TechKnowSurge
NIST CSF ID.AM-07 ISC2 CISSP 2.1 NIST 800-53 CM-8 CompTIA Security+ 4.2
VideoSecurityFree

DEMO: Assessments

Asset and data inventory assessments are foundational tools for identifying and prioritizing organizational risk. This content covers how to structure these assessments, assign ownership, and score assets and data based on risk factors and recovery requirements.

Complete this video to capture a CTF flag worth 1 point.

About this video

Asset and data inventory assessments are two of the most practical starting points for understanding an organization's risk exposure. An asset inventory goes beyond a simple equipment list by capturing key identifying details — device type, serial number, physical or remote location, and assigned owner — and then layering in a risk assessment component. Each asset receives a risk factor score expressed as a fraction, and those scores are weighted relative to the full inventory, making it straightforward to rank assets from highest to lowest concern and direct attention where it matters most. A data inventory assessment follows a similar logic but focuses on data sources rather than physical or virtual devices. Each data location is evaluated for recreatability — meaning whether the data could be obtained elsewhere or is unique to the organization, such as proprietary customer records — and assigned an owner and administrator. The assessment also documents Recovery Point Objective, which defines the maximum acceptable data loss measured in time, and Recovery Time Objective, which defines how long recovery is expected to take after an incident. Beyond ownership and recovery metrics, the data inventory scores each source against confidentiality, integrity, and availability, and checks whether the primary data source and its backups — both on-site and off-site — are encrypted. A separate indicator flags whether the organization is currently meeting its stated recovery objectives, with values that reflect whether those targets are being met, doubled, or exceeded in the wrong direction. Taken together, these scores produce a ranked view of data risk that complements the asset assessment, giving security and IT teams a clear, evidence-based picture of where their most critical exposures lie.

What you'll learn

What's covered

Inventory & Assessment Overview

Aligned to

NIST CSF
ID.AM-07 Inventories of data and corresponding metadata for designated data types are maintained.
ISC2 CISSP
2.1 Identify and classify information and assets
NIST 800-53
CM-8 System Component Inventory
CompTIA Security+
4.2 Explain the security implications of proper hardware, software, and data asset management.

Key terms

Asset
Any resource of value to an organization, including hardware, software, data, and personnel.
Risk Assessment
The process of identifying, analyzing, and evaluating risks to determine their potential impact.
Confidentiality
The principle that information is accessible only to those authorized to access it.
Integrity
The assurance that data has not been tampered with and remains accurate and complete.
Availability
The assurance that systems and data are accessible and operational when needed by authorized users.
Recovery Point Objective
RPO
The maximum acceptable amount of data loss measured in time, defining how far back data must be recoverable.
Recovery Time Objective
RTO
The maximum acceptable time to restore a system or service after a disruption.
Recreatability
A data attribute indicating whether lost or damaged data can be reproduced from an external or alternative source.

Topics

Risk Assessment Asset Inventory Data Classification Risk Management Cybersecurity Data Integrity Ownership Tracking

Transcript

I thought it'd be a good idea to get a visual of what one of these assessments may look like. I've got a couple real basic ones, and we're going to start at the asset inventory and assessment.

Asset Inventory and Assessment

The inventory side of it is over here on the left hand side. Maybe we just have the asset name. Maybe we are recording assets by the serial numbers, and so maybe there's some sort of serial number to this machine. And maybe we're recording - maybe this is another desktop, so we've got a desktop, and then it's maybe at a remote location, so we're going to select it.

Really, essentially the inventory side of this is just saying who this is assigned to right now. Maybe the owner is, let's say it's George here, and they're part of the finance team. And so there we have the owner and we've got it logged. Now we can start tracking this device.

The second part of this is more of the assessment side of it, and this is going to be a basic one. We're going to actually learn more about these assessments later on and what they look like. I'm just going to get some numbers in here to begin with, because I don't want to cover it too much. Besides, we're not actually going to be doing assessments of the actual assets; later on we're going to be doing the assessments of an actual risk, and that looks a little different. But this helps us identify what is going to be our more risky assets.

Over here now we have a risk factor that we have for each one of those. This is the factor based out of one, so a fraction of one. We can see this one's getting a little bit up there, it's about halfway there. And then we see a weighted number right here, and that's out of everything that's been assessed so far, where it kind of falls in line. So you can see that this one is the top weighted - that would be our number one concern right there - and this one would be the next one, and then these two come in at a bit of a tie here.

So this is an asset inventory and assessment, and a way that we can track our different assets here and then also do some preliminary investigation on the risk of those.

Data Inventory and Assessment

Here's another assessment that could help out. This is data inventory and assessment. You would add all your data locations here, and if it's recreatable - meaning is it something I could just download from maybe a partner or from some other source, or is it something that we've actually created? Maybe it's customer data that we have created that no one else can really create, it's something that is not recreatable.

And then we might attach an owner to it, an admin to it. We would specify a recovery point objective and a recovery time objective. I'm not going to get into those in this lesson, but the recovery point is how far back we're willing to lose information, and this says only 15 minutes of information to be lost if there was an incident. And then RTO is recovery time, so how long it would take to recover if there was an incident. Once again, we'll go more in depth into that later.

But then in here I'm also going to rate on confidentiality, integrity and availability, similar to the asset assessment that we did. And then, what is the primary source? For instance, this is a SQL database, so is that SQL database encrypted? We're saying yes for that one. Is it backed up on site? Yes. Is the backup encrypted? We've got no for that one. Is there an offsite copy of this? Yes there is. Is it encrypted? Yes it is.

And then are we meeting the recovery point objective or the recovery time objective? If we were meeting it, it would be one; if we're doubling it, it would be two; if we're tripling it, it would be three. So wherever we stand on that.

And then this gives us some values that are associated with this, so that way we can have a bit of an assessment and determine what the hot topics are, where our riskiest levels are from a data inventory standpoint. So this is something that we could do for an assessment to identify the riskiest data that we have.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →