Step 2 of 6 · Plan
Inventory What you need to protect.
Protection starts with a list. Here you collect which services you provide and what they rely on.

What it is about
You can only assess the risk to something you know about. If you know that payroll depends on a particular server and an external provider, you can ask what happens when one of them fails. Without an inventory, every risk analysis stays vague.
How you go about it
- You create your most important services, meaning what your customers or citizens actually get from you.
- For each service you record the systems, data, rooms and suppliers it depends on.
- For each entry you set how critical it is and who is responsible for it.
What UniqSuite does for you
- UniqSuite shows the dependencies as an overview. You see at a glance which services hang on a single system.
- Suppliers you enter here are ready later in the supplier check. Nothing needs to be maintained twice.
What you end up with
An inventory with dependencies and owners, the basis for the gap analysis and the risks.
Where the requirements come from
- ISO/IEC 27001, Annex A 5.9: inventory of information and other associated assets
- BSIG section 30(2) no. 9: asset management and access control
The references show where the requirements come from. They do not replace a legal assessment.
How far along are you with this step?
The quick check shows you in two minutes. Or let us show you UniqSuite with your own questions.
