Assets, Vendors & Frameworks

How to build an asset register on Mac

You can do this with RiskOS, a risk register for macOS. Record what you are protecting, say how much depends on it, and see the exposure attached to each one.

A risk register answers what could go wrong. An asset register answers what it would go wrong to. Connect the two and a line like ransomware encrypts primary file shares stops being an abstraction: it names the file store, the customer records inside it and the person who answers for both. That is the difference between a register a board can act on and a list of worries.

Note

An asset register is not an inventory of everything you own. It is the short list of things whose loss would hurt. Twenty entries you can defend are worth more than four hundred nobody reads.

Where the asset register lives

Choose Assets under Inventory in the sidebar, next to Vendors. The list fills the middle of the window and the panel on the right shows and edits whatever you select. On a new register the list is empty, and that is the right starting point — an asset register is built on purpose rather than discovered.

The section behaves like every other list in RiskOS. Search narrows it, N creates a new asset while you are in this section, and Z steps back if you change your mind.

Build the register, step by step

  1. Open the Assets section

    Choose Assets under Inventory in the sidebar. Everything here happens between the list in the middle and the panel on the right, so there is nothing to set up first.

  2. Agree what counts as an asset

    Settle the test before you type anything; it is easier than pruning later. A workable one is short: would losing this, or losing access to it, cause harm that someone outside your own team would notice? Anything that passes goes in, however cheap it was. Anything that does not stays out.

  3. Add your first asset

    Press N and give the asset a plain, specific name. Customer payment platform rather than Platform. Payroll records rather than HR data. The name is what you will search for months from now, and what a colleague has to recognise without asking.

  4. Give the asset a type

    Say whether the entry is a system, data, a facility or a process. The type does more than tidy the list: it exposes the gap in your thinking. Most registers start out as systems only, and the first pass over the types is usually where someone notices that the month-end close never made it in.

  5. Set the criticality

    Criticality records how much the organisation depends on this asset, rated on the asset itself rather than on any risk attached to it. The useful question is what the first day without it looks like: who stops working, what stops being delivered, who outside notices. Resist the pull to make everything your most critical entry.

  6. Name an owner

    Give the asset the name of a person, not a department. The owner is who you ask when a rating needs a second opinion. Spell names the same way across the register. Two spellings of M. Halvorsen split one person's responsibilities into two half-answers, and nothing will point that out for you.

  7. Connect the asset to the risks that threaten it

    Choose Risks, select a risk and open its Context section. Add the assets that risk would damage, and any vendors involved in it. Each appears with its criticality badge, so RiskOS shows the size of the exposure and the weight of what it touches on one screen.

  8. Import the rest in one pass

    If you already have a written list of systems to work from, open Import & Export and import assets from CSV. A template ships with RiskOS in its Examples folder. The preview is mandatory and line by line: what will be created, what will be updated, what will be skipped, any problems found and any columns ignored. An asset whose name matches one already in the register updates that entry instead of adding a second copy. Nothing changes until you confirm.

  9. Read the register back

    Return to Assets. Each row now carries its type, its criticality, its owner and the worst residual risk recorded against it. Read down that last column: where high criticality meets a high residual score, you are looking at the work the next quarter is actually about.

The four kinds of asset

Four types cover almost everything an organisation needs to protect, and the boundaries matter less than the habit of asking which one applies. If an entry could plausibly be two, pick the one that matches how you would talk about losing it.

The four asset types and how to tell them apart
TypeWhat belongs thereA test that settles it
SystemApplications, platforms and the infrastructure they run on.Could somebody switch it off?
DataRecords and collections whose loss, exposure or corruption causes harm.Would a copy in the wrong hands be a problem?
FacilityBuildings, sites and physical equipment.Does it have an address?
ProcessThe way work gets done: the payroll run, month-end close, customer onboarding.Does it have steps, owners and a deadline?

Why processes are worth the effort

Processes are the type most often left out and the type that explains the most. A system outage is survivable if the process it supports can be run another way for a week; it is an emergency if that process exists nowhere else. Recording both lets a risk point at the thing that actually stops.

What does not belong here

Third parties are not assets. A supplier, an outsourced provider or a processor belongs in Vendors, where each entry carries a criticality, a relationship owner, a next review date, notes and every risk that third party brings. The vendor list counts overdue reviews in its subtitle.

Criticality that means something

Criticality is a judgement about dependence, and it only earns its place if the ratings separate things. A register where everything sits at the top of the scale carries as much information as one where everything sits at the bottom.

Rate the asset, not the risk

Keep the two apart. Criticality says how much you depend on the asset; the risk's own score says how likely something is and how bad it would be. A highly critical asset with strong controls and no realistic threat is in good shape, and the register can only show that if the two numbers are set separately rather than blended into one gut feeling.

Keep the top of the scale small

Work out how many assets your organisation could genuinely fight for at once in a bad week, and let that be the size of your top rating. When a colleague argues that theirs belongs there too, the question to ask is which existing entry they would move down to make room.

An asset on its own is a label. An asset attached to risks is a view of exposure, and it reads both ways: from the risk you see what is at stake, and from the asset you see how much sits on top of it.

