INTRA/DP/DP001Identification of critical assets
The list of the information, systems, and physical assets whose loss, alteration, or destruction would cause the organization material harm, and the record of who decided that and when. It is the list that is the measure. A program that knows in principle what matters, and cannot produce the list, does not hold it.
| Control | Jurisdiction | Source | What it establishes | Prerequisite or recommendation |
|---|---|---|---|---|
| DP001/EUMandatory | European Union | Directive (EU) 2022/2555, article 21European Parliament and Council · read 29 Aug 2026 | That asset management, access control policies, human resources security, cryptography, and training are among the measures an entity in scope has to take, without saying what any of them holds. | Asset management is named among the measures an entity in scope has to take, alongside access control policies and human resources security in the same point. What the identification covers, and how far it goes, is left to the state of the art. |
