In Secfix, we can define:
Information Assets (e.g. "Sicherheitsinformationen")
Custom Assets (e.g. tools like "1Password")
Currently, there is no structured way to link these two asset types.
This limitation becomes especially relevant in the context of TISAX, where:
A clear relationship between Information (Informationswerte) and Information Carriers (Informationsträger) is expected
Transparency and traceability of these relationships is important for auditors
Example:
Information Asset: Sicherheitsinformationen
Custom Asset: 1Password
Description workaround:
"Passwort Manager Informationsasset: Sicherheitsinformationen"
➡️ This is:
Not structured
Not easily visible
Not auditable / traceable
Auditor feedback:
Transparency of linked information assets is limited and should be improved.
Please authenticate to join the conversation.
Open
Feature Request
About 4 hours ago

Sebastian
Get notified by email when there are changes.
Open
Feature Request
About 4 hours ago

Sebastian
Get notified by email when there are changes.