-
Notifications
You must be signed in to change notification settings - Fork 2
Specs M2 Assets Essential Asset
Claude edited this page Aug 28, 2026
·
1 revision
assets.models.essential_asset.EssentialAsset
Business process or type of information essential to the organization, the compromise of which would have a significant impact.
Represents a business process or a type of information essential to the organization, the compromise of which would have a significant impact.
| Field | Type | Constraints | Description |
|---|---|---|---|
id |
UUID | PK, auto-generated | Unique identifier |
scope_id |
relation | FK → Scope, required | Attached scope |
reference |
string | required, unique | Reference code (e.g. BE-001) |
name |
string | required, max 255 | Essential asset name |
description |
text | optional | Detailed description |
type |
enum | required |
business_process, information
|
category |
enum | required | See list below |
owner_id |
relation | FK → User, required | Essential asset owner |
custodian_id |
relation | FK → User, optional | Custodian / operational manager |
confidentiality_level |
enum | required |
negligible (0), low (1), medium (2), high (3), critical (4) |
integrity_level |
enum | required |
negligible (0), low (1), medium (2), high (3), critical (4) |
availability_level |
enum | required |
negligible (0), low (1), medium (2), high (3), critical (4) |
confidentiality_justification |
text | optional | Justification of the confidentiality level |
integrity_justification |
text | optional | Justification of the integrity level |
availability_justification |
text | optional | Justification of the availability level |
max_tolerable_downtime |
string | optional | Maximum tolerable downtime (MTD) |
recovery_time_objective |
string | optional | Recovery time objective (RTO) |
recovery_point_objective |
string | optional | Recovery point objective (RPO) |
data_classification |
enum | optional |
public, internal, confidential, restricted, secret
|
personal_data |
boolean | required, default false | Contains personal data |
personal_data_categories |
json | optional | Personal data categories (GDPR) |
regulatory_constraints |
text | optional | Specific regulatory constraints |
related_activities |
relation | M2M → Activity | Associated business activities (Module 1) |
supporting_assets |
relation | M2M → SupportAsset (via AssetDependency) | Associated support assets |
status |
enum | required |
identified, active, under_review, decommissioned
|
review_date |
date | optional | Next review date |
created_by |
relation | FK → User | Creator |
created_at |
datetime | auto | Creation date |
updated_at |
datetime | auto | Last modification date |
Essential asset categories (values of category):
-
Type
business_process:core_process,support_process,management_process -
Type
information:strategic_data,operational_data,personal_data,financial_data,technical_data,legal_data,research_data,commercial_data
Note: The categories must be configurable by the administrator.
Built from docs/ at v0.36.0. Edits made here are overwritten by the next release : open a pull request against the source instead.
- Administration
- Ask Cairn
- Assets and suppliers
- Compliance
- The dashboard
- Finding your way
- Getting started
- Incidents
- How records move
- Organisational context
- Reports and management review
- Risks
- Trust Center
- Architecture
- Configuration
- Contributing
- The documentation system
- Installation
- Internationalisation
- Operations
- Release process
- Security
- Testing
- Adding an assistant provider
- Adding a dashboard widget
- Adding a domain entity
- Declaring a lifecycle
- Adding an MCP tool
- Adding a REST endpoint
- Adding a report
- Interface conventions
- Dashboard widgets
- Lifecycles
- MCP tools
- MCP tool parameters : Assets
- MCP tool parameters : Compliance
- MCP tool parameters : Governance and context
- MCP tool parameters : General
- MCP tool parameters : Incidents
- MCP tool parameters : Reports and management review
- MCP tool parameters : Risks
- MCP tool parameters : System and administration
- MCP tool parameters : Trust Center
- Management commands
- Models
- Permissions
- REST endpoints
- Environment variables
- MCP server
- REST API
- Assistant module (Ask Cairn)
- Module 0: User Management and Access Control
- Module 1: Context and Organization
- Module 2: Asset Management
- Module 3: Compliance
- Module 4: Risk Management
- Module 4 bis - EBIOS Risk Manager
- Module 5 : Trust Center
- Module 6 : Security Incident Management
- Management review : ISO 27001:2022 compliance (clause 9.3)