Where assets appear once they have been recorded
WhereWhat you see
Inventory ▸ AssetsEvery asset with its type, criticality, owner and the worst residual risk recorded against it.
Risk panel ▸ ContextThe assets and vendors attached to that risk, each shown with its criticality badge.
Output ▸ Import & ExportAsset import from CSV, with the same line-by-line preview used everywhere else.
File ▸ Back Up RiskOS…Assets are written into the backup alongside risks, controls, actions, vendors, frameworks, indicators and events.

The question the worst residual column answers

Sorting risks by score tells you which single line is worst. The asset register answers a different question: where is the exposure concentrated? An asset whose worst residual is 15 with four more risks behind it is a different problem from one bad risk standing alone, even though both rows lead with the same number. RiskOS keeps that figure current as the risks beneath it change.

Assets with nothing against them

A critical asset showing no risk is one of the more useful things a register can tell you. Either the risks exist and have not been written down, or nobody has linked them in Context yet. For the first case, Risk Library carries thirty-nine worked examples across seven categories, and entries arrive in your register as drafts for you to rate yourself.

Troubleshooting

I cannot tell whether something is an asset or a risk

The asset is the thing; the risk is the sentence about what could happen to it. Customer payment platform is an asset. Single cloud region outage halts customer portal is a risk. If your entry contains a verb like fails or is lost, it belongs in Risks, and the noun inside it belongs here.

Everything came out as highly critical

Criticality inflation, and it is common on a first pass. Re-rate the smallest handful first — the entries nobody would argue about — and let the rest settle around them. If you cannot bring yourself to move anything down, the list is too short rather than uniformly vital.

An asset shows no risk against it

Nothing has been linked to it yet. Open the risk that would damage the asset, open its Context section and add the asset there. The worst residual figure on the asset row follows from those links, so an unlinked asset stays blank however many relevant risks the register holds.

My import created new entries instead of updating the ones I had

The names did not match. A name matching an existing entry updates it; anything else is treated as new. Read off the spelling the register already uses, correct the file and run the import again. The preview will then show updates rather than creations, before you confirm anything.

I cannot find an asset I know I added

Check which section you are in. Third parties go to Vendors, so an entry missing from Assets has often landed next door. If it is genuinely in Assets, search on a distinctive word from the name rather than the whole title.

Routines that keep an asset register useful

The register earns its keep in maintenance, not in the first afternoon. A few habits carry most of that weight.

  • Start from the risks you already have. Walk the register and record the assets those risks name. Every entry then arrives already connected to something.
  • Name a person, every time. An asset with a team in the owner field has nobody to answer for it, and the first time a rating is questioned you will be looking for a name.
  • Keep the top of the criticality scale small. If more than a handful of entries sit at the top, the rating has stopped sorting anything.
  • Fold assets into the review you already run. When Review brings a risk up for re-scoring, the context beside it names the assets involved — the natural moment to notice one is missing or wrongly rated.
  • Let vendors be vendors. Suppliers belong in Vendors, with a relationship owner and a next review date. Mixing them into Assets loses the review prompts you would otherwise get for free.
  • Back it up when the shape changes. B writes the whole register to a single file wherever you choose, assets and vendors included, and RiskOS puts the date in the default filename for you.

Frequently asked questions

What is an asset register?

It is the record of what an organisation is protecting: the systems, data, facilities and processes whose loss would cause harm. Each entry carries a type, a criticality and an owner. In RiskOS it sits under Inventory, and every asset shows the worst residual risk currently recorded against it.

What should go in an asset register?

Anything whose loss, exposure or unavailability would be noticed outside your own team. That usually means the platforms you serve customers from, the records you are trusted with, the premises work depends on, and the processes that have to run on a date. Leave out anything you would replace without telling anyone.

What is the difference between an asset and a risk?

An asset is a thing. A risk is a sentence about something happening to it. Payroll records is an asset; payroll provider suffers a prolonged outage is a risk. Assets are rated for how much you depend on them, risks for likelihood and impact, and linking the two is what shows you where exposure is concentrated.

How do I link an asset to a risk on Mac?

Open the risk, then open the Context section of its panel. Add the assets the risk would damage and any vendors involved. Each appears with its criticality badge. The link works in both directions: the risk gains context, and the asset's row starts reporting the worst residual risk attached to it.

Can I import an asset list from a CSV file?

Yes. Import & Export takes assets from CSV, and a template ships with RiskOS in its Examples folder. The preview shows line by line what will be created, updated or skipped, plus any problems and ignored columns. A name matching an existing asset updates it, so a re-import corrects rather than duplicates. Nothing is written until you confirm.

How many assets should a register have?

Fewer than people expect. Most organisations can describe what matters in twenty to sixty entries, and a register that runs to hundreds is usually recording equipment rather than dependence. The right size is the number you could talk through in a meeting without losing the room.

What does asset criticality mean?

It records how much the organisation depends on that asset, judged on the asset itself rather than on any threat to it. Set it by asking what the first day without it looks like. It appears as a badge wherever the asset is shown, including beside every risk that names it, so weight and exposure read together.

Is my asset register stored on my Mac?

Yes. Everything here happens on your Mac. There is no account, nothing is uploaded, and your register never leaves the machine except when you export or back it up yourself. The only network RiskOS uses is Apple's App Store, for purchases, and it never sees what you have recorded.