Categorisation criteria include consideration of the degree to which an asset within the function may be leveraged to achieve a threat objective
Context and Guidance: The possibility of an asset within the function being leveraged to achieve a threat objective is added to the criteria used for categorising information assets. Consideration for the way an asset may be utilised by a threat actor will enable a more comprehensive prioritisation of the risks to, and impacts associated with, IT and OT assets. It is important to consider that a threat actor may have multiple objectives and that those objectives may change over time or in different situations.
Related Practices • Progression: This practice is part of a practice progression. Practice progressions are groups of related practices that represent increasingly complete or more advanced implementations of an activity. The practices in this progression include: ASSET-2c, ASSET-2d.