N.1.06.02 Overview of ICT assets
Control Overview
This control requires the organization to maintain a complete, accurate, and continuously updated inventory of all physical, virtual, and cloud-based ICT assets (including servers, data storage systems, and firewalls). To prevent security incidents caused by unmanaged, "shadow," or unpatched infrastructure, every asset or logical asset group must have a designated manager or owner responsible for its maintenance and protection. The inventory must detail asset locations, descriptions, and configurations to serve as a reliable foundation for vulnerability and patch management.
Applicability Note: This control is fully applicable to the anDREa platform, encompassing its SaaS/PaaS infrastructure, client environments, and internal company hardware.
Compliance & Strategic Approach
Our approach integrates ICT asset management into our ISO/IEC 27001-based ISMS, aligning physical assets, internal operational profiles, and live customer cloud deployments under unified governance.
Because anDREa operates primarily in a cloud-native SaaS/PaaS model, our asset tracking is highly automated. We manage physical assets through structured inventory lists, while virtual infrastructure and tenant assets are monitored in real time. Crucially, tracking is simplified by our architecture: we maintain a "single version/patch level in operation" model for the core platform. For customer-specific environments, we utilize dynamic configurations to map and track specialized parameters, such as network rules or custom software deviations, ensuring that no virtual asset exists without an explicit owner and a known baseline state.
Control Mappings & Evidence
| Framework / Document Reference | Element & Identifier | Description / Relationship to NIS 2 |
|---|---|---|
| ISO 27001 | A.05.09 - Inventory of information and other associated assets | Mandates the identification, cataloging, lifecycle tracking, and explicit assignment of ownership for all ICT assets. |
| Internal Asset Platform | anDREa People - Asset Overview | The central internal repository managing core corporate hardware, software licenses, and digital profiles. |
| Physical Registry | Inventory List & Inventory Valuation | Documented and regularly updated registry of corporate physical property, procurement tracking, and active hardware states. |
| Cloud Monitoring Platform | myDRE Insights Platform Telemetry | Live administrative console providing detailed visibility, per-client resource breakdown, virtual machine (VM) statuses, access logs, and real-time cloud resource consumption. |
| Configuration Management | Tenant Configurations | Active technical registry tracking per-customer operational parameters, non-default network rules, firewalls, and specific software versions/patch levels. |
| Architectural Standard | myDRE Highlevel Architecture | Strategy documentation proving the platform-wide deployment policy that keeps all core instances on a single, continuously patched version, mitigating legacy asset sprawl. |
Audit Summary
- Compliance Status: Fully Compliant
- Gaps Identified: None. Virtual, physical, and customer-tenant asset tracking workflows are fully formalized, mapped to explicit owners, and actively maintained.