Know What You Have. Understand What Matters. Prove You’re in Control.

CQ IT AssetPortfolioAsset RegisterData ProfileClassificationReview
Asset record
Business Application
CriticalityTier 1 · CriticalApproved
Data sensitivityRestrictedCurrent
Accountable ownerAssigned
Analyst reviewComplete
RecertificationCurrent
What It Is

A governed classification layer for IT assets.

CQ IT Asset Classification structures the business and security context required to classify each asset and maintain an approved record over time.

Asset context

Connect the asset to the business.

Record purpose, organizational context, ownership, and related business processes.

Classification

Assess criticality and data sensitivity.

Apply CIAT impact assessment, data profiling, recovery requirements, and policy-based tiering.

Governance

Keep review and approval with the record.

Maintain analyst review, accountable approval, change handling, and recertification history.

Why It Matters

Asset classification connects technical records to business impact.

Criticality, sensitive-data context, ownership, and approval status provide the basis for consistent security governance across the asset portfolio.

CQ keeps these elements connected to the approved asset record as the asset changes.

Business criticality
Data sensitivity
Accountable ownership
Review and approval history
How It Works

Four stages from asset context to approved baseline.

The workflow records the information, review, and approval required to maintain a governed classification.

01 · Establish Context

Define the asset.

Capture identity, purpose, organization, accountable owner, custodian, and related business processes.

02 · Profile & Classify

Assess impact and sensitivity.

Profile the information handled by the asset and complete CIAT classification and tiering.

03 · Review & Approve

Validate the classification.

Route the package through analyst review and the required owner, custodian, and CISO approvals.

04 · Maintain Baseline

Keep the record current.

Use change requests and recertification to preserve the approved baseline and its history.

Product View

See classification status across the portfolio.

Portfolio views surface classification coverage, criticality, sensitive-data context, review status, and items requiring action.

Asset PortfolioIllustrative product view
ClassificationApproved
CriticalityTiered
ReviewTracked
OwnershipAssigned
Portfolio by criticality
Classification profile
Product Capabilities

Capabilities for governed asset classification.

Context & Data Profiling

Build the classification context.

Capture asset identity, business relationships, ownership, information handled, sensitivity, and relevant recovery requirements.

Asset intakeData profilingOwnershipBusiness processes
Asset context
OwnerAssigned
Data profileCurrent
Business processLinked
CIAT & Tiering

Apply a consistent classification model.

Assess Confidentiality, Integrity, Availability, and Traceability, then apply policy rules for portfolio tiering.

CIATTier 1–4Recovery thresholdsPolicy rules
Classification
ImpactAssessed
TierCalculated
RationaleRecorded
Review & Approval

Route the classification through defined authority.

Support analyst review, owner and custodian accountability, CISO approval, returned work, and controlled changes.

Analyst reviewApprovalReworkChange requests
Governance
ReviewComplete
ApprovalRecorded
ChangeControlled
Dashboards & Evidence

Track portfolio status and decision history.

Use role-based dashboards, reports, notifications, recertification, and audit history to maintain the current governance view.

DashboardsReportsNotificationsRecertificationAudit history
Oversight
ActionsVisible
ReviewsTracked
HistoryAvailable
Value by Role

One governed asset record. Different responsibilities.

Each role works with the same classification record at the level required for its decisions and actions.

Security Leadership / CISO

Review exposure and approvals.

See critical and high-impact assets, pending approvals, overdue reviews, and concentrations by organizational area.

Security & Risk Analysts

Manage classification review.

Work from assigned review queues, returned items, classification inputs, and evidence required for a review decision.

Asset Owners & Operations

Manage accountable actions.

See owned assets, incomplete profiles, approvals, requested changes, and recertification due dates.

Executive Leadership

See material asset exposure.

Review where critical assets and sensitive-data exposure concentrate and whether governance actions are current.

Audit Readiness

Can you explain why an asset was classified, approved and governed that way?

CQ IT Asset Classification retains the approved baseline, classification rationale, accountable ownership, review status, approval evidence, and change history for governance review and audit preparation.

ISO/IEC 27001NIST CSF 2.0NIST SP 800-53DORANIS2GDPR
ContextWhat was classified

Maintain asset identity, business relationships, data profile, and relevant classification inputs.

RationaleWhy the result was reached

Retain CIAT responses, tier inputs, evidence, and approved classification rationale.

AccountabilityWho reviewed and approved

Keep responsible roles, review decisions, approvals, and returned work attached to the record.

HistoryHow the baseline changed

Preserve approved snapshots, change requests, recertification, and prior classification evidence.

Why CipherQuest

Cyber risk expertise built into the workflow.

CQ IT Asset Classification applies structured risk methodology, accountable review, and evidence retention within a practical SaaS workflow.

Practitioner-led design

Classification logic is built around cyber risk, business impact, accountability, and governance decisions.

Governance by design

Review, approval, change handling, and history are part of the product record rather than separate administrative steps.

More than two decades of experience

CipherQuest brings long-standing cybersecurity and risk-management experience to the product.

Operate with Control.
Govern with Confidence.
Discuss Your Requirements