The provider should identify all primary assets, which include key information (data), critical business processes, and essential services that enable the organization's mission or service delivery.
The provider should then assess and document which of the identified primary assets are directly or indirectly involved in the provision, management, or support of the regulated service. Only those assets confirmed as related will be included in the specified scope.
For every primary asset confirmed as related to the regulated service (from step 1.2), the provider should identify and document all supporting assets necessary for its operation. This includes, but is not limited to:
Hardware:
- Servers
- Workstations
- Network devices (routers, switches, firewalls)
- Mobile devices
Software:
- Operating systems
- Applications
- Databases
- Security tools
Network and communication:
- Interconnections
- Cloud services
- Communication links
Personnel:
- Roles and individuals critical to operating or managing the assets/service
Facilities/Environment:
- Data centers
- Offices
- Power supply
- Environmental controls