Skip to content

Asset management

See a change before four registers drift apart.

KaitoSec gives IT, security, privacy and continuity the same inventory of systems, processes, data, vendors and AI components, with clear ownership and visible dependencies.

Where friction starts today

Nobody can secure an inventory they only half know

Ask three teams for a list of systems and you get three different answers. IT has a spreadsheet, security has a slightly older one, and the privacy team keeps its record of processing somewhere else entirely. None of them agree on what counts as critical, who owns it, or what data runs through it. Every audit starts with a week of reconciling lists that should have been one list all along.

The inventory is where everything else starts. Classification, risk scoring, business impact analysis, your GDPR record of processing, the register of AI systems: all of it reads from the same set of assets. Keep four copies and they drift apart by the next quarter. Keep one and a change to an asset shows up everywhere it matters, the first time you make it.

One data model

What you enter here, the other modules already know

Modules are views on the same record, not separate databases. A change made here is the change every other module reads, with no export step and no second entry.

A change in this module is written to the shared data model, which the other modules read immediately.

This module

Asset Management

Shared data model

One asset, one risk, one control, one piece of evidence

  • Risk ManagementCurrent at once
  • Business ContinuityCurrent at once
  • Compliance MappingCurrent at once

Entry to evidence

Every change carries its own proof

An auditor rarely asks what the register says today. They ask who changed it, when, and on what basis. That trail is written while the work happens, so nothing has to be reconstructed at the end of the year.

One change writes its previous value, its owner and its date, and surfaces in the management report, the audit evidence and the customer questionnaire.

One change

A risk is re-assessed

Written with it

  • Previous value and version
  • Person responsible
  • Date and reason

Where it surfaces

  • Management report
  • Audit evidence
  • Customer questionnaire

What changes for your team

01

Capture operational context once

Hardware, software, cloud services, data stores and AI components live in one structured register with owner, classification, lifecycle and dependencies. The record powers control selection, BIA, RoPA and AI governance at the same time.

02

Anchor processing activities to real systems

Your record of processing activities sits in the same register as your IT assets. Personal data flows are linked to the systems and vendors that process them, so Article 30 compliance is a view of your operation, not a separate spreadsheet.

03

Derive affected work from one change

Each asset carries the risks it introduces, the controls that protect it, the vendors that touch it and the continuity dependencies it creates. When an asset changes, KaitoSec surfaces the impact on every management system that cared about it.

The workflow

01

Assess protection needs and business criticality together

Document confidentiality, integrity and availability under ISO 27001 or BSI Grundschutz and add business criticality for the BCMS. Risk assessment and recovery then use the same justified classification.

02

Bring existing inventories under control

Import current CSV inventories and add data from connected source systems. Review duplicates, ownership and classification before a technical discovery becomes a defensible business record.

03

Vendor and data-flow mapping

Link assets to the vendors that supply or process them and visualise data flows across the organisation. The same view supports GDPR scoping, NIS2 supply-chain obligations and DORA ICT third-party reporting without separate diagrams.

FAQ

What types of assets can KaitoSec track?

Hardware (servers, endpoints, network), software (on-premises and SaaS), cloud infrastructure (IaaS, PaaS), data stores, AI systems and models, plus organisational assets such as processes, services and locations. Custom asset types extend the model where you need them.

How does the record of processing activities work?

Processing activities live in the same register as the IT assets that perform them. Each activity carries data categories, legal basis, recipients and responsible team, and is linked to the underlying systems and vendors. Changes to an asset surface on the activities it feeds, so the RoPA never drifts.

Can we import an existing asset spreadsheet?

Yes. A CSV import with field mapping brings in the existing inventory. You then review owners, classification and links to risks, controls and continuity dependencies.

How does asset management support BSI Grundschutz?

The asset register maps directly to BSI IT-Grundschutz target-system modelling. Grundschutz modules can be assigned to asset groups and the required documentation is generated from the model, with the same data feeding ISO 27001 mapping where both frameworks are in scope.