Cyber Assessment Framework
The CAF is a collection of cyber security guidance for organisations that play a vital role in the day-to-day life of the UK, with a focus on essential functions.
Pages
Page 7 of 25
Principle A3 Asset Management

Appropriate organisational structures, policies, processes and procedures in place to understand, assess and systematically manage security risks to network and information systems supporting essential functions.
Principle
Everything required to deliver, maintain or support networks and information systems necessary for the operation of essential functions is determined and understood. This includes data, people and systems, as well as any supporting infrastructure (such as power or cooling).
Description of principle
In order to manage security risks to the network and information systems supporting essential functions, organisations require a clear understanding of what needs to be protected including service dependencies. This understanding might include physical assets, software, data, essential staff and utilities. These should all be clearly identified and recorded so that it is possible to understand what things are important to the delivery of the essential function and why.
Guidance
Whichever risk management method your organisation uses, asset management will play a key role as you cannot effectively manage risks without understanding what assets are part of the essential function. Your asset management regime should consider all relevant assets, and dependencies between them. Dependencies may be identified between assets under your organisation's control (including IT and OT domains), elements of the supply chain (including power), and key staff who are critical to operations. Assets in an operational technology environment may need a more tailored approach than the corporate IT assets.
For asset management to be effective, up to date knowledge of your assets must be maintained throughout their lifecycle.
-
ISO/IEC 27001/2
Asset management is part of an ISO 27001 Information Security Management System (ISMS), but management of critical assets may require a tailored approach.
If your organisation is using an ISMS as a tool for compliance with cyber regulation, you must ensure the scope includes all systems relevant to the operation of the essential function covered by the regulation. Asset management is a key part of an ISMS, although critical services may need more attention than the minimum requirements of the standard.
-
ISO 55001 - Asset management
This standard aligns with ISO 27001 and can be used in conjunction with it or independent of it. It outlines requirements for a generic asset management system. An organisation following this standard as a tool for compliance with cyber regulation must ensure the scope encompasses all the relevant systems. The standard covers needs and expectations of stakeholders, which must include any requirements from regulators.
-
Information Technology Infrastructure Library (ITIL)
ITIL is an IT service management framework that outlines best practices for delivering IT services. It recommends a staged approach to IT Asset Management (ITAM). You may find this useful for improving management of your IT assets, but must keep in mind that there may be assets and dependencies beyond the corporate IT domain as outlined above.
A3.a Asset Management
| Not achieved | Achieved |
|---|---|
| At least one of the following statements is true: | All the following statements are true: |
Inventories of assets relevant to the essential function(s) are incomplete, non-existent, or inadequately detailed. Only certain domains or types of asset are documented and understood. Dependencies between assets are not understood (such as the dependencies between IT and OT). Information assets, which could include personally identifiable information and / or important / critical data, are stored for long periods of time with no clear business need or retention policy. Knowledge critical to the management, operation, or recovery of the essential function(s) is held by one or two key individuals with no succession plan. Asset inventories are neglected and out of date. | All assets relevant to the secure operation of essential function(s) are identified and inventoried (at a suitable level of detail). The inventory is kept up-to-date. Dependencies on supporting infrastructure (e.g. power, cooling etc) are recognised and recorded. You have prioritised your assets according to their importance to the operation of the essential function(s). You have assigned responsibility for managing all assets, including physical assets, relevant to the operation of the essential function(s). Assets relevant to the essential function(s) are managed with cyber security in mind throughout their lifecycle, from creation through to eventual decommissioning or disposal. |
Additional information
- NPSA Identify your Most Valuable Assets
- RITICS Asset management within ICS / OT environments
- RITICS Visibility for ICS / OT environment asset management
- RITICS A manual approach to asset management in ICS / OT environments
- RITICS Resolving anti-patterns in ICS / OT environments
- ISO/IEC 27001
- ISO 55001 (to be replaced by ISO/FDIS 55001)
- ITIL
- NIST SP800-82
- ISO/IEC 27019