Assets and vendors

Record assets

Assets holds information assets, applications, infrastructure, locations and other protected objects. Record owner, deputy, protection need, location, lifecycle, technical details and vendors. Add dependencies to keep outages and recovery understandable.

Asset overview with protection need and owners

Each asset can link risks, measures, contracts, backups, recovery steps and documents. A protection-need change does not automatically reassess dependent records. Update risks, recovery objectives and measures in the same task.

Assess vendors

Vendors stores contacts, service, criticality, contracts, data protection relevance, security assessment, cancellation dates and reassessment. Link the vendor to the used assets and processing activities.

Vendor list with assessments and deadlines

Track contract end, cancellation period, reminder and reassessment separately. An archived vendor remains available as evidence. Existing links are checked before deletion.

Access requests

Access documents requests for access. A request records its target person, requested rights, justification and approver. Approved requests remain linked to the implemented access as evidence.

Access requests with approval status