Asset (Optional)

 

The following table details the validation rules for Asset fields related to Cyber risk.

 

Please note that while the entire table is optional, if you choose to use it, some fields are mandatory.

Mandatory fields are highlighted. For your convenience, the table is sortable by column head.

 

Field

Description

Validation Rules

Default Value

Data Type

Mandatory/ Optional

Common Core

Asset SID

Unique, system-generated  asset identifier

 

N/A

String

Mandatory

 

Organization SID

Unique, system-generated  organization identifier.

 

N/A

Integer

Mandatory

 

Asset ID

Unique, user defined asset identifier

Can contain up to 100 characters

N/A

String

Optional

 

Asset Type Code

Asset type

       UNK (Unknown)

       DB (Database)

       PA (Paper)

       PHY (Physical)

       CMP (Computer)

       SVR (Server)

       LPT (Laptop)

       MOB (Mobile)

       USB (USB Storage)

       OTH (Other)

Note: "Physical assets" are not computers but can be controlled by computers; e.g., security systems, lights, heating controls, etc.

Must be one of the following values:

       UNK

       DB

       PA

       PHY

       CMP

       SVR

       LPT

       MOB

       USB

       OTH

N/A

String

Mandatory

 

Business Interruption Cost

Daily cost incurred from temporarily losing access to this asset

Can contain up to 100 characters

Must be numeric values

Unknown

Float

Optional

 

Recovery Cost

Cost to recover asset

Can contain up to 100 characters

Must be numeric values

Unknown

Integer

Optional

 

Street

Street on which this location is located

Can contain up to 255 characters

Unknown

String

Optional

 

City

City in which this location is located

Can contain up to 255 characters

Unknown

String

Optional

 

Geography SID

Unique, system-generated identifier.

 

N/A

Integer

Mandatory

 

Country Code

Code for the country in which the asset is located

2 or 3 letter code must come from this list:

Country Codes

 

You may also use the code "ZZ" to indicate unknown country or territory

Unknown

String

Optional

Yes

Country Name

Name of the country in which the asset is located

 

Unknown

String

Optional

 

Cresta Code

Code for the CRESTA zone in which this location is located.

 

When entering CRESTA codes, aggregate locations to one location record (with the appropriate number of risks) for each unique combination of CRESTA, construction, occupancy, etc. Whenever possible, avoid having one location for each risk in a CRESTA zone.

 

The Catastrophe Risk Evaluating and Standardizing Target Accumulations organization is an independent body for the technical management of natural hazard coverage. See www.cresta.org for more information about this organization.

 

For lists of the CRESTA codes for each supported country, see the topic, "CRESTA and Area Codes" in the Reference section of the Exposure Data Validation Reference.

Can contain up to 15 characters

Unknown

String

Optional

 

CRESTA Name

Name of the CRESTA zone in which this location is located

Can contain up to 255 characters

Unknown

String

Optional

 

Area Code

Code for the area (state) in which this location is located

 

For lists of the area codes for each supported country, see the topic, "CRESTA and Area Codes" in the Reference section of the Exposure Data Validation Reference.

Can contain up to 15 characters

Unknown

String

Optional

 

Area Name

Name of the area (state)

Can contain up to 255 characters

Unknown

String

Optional

 

Subarea Code

Code for the subarea in which this location is located

Can contain up to 15 characters

Unknown

String

Optional

 

Subarea Name

Name of the subarea in which this location is located

Can contain up to 255 characters

Unknown

String

Optional

 

Postal Code

Postal code of the postal area in which this location is located

Can contain up to 15 characters

Unknown

String

Optional

 

Postal Name

Name of the postal area in which this location is located

Can contain up to 255 characters

Unknown

String

Optional

 

Subarea 2 Code

Code for sub area in which this location is located (for use with Japan, Mexico, and New Zealand)

Can contain up to 15 characters

Unknown

String

Optional

 

Subarea 2 Name

Name of the sub area in which this location is located (for use with Japan, Mexico, and New Zealand)

Can contain up to 255 characters

Unknown

String

Optional

 

Latitude

Latitude of the area in which the asset is located

 

Unknown

NUMERIC

Optional

 

Longitude

Longitude of the area in which the asset is located

 

Unknown

NUMERIC

Optional

 

Access Level

Level of access to this asset

Must be one of the following values:

       Unknown

       Limited Organization Access

       Full Organization Access

       Accessible by Individuals Outside of Organization

       Other

Unknown

String

Optional

 

Asset Count

Number of assets in this category

Can contain up to 100 characters

Unknown

Integer

Optional

 

Operating System Type

Type of operating system used on this asset

Must be one of the following values:

       Unknown

       Linux

       Unix

       Ubuntu

       Mac OS

       Apple iOS

       Windows XP

       Windows 7

       Windows 8

       Windows 10

       Android OS

       IBM Mainframe OS

       Other

Unknown

String

Optional

 

Update/Patch Frequency

Identifies the schedule by which the system is updated or patched

Must be one of the following values:

       Unknown

       None

       Daily

       Weekly

       Biweekly

       Monthly

       Quarterly

       Annually

       Other

Unknown

String

Optional

 

Cloud Type

Type of cloud service used:

         AWS (Amazon Web Services)

         IBM (IBM SmartCloud/IBM Cloud)

         MSA (Microsoft Azure)

         NONE (Organization does not use a cloud service)

         OTH (Other)

         PRV (Private)

         RCK (Rackspace)

         SAL (Salesforce)

         UNK (Cloud Type present but Unknown)

         VMW (VMWare)

Must be one of the following values:

       AWS

       IBM

       MSA

       NONE

       OTH

       PRV

       RCK

       SAL

       UNK

       VMW

Unknown

String

Optional

Yes

Remote Access Permitted

Indicates whether remote access is permitted to this asset item

Must be one of the following values:

       Unknown

       No

       Yes with single factor authentication

       Yes, with two factor authentication

       Yes, with multifactor authentication

Unknown

String

Optional

 

Physical Security Measures

Indicates whether the Organization has physical security measures in place for assets like data centers/servers and rooms, e.g., access cards, retina scanner, fingerprint scanner etc.

Must be one of the following values:

       Unknown

       No

       Yes with single factor authentication

Unknown

String

Optional

 

Encryption Quality Score

Score assigned based on the quality of the encryption being used

 

See the Quality Score Rubric to determine a score.

Must be one of the following values:

       Unknown

       None

       Poor

       Below Average

       Average

       Above Average

       Excellent

       Other

Unknown

String

Optional

 

Antivirus Quality Score

Score assigned based on the quality of the antivirus service/product being used

 

See the Quality Score Rubric to determine a score.

Must be one of the following values:

       Unknown

       None

       Poor

       Below Average

       Average

       Above Average

       Excellent

       Other

Unknown

String

Optional

 

Firewall Quality Score

Score assigned based on the quality of the firewall service/product being used

 

See the Quality Score Rubric to determine a score.

Must be one of the following values:

       Unknown

       None

       Poor

       Below Average

       Average

       Above Average

       Excellent

       Other

Unknown

String

Optional

 

Application Security Score

Score assigned based on the quality of the Application Security

 

See the Quality Score Rubric to determine a score.

Must be one of the following values:

       Unknown

       None

       Poor

       Below Average

       Average

       Above Average

       Excellent

       Other

Unknown

String

Optional

 

Data Update Frequency

Frequency at which the data on this asset is updated

Must be one of the following values:

       Unknown

       None

       Daily

       Weekly

       Biweekly

       Monthly

       Quarterly

       Annually

       Other

Unknown

String

Optional

 

 

© 2016 AIR Worldwide. All rights reserved.