The organisation should maintain a Critical Asset Register for hardware and software assets that affect the functionality of its system or influence how PII and other sensitive information is stored or handled.
The register should document each asset’s name, unique ID, version, identifying characteristics, owner and location where applicable. It should also describe component relationships and dependencies, and classify each asset’s relevance to confidentiality, integrity, availability and accountability of user activity.