Information Asset and Data Classification Register
v2.0
Purpose. This register lists the information assets Nova holds or manages, their owners, classification and the controls that protect them.
1.Purpose of the register
The information security management system requires Nova to know what information it holds, who owns it and how sensitive it is. This register is the master list and drives access reviews, backup priorities and breach assessments. It is maintained by the Business Services Manager with the Cyber Security Lead.
2.Classification levels
Public information can be shared freely. Internal information is for Nova staff only. Confidential information includes client configurations, contracts and staff records and must be access controlled. Restricted information includes credentials, client personal information, health and financial data and must be encrypted, logged and limited to named roles.
- Public
- Internal
- Confidential
- Restricted
3.What is recorded
Each asset entry records the asset name, description, owner, location or system, classification, retention period, backup arrangement and the date last reviewed. Client environments are recorded as one asset each with a link to the site documentation.
4.Current entries
The register currently holds 212 assets, including the password vault, the ticketing platform, the documentation platform, the monitoring platform, source code repositories, finance and payroll systems, staff records, and one entry for each of the 140 managed client environments.
5.Adding and changing entries
New systems and new clients must be added before they go live. Owners must confirm their entries at the annual review, and assets no longer held must be marked as disposed with the date and the disposal method.
6.Review
The register will be reviewed annually and sampled at each internal audit.