Asset Management

Supplier Security Management

Description Before engaging in an agreement with a supplier of an IT-service, an information security risk assessment is performed. Contractual agreements regarding information security are made with suppliers of IT-services....

Software Bill-of-Materials

Description The organisation must know what software is used on managed devices, including a Software “Bill-of-Materials” (BOM) of libraries and components. Specification Use of automated scripts and tooling to identify...

Domain reservations

Description Domain names reserved for organisational purposes cannot be released shortly after the domain name is no longer needed. A list of domain names that can never be released needs...

Security in projects and changes

Description Planned changes are evaluated for potential security impact. The classification of all processes and systems involved in the change is reviewed and adjusted where necessary. In projects, sufficient resources...

Emergency updates

Description Emergency changes requiring immediate implementation are properly handled to ensure minimal impact on systems and IT applications. The emergency change is registered, evaluated and tested after implementation and approved...

Patch management

Description Available patches and/or security fixes are installed in compliance with set and approved policies (including those for operating systems, databases and installed applications) and recommendations of CERT and/or suppliers....

Detection of assets

Description Organisations actively and passively detect assets that may not be registered in the CMDB, both within the network and outside. Discrepancies in CMDB and detected assets are resolved. Specification...

Asset registration

Description The assets making up a system that are under control of the organisation are registered and tracked in the CMDB. System owners periodically check that the information in the...

Asset inventory

Description Organisations maintain an accurate and up-to-date registry of organisational hardware and software assets in a Configuration Management Database (CMDB). Specification Organisationally owned assets are registered with their relevant attributes,...

Governance of Processes and Systems

Description The Information Systems and Processes are identified and registered. Each System and Process has an owner within the organisation. The owner is responsible for compliance with the organisational information...