0% found this document useful (0 votes)
19 views19 pages

Data Asset Inventory Template for SIOs

This template is designed to help social impact organizations (SIOs) document their data assets and assess data risk, aiding in the mitigation of potential data breaches. It includes tabs for data asset inventory, risk rating, and a risk rating guide, allowing organizations to start with known data assets and gradually expand their assessments. The process encourages organizations to begin small and recognize the importance of evaluating risk to identify necessary mitigation measures.

Uploaded by

osseyroger.felix
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as XLSX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
19 views19 pages

Data Asset Inventory Template for SIOs

This template is designed to help social impact organizations (SIOs) document their data assets and assess data risk, aiding in the mitigation of potential data breaches. It includes tabs for data asset inventory, risk rating, and a risk rating guide, allowing organizations to start with known data assets and gradually expand their assessments. The process encourages organizations to begin small and recognize the importance of evaluating risk to identify necessary mitigation measures.

Uploaded by

osseyroger.felix
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as XLSX, PDF, TXT or read online on Scribd

What is the purpose of this template?

Often social impact organizations (SIOs) are unsure of where to begin in defining their data risk, ultimately leading to stagnancy in
mitigating data risk. Consider this spreadsheet a starter tool in this process. It was designed to support SIOs in documenting their data
assets, defining the sensitivity of the content within each, and then assessing the level of risk entailed with each data asset in the event
of a data breach.

What can I find in the different tabs?


Tab

Data Asset Inventory

Risk Rating

Risk Rating Guide

How do I get started?

We recommend starting with the data assets you know best. These are typically the data assets that are either critical or commonly use
in your organization. Fill out the Data Asset Inventory for these key data assets. You can always come back another time and add more
data assets after consulting with your colleagues. Once you have completed the columns of the Data Asset Inventory, you can then
move to the Risk Rating tab. Here you will make your assessments and see what risk ratings come of it.

In short, you don't need a comprehensive list of data assets to start this process. Start small, and see the value in assessing risk. You'll
find that the process will quickly lead to you identifying assets that might need risk mitigation measures.
Instructions

of this template?

ganizations (SIOs) are unsure of where to begin in defining their data risk, ultimately leading to stagnancy in
onsider this spreadsheet a starter tool in this process. It was designed to support SIOs in documenting their data
nsitivity of the content within each, and then assessing the level of risk entailed with each data asset in the event

he different tabs?
Description

This template is for creating a data asset inventory. In practice you can use this template to create a list of your
organization's data assets, along with a brief description and the attributes of each asset.

Within this tab, you will go through a process of defining the nature of the data found in each asset and the data's
level sensitivity. Then you will assess the level of risk associated with different forms of data breaches for each
asset.

This tab is meant to help you understand the risk rating levels used in the Risk Rating tab. This information used in
this tab is based on definitions from the NIST Cybersecurity Framework. You can reference this tab when
assessing the potential impact of a data breach in regards to loss of data confidentiality, integrity, and availability.

d?

ng with the data assets you know best. These are typically the data assets that are either critical or commonly used
ill out the Data Asset Inventory for these key data assets. You can always come back another time and add more
ulting with your colleagues. Once you have completed the columns of the Data Asset Inventory, you can then
g tab. Here you will make your assessments and see what risk ratings come of it.

ed a comprehensive list of data assets to start this process. Start small, and see the value in assessing risk. You'll
will quickly lead to you identifying assets that might need risk mitigation measures.
Data Asset Inventory
Foundational Documentation
Data Asset Contents Use Data Steward/Owner

Write how the data asset is Write the role or title of the
Write the name of the data Write a brief description of the
used (i.e. the business person responsible for this
asset in question (ex. content you find within the
purpose) in your organization. data asset.
database, CRM, folder etc.) data asset.

Full list of funding


Regular tracking of
opportunities, along with a
opportunities to grow business
description of relevant
EXAMPLE: Grant and Funding revenue at each stage of the
information (stage, anticipated Director of Business Strategy
Opportunity Tracker opportunity, from when it is
$ values, competition,
identified to when a proposal
timeline, etc.)
is submitted.
Technical Details
Format Location Timeframe Size on Disk

Write where the data is Write the period over which


Write how the asset is stored. Write the approximate size of
stored. (On premises? With a the data was collected,
(ex. CSV, XML, JSON, SQL db, the entire data asset, usually
cloud provider? A remote including start and end date (if
proprietary archive, XLSX, etc.) expressed in MB, GB, TB, etc.
location?) there is one).

