Assets

One inventory,
your control scope.

Keep an inventory of what you protect, organized into asset classes you define, each asset with an owner, CIA ratings and an active or retired status. The inventory is the scope your controls apply to, so coverage is measured against a real estate rather than an assumed one.

Start for freeBook a conversation
++++
app.devguard.ch / assets
1,284 tracked
1,284
+12
assets tracked
By type
Cloud612
Code repos448
Endpoints138
Databases86
Search assets…
CloudAll types
AssetTypeOwnerStatus
prod-api-clusterCloudJDTracked
acme-app/webRepoAKTracked
customers-dbDatabaseMRNew
edge-cdn-euCloudJDTracked
laptop-fleetEndpointTSTracked
Every framework
ISO/IEC 27001ISO/IEC 27002SOC 2SOC 1GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018ISO/IEC 27701ISO 9001ISO 14001ISO 45001Swiss nFADP
ISO/IEC 27001ISO/IEC 27002SOC 2SOC 1GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018ISO/IEC 27701ISO 9001ISO 14001ISO 45001Swiss nFADP
ISO/IEC 27001ISO/IEC 27002SOC 2SOC 1GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018ISO/IEC 27701ISO 9001ISO 14001ISO 45001Swiss nFADP
ISO/IEC 27001ISO/IEC 27002SOC 2SOC 1GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018ISO/IEC 27701ISO 9001ISO 14001ISO 45001Swiss nFADP
  • ISO/IEC 27001
  • ISO/IEC 27002
  • SOC 2
  • SOC 1
  • GDPR
  • HIPAA
  • PCI DSS v4.0.1
  • NIST CSF 2.0
  • EU AI Act
  • NIS2 Directive
  • DORA
  • OWASP
  • ISO/IEC 42001
  • CIS Controls
  • Cloud Controls Matrix
  • ISO/IEC 27017 & 27018
  • ISO/IEC 27701
  • ISO 9001
  • ISO 14001
  • ISO 45001
  • Swiss nFADP
How it works

Track it, own it, scope it.

One inventory of asset classes you define, each asset owned and rated, that your controls apply to.

01

Track every asset

Add assets into asset classes you define, whether that’s cloud, repositories, databases or endpoints, each asset with an owner, CIA ratings and an active or retired status. You decide what belongs in scope, so nothing important sits unaccounted for.

02

Own it and rate it

Every asset has an owner and CIA ratings for confidentiality, integrity and availability, so the people accountable and the sensitivity of each asset are clear instead of buried in a long list.

03

This inventory is your scope

Your controls apply to the assets in this inventory, and retiring an asset takes it out of scope. What you protect is defined here, so coverage means coverage of a real estate, not an assumed one.

The inventory is the scope

Your controls map to the assets in this inventory, so when coverage says a control is met, it’s met against the estate you actually track, not a list you hope is complete.

Why it’s built this way

Built to be the real scope.

Four choices behind how the inventory works here, each one something you can check, not an adjective.

01

Controls apply to this inventory

Your controls map to the assets you track here, so coverage is measured against a real estate rather than an assumed one.

02

Asset classes you define

You organize the inventory into your own asset classes, whether that’s cloud, repositories, databases or endpoints, instead of being boxed into a fixed set of types.

03

Every asset has an owner, ratings and a status

Each asset carries an owner, CIA ratings and an active or retired status, so who’s accountable and what’s still in scope is clear rather than guessed.

04

Retired assets leave the scope

Mark an asset retired and it drops out of your control scope, so the inventory reflects what you run today instead of drifting out of date between audits.

Swiss-hosted, yours to export.

Hosted in Switzerland by default, in German and English, with on-premise possible. Your data is yours, with CSV export of your inventory and no lock-in.

See the full feature comparison

One module of the platform

Where assets connect.

Assets are one module; the inventory is the scope the rest of the workspace builds on, from the risks an asset carries to the coverage measured against it.

2.0SCORE

Risks

Tie a risk to the assets it threatens, scoped from this inventory.

AWAWSReviewed
CFCloudflareReviewed
StStripe

Vendors

Connect the third parties behind the assets you track.

coverage86%

Coverage

See control coverage measured against the assets in your inventory.

342
artifacts captured
linked to controls

Evidence

Attach proof to the asset the control applies to.

FAQ

The questions evaluators ask.

What kinds of assets can I track?

You define your own asset classes, so the inventory holds whatever fits your estate, whether that’s cloud, repositories, databases or endpoints. Each asset has an owner, CIA ratings and an active or retired status.

Does devguard discover my cloud assets automatically?

No. Assets are tracked in the inventory by you, so what’s in scope is what you’ve decided is in scope. There’s no automatic AWS, Azure or GCP sync, and that’s deliberate: your control scope reflects the estate you’ve accounted for, not whatever a scan happened to find.

How do assets relate to my controls?

The inventory is the scope your controls apply to. When coverage reports a control as met, it’s met against the assets you actually track, so coverage reflects a real estate rather than an assumed one.

How is this different from an asset spreadsheet or another GRC tool?

In a spreadsheet, an asset is a row disconnected from the controls meant to protect it. Here, the inventory is the scope your controls map to, each asset has an owner, CIA ratings and an active or retired status, so what you protect and what your controls cover stay the same list.

Where’s the data hosted, and can I export it?

Swiss-hosted by default, in German and English, with on-premise possible. Your data is yours, and you can export your inventory to CSV, so there’s no lock-in.

Make your inventory the scope your controls map to.

Track your assets in one inventory, organized into classes you define, each owned and rated, and let your controls apply to a real estate. Coverage you can stand behind starts with the assets you actually track.

Start for freeBook a conversation
Sign in
Start for free
Book a conversationStart for free