MLchartDataset catalogue

Asset

Term · Cybersecurity · MLC-T-CYB-000244

1. A distinguishable entity that provides a service or capability. Assets are people, physical entities, or information located either within or outside the United States and employed, owned, or operated by domestic, foreign, public, or private sector organizations.

2. An item of value to the achievement of organizational mission/business objectives. Note 1: Assets have interrelated characteristics that include value, criticality, and the degree to which they are relied upon to achieve organizational mission/business objectives. From these characteristics, appropriate protections are to be engineered into solutions employed by the organization. Note 2: An asset may be tangible (e.g., physical item such as hardware, software, firmware, computing platform, network device, or other technology components) or intangible (e.g., information, data, trademark, copyright, patent, intellectual property, image, or reputation).

3. An item of value to stakeholders. An asset may be tangible (e.g., a physical item such as hardware, firmware, computing platform, network device, or other technology component) or intangible (e.g., humans, data, information, software, capability, function, service, trademark, copyright, patent, intellectual property, image, or reputation). The value of an asset is determined by stakeholders in consideration of loss concerns across the entire system life cycle. Such concerns include but are not limited to business or mission concerns.

4. Anything that has value to a person or organization.

5. Anything that has value to an organization, including, but not limited to, another organization, person, computing device, information technology (IT) system, IT network, IT circuit, software (both an installed instance and a physical instance), virtual computing platform (common in cloud and virtualized computing), and related hardware (e.g., locks, cabinets, keyboards).

6. Resources of value that an organization possesses or employs.

7. Anything that can be transferred.

8. The data, personnel, devices, systems, and facilities that enable the organization to achieve business purposes.

Table 1. Record
IdentifierMLC-T-CYB-000244
FieldCybersecurity
ReferencesCNSSI 4009-2022 from DoDD 3020.40; CNSSI 4009-2022; NIST SP 800-160 Vol. 2 Rev. 1; NIST SP 800-160v1r1 from ISO/IEC/IEEE 24765:2017; NISTIR 7693; NISTIR 7694; NISTIR 8011 Vol. 1; NISTIR 8202; NISTIR 8286 from NIST Cybersecurity Framework Version 1.1; NIST CSRC Glossary
Record as JSON
{
  "id": "MLC-T-CYB-000244",
  "term": "Asset",
  "field": "Cybersecurity",
  "definition": "1. A distinguishable entity that provides a service or capability. Assets are people, physical entities, or information located either within or outside the United States and employed, owned, or operated by domestic, foreign, public, or private sector organizations.\n\n2. An item of value to the achievement of organizational mission/business objectives. Note 1: Assets have interrelated characteristics that include value, criticality, and the degree to which they are relied upon to achieve organizational mission/business objectives. From these characteristics, appropriate protections are to be engineered into solutions employed by the organization. Note 2: An asset may be tangible (e.g., physical item such as hardware, software, firmware, computing platform, network device, or other technology components) or intangible (e.g., information, data, trademark, copyright, patent, intellectual property, image, or reputation).\n\n3. An item of value to stakeholders. An asset may be tangible (e.g., a physical item such as hardware, firmware, computing platform, network device, or other technology component) or intangible (e.g., humans, data, information, software, capability, function, service, trademark, copyright, patent, intellectual property, image, or reputation). The value of an asset is determined by stakeholders in consideration of loss concerns across the entire system life cycle. Such concerns include but are not limited to business or mission concerns.\n\n4. Anything that has value to a person or organization.\n\n5. Anything that has value to an organization, including, but not limited to, another organization, person, computing device, information technology (IT) system, IT network, IT circuit, software (both an installed instance and a physical instance), virtual computing platform (common in cloud and virtualized computing), and related hardware (e.g., locks, cabinets, keyboards).\n\n6. Resources of value that an organization possesses or employs.\n\n7. Anything that can be transferred.\n\n8. The data, personnel, devices, systems, and facilities that enable the organization to achieve business purposes.",
  "references": [
    "CNSSI 4009-2022 from DoDD 3020.40",
    "CNSSI 4009-2022",
    "NIST SP 800-160 Vol. 2 Rev. 1",
    "NIST SP 800-160v1r1 from ISO/IEC/IEEE 24765:2017",
    "NISTIR 7693; NISTIR 7694",
    "NISTIR 8011 Vol. 1",
    "NISTIR 8202",
    "NISTIR 8286 from NIST Cybersecurity Framework Version 1.1",
    "NIST CSRC Glossary"
  ],
  "url": "https://mlchart.com/terminology/cybersecurity/asset/"
}

Record 243 of 4,669 in Cybersecurity terminology (MLC-0102). Request the full dataset.