Know What You Have. Understand What Matters. Prove You’re in Control.
A governed classification layer for IT assets.
CQ IT Asset Classification structures the business and security context required to classify each asset and maintain an approved record over time.
Connect the asset to the business.
Record purpose, organizational context, ownership, and related business processes.
Assess criticality and data sensitivity.
Apply CIAT impact assessment, data profiling, recovery requirements, and policy-based tiering.
Keep review and approval with the record.
Maintain analyst review, accountable approval, change handling, and recertification history.
Asset classification connects technical records to business impact.
Criticality, sensitive-data context, ownership, and approval status provide the basis for consistent security governance across the asset portfolio.
CQ keeps these elements connected to the approved asset record as the asset changes.
Four stages from asset context to approved baseline.
The workflow records the information, review, and approval required to maintain a governed classification.
Define the asset.
Capture identity, purpose, organization, accountable owner, custodian, and related business processes.
Assess impact and sensitivity.
Profile the information handled by the asset and complete CIAT classification and tiering.
Validate the classification.
Route the package through analyst review and the required owner, custodian, and CISO approvals.
Keep the record current.
Use change requests and recertification to preserve the approved baseline and its history.
See classification status across the portfolio.
Portfolio views surface classification coverage, criticality, sensitive-data context, review status, and items requiring action.
Capabilities for governed asset classification.
Build the classification context.
Capture asset identity, business relationships, ownership, information handled, sensitivity, and relevant recovery requirements.
Apply a consistent classification model.
Assess Confidentiality, Integrity, Availability, and Traceability, then apply policy rules for portfolio tiering.
Route the classification through defined authority.
Support analyst review, owner and custodian accountability, CISO approval, returned work, and controlled changes.
Track portfolio status and decision history.
Use role-based dashboards, reports, notifications, recertification, and audit history to maintain the current governance view.
One governed asset record. Different responsibilities.
Each role works with the same classification record at the level required for its decisions and actions.
Review exposure and approvals.
See critical and high-impact assets, pending approvals, overdue reviews, and concentrations by organizational area.
Manage classification review.
Work from assigned review queues, returned items, classification inputs, and evidence required for a review decision.
Manage accountable actions.
See owned assets, incomplete profiles, approvals, requested changes, and recertification due dates.
See material asset exposure.
Review where critical assets and sensitive-data exposure concentrate and whether governance actions are current.
Can you explain why an asset was classified, approved and governed that way?
CQ IT Asset Classification retains the approved baseline, classification rationale, accountable ownership, review status, approval evidence, and change history for governance review and audit preparation.
Maintain asset identity, business relationships, data profile, and relevant classification inputs.
Retain CIAT responses, tier inputs, evidence, and approved classification rationale.
Keep responsible roles, review decisions, approvals, and returned work attached to the record.
Preserve approved snapshots, change requests, recertification, and prior classification evidence.
Cyber risk expertise built into the workflow.
CQ IT Asset Classification applies structured risk methodology, accountable review, and evidence retention within a practical SaaS workflow.
Classification logic is built around cyber risk, business impact, accountability, and governance decisions.
Review, approval, change handling, and history are part of the product record rather than separate administrative steps.
CipherQuest brings long-standing cybersecurity and risk-management experience to the product.