A System Asset refers to any component, whether hardware, software, network, or information system, that is essential to the operation and security of an organisation. This includes servers, databases, applications, network devices, and other infrastructure components that store, process, or transmit information.
The classification of a System Asset in Secure Arc's Cybersecurity Office is derived from the classification of the Information Assets that it is responsible for protecting. The security controls that must be applied to these System Assets are inferred from the threats applicable to the System Asset and the value derived from its associated Information Assets. This approach is based on the guidelines provided by NIST
FIPS 199 and
FIPS 200.