> For the complete documentation index, see [llms.txt](https://intuitem.gitbook.io/ciso-assistant/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://intuitem.gitbook.io/ciso-assistant/concepts/assets-and-resilience/assets.md).

# Assets

An **asset** is anything of value worth protecting. Assets are first-class objects in CISO Assistant, decoupled from any specific risk study or audit, so the same asset can participate in many analyses without being duplicated.

Assets are always defined by the organisation and can be attached to the global domain or to a specific domain.

## Mental model

```mermaid
graph LR
  D[Domain] -->|scopes| A[Asset]
  A -->|supports| A
  RS[Risk scenario] -->|impacts| A
  V[Vulnerability] -->|affects| A
  I[Incident] -->|affects| A
  BIA -->|assesses| A
```

The asset is a hub other surfaces point at: risk scenarios impact it, vulnerabilities affect it, incidents affect it, and a Business Impact Analysis assesses it (through an intermediate `AssetAssessment` row, one per asset in the BIA). The `supports` self-loop captures the primary/support hierarchy — a support asset is recorded as a child of its primary parent through `parent_assets`.

| User-facing   | Internal                 | Notes                                      |
| ------------- | ------------------------ | ------------------------------------------ |
| Asset         | `Asset`                  | First-class; primary vs support via `type` |
| Domain        | `Folder`                 | Required; drives IAM scoping               |
| Risk scenario | `RiskScenario`           | Lives inside a `RiskAssessment`            |
| Vulnerability | `Vulnerability`          | First-class                                |
| Incident      | `Incident`               | First-class                                |
| BIA           | `BusinessImpactAnalysis` | Bridges to assets via `AssetAssessment`    |

## Primary vs supporting assets

* **Primary assets** are core resources directly contributing to the organisation's main objectives — business processes, data, intellectual property.
* **Supporting assets** indirectly aid primary functions — IT systems, services, locations, people.

The distinction matters for risk work: scenarios typically express *what can happen to a primary asset* via *which supporting assets are involved*.

<figure><img src="https://629777851-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FCqFeU3oPCgDWkkR386NK%2Fuploads%2Fgit-blob-2a84db86dbf70f069f4e8c770017deccf85d09f1%2Fassets-list.png?alt=media" alt=""><figcaption><p>Primary and supporting assets in one list, separated by the Type column</p></figcaption></figure>

## Related

* [Asset classes](/ciso-assistant/concepts/assets-and-resilience/asset-classes.md)
* [Risk assessments](/ciso-assistant/concepts/risk/risk-assessments.md)
* [Vocabulary → Asset](/ciso-assistant/introduction/vocabulary.md)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://intuitem.gitbook.io/ciso-assistant/concepts/assets-and-resilience/assets.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
