Skip to content
Asset Register

Register  ·  Security

What Incident Response Needs From Asset Data

The questions asked in the first hour of an incident are asset questions, and organisations without a register spend that hour building one.

Reference  ·  666 words

An incident begins with a set of questions about what exists. If the answers require investigation, the investigation happens while the incident continues.

The first-hour questions

What is this system and what does it do?

Who owns it?

What data is in it?

Who has access?

Who are the administrators?

What can it reach, and what can reach it?

Is the vendor's status known and who is our contact?

What is our contractual notification position with them?

Every one of these is a register field. Organisations that maintain them answer in minutes; organisations that do not spend the first hours reconstructing.

The device questions

Which devices belong to the affected user?

Are they encrypted?

Are they enrolled in management, and can we wipe or isolate them?

When did each last check in?

Who else uses them?

The access questions

What did this account have access to?

Was that access unusual for the role?

What other accounts does this person hold, including local and non-federated ones?

What integrations run as this account?

What did they own that will break if we disable it? This one determines whether containment causes a second incident.

Preparing in advance

Keep the register current, which is the whole argument.

Draw the integration map, so the blast radius question has an answer.

Record vendor contacts and notification terms per application, so nobody is reading a contract at two in the morning.

Tag applications by data sensitivity, so triage can prioritise.

Maintain the administrator lists, since compromised administrator access is the worst case and the list tells you what that means here.

Keep an offline copy. A register held only in a system that may itself be affected is unavailable exactly when needed.

The offline copy specifically

A periodic export of the register, held somewhere reachable if your main systems are not.

Including: applications, owners, data classifications, vendor contacts, administrator lists, and the integration map.

Refreshed on a schedule and tested by someone actually retrieving it.

This is a small discipline that separates a manageable incident from one where the response team cannot see the estate.

After the incident

Update the register with what was learned. Incidents reveal applications, integrations and access that discovery missed.

Feed the gaps back into discovery. If an incident involved an application nobody knew about, the question is which discovery source should have found it.

Record the response as evidence.

Review the blast radius and reduce it where the incident showed it was larger than assumed.

The honest position

Asset data does not prevent incidents.

It changes how long the first phase takes, and the first phase is where containment either happens or does not. That is a narrow claim and it is the reason security functions should care about a register that otherwise looks like a finance exercise.

What the offline copy should contain

A register held only in systems that may themselves be affected is unavailable exactly when needed.

The application list with owners, data classifications and vendor contacts.

Administrator lists per application.

The integration map.

Contractual notification terms per vendor.

Device counts by type, with encryption status.

Key contacts: legal, insurer, external response support if retained.

Exported monthly, held somewhere reachable without your primary identity provider, and tested by having someone actually retrieve it.

A PDF on an encrypted drive is adequate. The requirement is availability, not sophistication.

The tabletop that uses the register

Testing whether asset data actually supports response, which is different from having it.

Pick an application holding meaningful data.

Ask the eight first-hour questions and time how long each takes to answer.

Anything taking more than a few minutes is a gap, and the gap is a register field or a join.

Test with the primary systems assumed unavailable, which is what forces the offline copy to be real.

Include the integration map question: what else is exposed.

Run it annually, and after any material change to the estate or the tooling. The exercise finds problems that reading the register never will.