Categorization criteria include consideration of the degree to which an asset within the function may be leveraged to achieve a threat objective
The possibility of an asset within the function being leveraged to achieve a threat objective is added to the criteria used for categorizing information assets. Consideration for the way an asset may be utilized by a threat actor will enable a more comprehensive prioritization of the risks to, and impacts associated with, IT and OT assets. It is important to consider that a threat actor may have multiple objectives and that those objectives may change over time or in different situations.
Related Practices · Progression: This practice is part of a practice progression. Practice progressions are groups of related practices that represent increasingly complete or more advanced implementations of an activity. The practices in this progression include: ASSET-2c, ASSET-2d.