Information Assets

The register of the information your organisation holds — each entry carrying a confidentiality classification, a lifecycle status, a data category and a retention period.

An information asset is anything that holds or processes data worth protecting: a customer database, a payroll spreadsheet, a document store. This register is where you write those down and grade how sensitive each one is, so that risk and data-protection work can point at real, named things. It sits in the Assets (CMDB) group of the left menu, alongside machines, software, services and external services. CMDB stands for Configuration Management Database: the record of what your organisation runs and relies on.

This register is maintained by hand. There is no discovery agent and no import file for information assets today — you add each one through the form on this screen, and correct it through the same form.

Who uses it

Everyone with access to the CMDB module can read the register. What you may change depends on your role:

Role What they can do here
Viewer Read the register, search and filter it, and reload it with Refresh. Neither Add Information Asset nor the Actions column is shown.
Contributor Everything a Viewer can do, plus add new assets and edit existing ones. This is the role used for the screenshot below.
Manager As Contributor. A Manager also holds the delete permission for information assets, but no delete control appears on this screen — see "Tips and limits" below.
Admin Full access to every information-asset permission.

What's on this screen

The screen is one long page: a header, a row of three filters, the table, and a pagination row beneath it. There is no side panel and no separate detail page — an asset's full record opens in a dialog when you edit it.

The capture below is a staging tenant holding two placeholder records, Test and Test 2 reporting — enough to show the table, the badges and the row actions, but not a real register. Walk the screen in this order to get your bearings:

  1. Open the Assets (CMDB) group in the left menu and choose Information Assets. The group expands to show the sibling inventories — CMDB, Software, CMDB Services, External Services and SBOM — with this page highlighted.
  2. Look to the top right for Add Information Asset — the only way to create one. If you cannot see it, your role does not carry the create permission.
  3. Read a row left to right: name, classification pill, status, data category, and the date the record last changed. The Edit button at the end reopens that asset in a form.
  4. Below the table, the count tells you how many assets match the filters now applied, not how many exist. Clear the filters to see the whole register.
  5. To the right of the count, Previous and Next move through the pages, with Page 1 of 1 between them. Both are greyed out when everything fits on one page, as here.
The Information Assets register with two seeded records — /cmdb/information.
The Information Assets register with two seeded records — /cmdb/information.

Add an information asset

The create form opens as a dialog over the register. Only the name is required; everything else can be filled in later through Edit.

  1. Select Add Information Asset. A dialog titled Add Information Asset opens with the fields laid out in two columns.
  2. Type the asset's Name — the placeholder suggests the style, "e.g. Customer Database". Use the name your colleagues use; the register sorts on it.
  3. Choose the Classification. It opens on Internal; the other choices are Public, Confidential and Restricted.
  4. Choose the Status. It opens on Active; use Inactive, Archived, Decommissioned or Unknown where the asset is no longer in daily use.
  5. Fill in Data Category — a free-text label for the kind of data held, such as "Customer PII". It is a text field, not a list, so agree your vocabulary first.
  6. Enter Retention period (days) as a whole number of days: five years is 1825. Anything that is not a whole number is refused with "Retention period must be a whole number of days". Leave it blank if no period has been agreed.
  7. Add Tags as a comma-separated list, for example gdpr, critical. Tags are searchable, so they group assets that share a treatment.
  8. Write the Description and any Notes. Both are free text; the description is searched, so put the identifying detail there.
  9. Select Add Information Asset at the foot of the dialog. The dialog closes, the register reloads, and the new asset takes its place in name order — on a register longer than one page, that may be a page you are not looking at. Choosing Cancel instead discards everything you typed.
You become the owner, and names must be unique

There is no owner field on the form: the asset is recorded against the person who created it. If the name matches an asset that already exists, the dialog stays open and shows "An information asset with this name already exists" — change the name and submit again.

Correct an asset

Editing uses the same form, opened over the row you chose and pre-filled from the saved record.

  1. Find the row and select Edit at the end of it. A dialog titled Edit Information Asset opens with every field carrying its current value; tags appear as a comma-separated list.
  2. Change what needs changing — usually the classification after a review, or the status when an asset is retired. Nothing is written until you save, so closing the dialog leaves the record as it was.
  3. To clear a value, empty the field. Clearing Tags or Retention period (days) in the editor removes the stored value rather than leaving the old one in place.
  4. Select Edit at the foot of the dialog to save. The dialog closes, the register reloads, and the row's Last Updated date moves to today. If you have renamed the asset to a name another asset already uses, the dialog stays open and shows "An information asset with this name already exists".

Find an asset in the register

The three filters combine — a search term, a classification and a status all narrow the same query. Changing any of them returns you to the first page.

  1. Type into Search information assets.... The list refreshes shortly after you stop typing, matching on name, description and data category, and on an exact tag.
  2. Open All Classifications and pick one level to see only assets graded at it.
  3. Open All Statuses and pick a lifecycle value — for example Decommissioned, to review what has been retired.
  4. If the empty-state panel appears, your combination matched nothing. Widen the filters or clear the search box to bring the rows back.
  5. Select Refresh to re-run the current query without changing it — worth doing if a colleague has been editing the register while you have had it open.

Classification and status

Two columns use a fixed vocabulary. Classification answers "how sensitive is the data in this asset?"; status answers "where is this asset in its life?"

Classification Use it when
Public The information can be shared openly with no harm.
Internal For staff use; not intended for release outside the organisation.
Confidential Sensitive; limited to the people who need it for their work.
Restricted The most sensitive grade; access tightly controlled and recorded.
Status Meaning
Active In use.
Inactive Not currently in use, but retained.
Archived Kept for the record only.
Decommissioned Retired from service.
Unknown No status established yet.

Tips and limits

Where this connects