Asset Management
๐ท Asset Management
"Keep track of what matters most โ your assets and their dependencies."
Brainframe GRC helps you classify, link, and manage assets with their business requirements in mind.
The Inventory Overview already provides a general asset listing.
The Asset Management feature builds on this by letting you record detailed information for each asset, including maximum potential impacts โ all of which feed directly into risk management.
Brainframe GRC distinguishes between:
- Primary assets โ core services, processes, or data critical to your business.
- Supporting assets โ underlying systems/resources that impact the primary assets.
This creates a risk hierarchy and makes dependency chains clear.
1๏ธโฃ Asset Overview
These must always be documented and linked with supporting assets and risks.
2๏ธโฃ Adding or Editing Primary Assets
To create or link a primary asset:
- Go to the Resources menu โ Core Business Assets.
- Click the [+] button.
- Enter the asset name:
- The system searches for similar existing documents.
- You can link an existing document as a primary asset (auto-collects supporting assets + risks).
- Or Create a new document (define type, title, details).
If you create a new asset, here's the view that you will be shown where you can define the document type, the title and other details related to the document type:
The next screen will allow you to configure all the details of your primary assets. The same screen will be shown if you click the update primary asset (L) on the primary asset list screen
From here you can:
- Open the asset document.
- Assign Responsible (R).
- Assign Accountable (A), with optional Consulted (C) and Informed (I).
- Configure which document types auto-link as supporting assets.
- Manually add supporting assets.
- Free text field where you can define Business Requirements (see below).
- Configure which document types auto-link as related risks.
- Manually add related risks.
3๏ธโฃ Business Requirements
Examples aligned with ISO 27001:
- ๐ Confidentiality โ e.g. Personal data must not be accessed by unauthorized users.
- ๐ Integrity โ e.g. Databases must ensure transactional accuracy.
- ๐ Availability โ e.g. Servers must withstand a full outage of 1/3 of data centers.
- ๐ Proof โ e.g. Financial regulator requires daily transaction records.
- โฑ RTO (Recovery Time Objective) โ e.g. Service must be restored within 30 minutes.
- ๐พ RPO (Recovery Point Objective) โ e.g. Data must be restorable to at least 24 hours before incident.
- โ Regulatory โ e.g. EU data processing requires GDPR compliance.
4๏ธโฃ Asset Creation Behaviour Configuration
When first adding an asset, youโll define where new items are stored:
- In a new โAsset Inventoryโ folder under INBOX, or
- In a specific folder you choose.
5๏ธโฃ Adding or Editing Supporting Assets
Supporting assets assist the primary one and may impact it if disrupted.
- In Core Business Assets, click the pen or [+] next to the primary asset.
- Link an existing document or Create a new one.
- Select the type, fill in the details, and the asset will be linked.
6๏ธโฃ Adding Existing Assets as Primary Assets
Any document can be upgraded to a primary asset:
- Click the three dots next to the document.
- Select Add to โ Add as primary asset.
7๏ธโฃ Asset List View
Switch to List View for an Excel-like layout of all assets.
From here you can:
- Create a new primary asset.
- Filter the asset list.
- Load additional risk information like properties and last readings, and add a color to the different risks.
- Configure the columns that are shown and export to Excel.
- Click the asset name to open it.
- Track and select checklist stage (Kanban).
- View RACI roles.
- Check all linked tasks.
- Review supporting assets.
- See linked documents.
- Review Business Requirements.
- Check related risks.
8๏ธโฃ Best Practices
- ๐ Keep assets structured in dedicated folders.
- ๐ Always link supporting assets to ensure dependency visibility.
- ๐งฎ Define business requirements early to align with ISO and resilience needs.
- โ Map regulatory requirements (GDPR, NIS2, DORA) to relevant assets.
๐ฏ Visual Checklist
- [x] Primary assets documented
- [x] Supporting assets linked
- [ ] Business requirements defined
- [ ] Risks connected to assets
- [ ] Exported list view for auditors
Updated on: 05/09/2025
Thank you!