Skip to main content
MuonPartners
Services
Architecture

Solution design and technology roadmapping

Solution AssessmentTechnology RoadmapsIntegration DesignSolution ArchitectureTechnical Design
Cyber Security

Security assessments, IAM, and compliance

AssessmentsIAMComplianceSecurity BaselineCyber Innovation
Network and Platform

Network architecture and cloud platforms

Network DesignCloud StrategyModernisation
Enterprise Architecture

Business-technology alignment

Business AlignmentPortfolio AnalysisGovernance
View all services
ProjectsCase StudiesInsightsToolsAbout
Contact Us

Services

Architecture
Solution AssessmentTechnology RoadmapsIntegration DesignSolution ArchitectureTechnical Design
Cyber Security
AssessmentsIAMComplianceSecurity BaselineCyber Innovation
Network and Platform
Network DesignCloud StrategyModernisation
Enterprise Architecture
Business AlignmentPortfolio AnalysisGovernance
ProjectsCase StudiesInsightsToolsAboutContact
Get in Touch
MuonPartners

Strategic technology consulting for Australian organisations navigating complexity.

Services

  • Architecture
  • Cyber Security
  • Network and Platform
  • Enterprise Architecture

Company

  • About
  • Products
  • Frameworks
  • Cross-Framework Mapping
  • Projects
  • Case Studies
  • Insights
  • Contact

Contact

  • [email protected]
  • Australia
  • LinkedIn

© 2026 Muon Partners. All rights reserved.

ABN 50 669 022 315 · A Muon Group company.

Privacy PolicyTerms of Service
  1. Frameworks
  2. >AESCSF
  3. >ASSET
  4. >ASSET Anti-Patterns
  5. >AESCSF-ASSET-AP2
AESCSF-ASSET-AP2Active

The management of asset inventories is not linked to data governance or business impact assessment activities (ASSET-...

Statement

The management of asset inventories is not linked to data governance or business impact assessment activities (ASSET-1a, PRIVACY-AP1)

Context and Guidance: Asset inventories are used as a source of truth to support other business activities. If your organisation has not established asset inventories (i.e., ASSET-1a is "No"), this Anti-Pattern is "Present".

The management of your asset inventories should be linked to data governance or business impact assessment (BIA) activities, to provide confidence that the inventories contain accurate and complete information.

Data governance ensures that your organisation knows what types of data it holds / processes, so that the risk associated with holding / processing that data can be appropriately managed.

BIAs support you in determining which assets the organisation considers to be critical and/or sensitive.

Knowing the types of data your organisation has, how important it is, and where it is stored, is critical to understanding how a threat actor may target your organisation to achieve a threat objective.

PRIVACY-AP1 must be "Not Present" for this Anti-Pattern to be "Not Present".

Location

Domain
ASSET
Objective
ASSET Anti-Patterns

Practice Details

Identifier
AESCSF-ASSET-AP2
Type
Anti-pattern
Domain
ASSET
Objective
ASSET Anti-Patterns

Maturity Level

MIL-1MIL-2MIL-3

Security Profile

SP-1SP-2SP-3
ISM
ISM-1602relatedvia aescsf-reference
ISM-1211relatedvia aescsf-reference
View in graphReport an issue
← Back to ASSET Anti-Patterns
ASSET Anti-Patterns3 controls
AESCSF-ASSET-AP1Changes to Internet-facing assets are not assessed or tested to identify potential cybersecurity vulnerabilities aris...AESCSF-ASSET-AP2The management of asset inventories is not linked to data governance or business impact assessment activities (ASSET-...AESCSF-ASSET-AP3Asset inventories have not been updated in the past 24 months