Assets and vendors
Record assets
Assets holds information assets, applications, infrastructure, locations and other protected objects. Record owner, deputy, protection need, location, lifecycle, technical details and vendors. Add dependencies to keep outages and recovery understandable.

Each asset can link risks, measures, contracts, backups, recovery steps and documents. A protection-need change does not automatically reassess dependent records. Update risks, recovery objectives and measures in the same task.
Assess vendors
Vendors stores contacts, service, criticality, contracts, data protection relevance, security assessment, cancellation dates and reassessment. Link the vendor to the used assets and processing activities.

Track contract end, cancellation period, reminder and reassessment separately. An archived vendor remains available as evidence. Existing links are checked before deletion.
Access requests
Access documents requests for access. A request records its target person, requested rights, justification and approver. Approved requests remain linked to the implemented access as evidence.
