Alessandro AleddaInsider Threat and Risk

INTRA/DP/DP001Identification of critical assets

The list of the information, systems, and physical assets whose loss, alteration, or destruction would cause the organization material harm, and the record of who decided that and when. It is the list that is the measure. A program that knows in principle what matters, and cannot produce the list, does not hold it.

Pillar
DP  |  Data and asset protection
Sources cited
1
Added
30 AUGUST 2026
Updated
30 AUGUST 2026
ControlJurisdictionSourceWhat it establishesPrerequisite or recommendation
DP001/EUMandatoryEuropean UnionDirective (EU) 2022/2555, article 21European Parliament and Council · read 29 Aug 2026That asset management, access control policies, human resources security, cryptography, and training are among the measures an entity in scope has to take, without saying what any of them holds.Asset management is named among the measures an entity in scope has to take, alongside access control policies and human resources security in the same point. What the identification covers, and how far it goes, is left to the state of the art.