Google Sheet stored in Cloud, Google Workspace,


2016 through current date 150 KB
company shared drive physical location unknown
# of Records Last Inventory Update

Write the approximate number of


records contained in the asset, Write when this row of the
expressed in whatever units are Data Asset Inventory was last
most useful (e.g. number of rows, updated.
users, transactions)

Approximately 500 funding


January 2024
opportunities
Data Asset Inventory Risk Rating

Data Asset Users Affected Personally Identifiable Information (PII)

How many people could be affected in the


Does this contain Personally Identifiable
event of a data breach? What types of people?
Information in this column is Information (PII)? If so, briefly describe. PII
Types of people may include users,
linked from the Data Asset may include (but is not limited to) names,
beneficiaries, employees, clients, donors,
Inventory tab. addresses, phone numbers, emails,
business contacts, or anyone else on whom
identification numbers, account numbers, etc.
data is stored.

EXAMPLE: Grant and Funding 20 daily active users, ~100 external business Yes, internal and external business contact
Opportunity Tracker contacts names and email addresses
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
Security Category: How would you rate the imp
Business Sensitive Regulations (if known)
resulting in a... (see Risk Rating Gu

Is this data subject to any external data


Does this contain information that is or privacy protections, laws, or
Loss of Confidentiality
essential to business operations, stability, regulations? If so, state them. These
(the unauthorized disclosure
competitiveness and/or integrity? may differ by location of your
of information)
If so, briefly describe. organization, of your clients, or of your
data centers.

Yes, active and past business activities,


contacts, and revenues No Low
would you rate the impact if there was a data breach Overall Risk
... (see Risk Rating Guide for more info) Rating

Loss of Integrity Loss of Availability


(the unauthorized (the disruption of access to Highest of the
modification or destruction or use of information or an three ratings
of information) information system)

Medium Medium Medium


Risk Rating Guide
POTENTIAL IMPACT

Security Objective LOW MEDIUM HIGH

Confidentiality The unauthorized disclosure of The unauthorized disclosure of The unauthorized disclosure of
Preserving authorized restrictions on information could be expected to information could be expected to information could be expected
information access and disclosure, have a limited adverse effect on have a serious adverse effect on to have a severe or catastrophic
including means for protecting organizational operations, organizational operations, adverse effect on organizational
personal privacy and proprietary organizational assets, or organizational assets, or operations, organizational
information. individuals. individuals. assets, or individuals.

The unauthorized modification


Integrity The unauthorized modification or The unauthorized modification or
or destruction of information
Guarding against improper destruction of information could destruction of information could
could be expected to have a
information modification or be expected to have a limited be expected to have a serious
severe or catastrophic adverse
destruction, and includes ensuring adverse effect on organizational adverse effect on organizational
effect on organizational
information nonrepudiation and operations, organizational assets, operations, organizational assets,
operations, organizational
authenticity. or individuals. or individuals.
assets, or individuals.

The disruption of access to or


The disruption of access to or use The disruption of access to or use
use of information or an
of information or an information of information or an information
information system could be
Availability system could be expected to have system could be expected to
expected to have a severe or
Ensuring timely and reliable access to a limited adverse effect on have a serious adverse effect on
catastrophic adverse effect on
and use of information. organizational operations, organizational operations,
organizational operations,
organizational assets, or organizational assets, or
organizational assets, or
individuals. individuals.
individuals.

Source: FIPS 199, Standards for Security Categorization of Federal Information and Information Systems

Amplifications
A limited adverse effect means that, for example, the loss of confidentiality, integrity, or availability
might: (i) cause a degradation in mission capability to an extent and duration that the organization is
LOW able to perform its primary functions, but the effectiveness of the functions is noticeably reduced; (ii)
result in minor damage to organizational assets; (iii) result in minor financial loss; or (iv) result in
minor harm to individuals.

A serious adverse effect means that, for example, the loss of confidentiality, integrity, or availability
might: (i) cause a significant degradation in mission capability to an extent and duration that the
organization is able to perform its primary functions, but the effectiveness of the functions is
MEDIUM
significantly reduced; (ii) result in significant damage to organizational assets; (iii) result in significant
financial loss; or (iv) result in significant harm to individuals that does not involve loss of life or
serious life threatening injuries.

A severe or catastrophic adverse effect means that, for example, the loss of confidentiality, integrity,
or availability might: (i) cause a severe degradation in or loss of mission capability to an extent and
HIGH duration that the organization is not able to perform one or more of its primary functions; (ii) result
in major damage to organizational assets; (iii) result in major financial loss; or (iv) result in severe or
catastrophic harm to individuals involving loss of life or serious life threatening injuries.

You might also like