value them by the impact of their loss rather than by the cost of the device that carries them.