Skip to content
English
  • There are no suggestions because the search field is empty.

How To Add And Edit A Security Resource

A step-by-step guide to recording a security resource, attaching its costs and ownership, and keeping the record current as it changes.

Adding a resource records something your security posture depends on, so it can be owned, costed, used as evidence and tracked to its renewal date. This article covers adding one, uploading many at once, and editing or retiring them later.

Adding a resource

  1. From the navigation menu, click Catalogue > Security Resources, then select the tab for the type you are adding: Technology, People, Service Provider or Documentation.

  2. Click the Create Resource button (+)on the top right to open the form.

  3. Enter the Name and Description, and set the Criticality to reflect how much the organisation depends on it.

  4. Record the costs where you know them: the purchase or capital cost, the ongoing operating cost and any one-off non-recurring cost, along with the currency and how often the recurring cost falls. These are what allow Threat Modelling to produce a return on investment figure, so they are worth entering even approximately.

  5. Set the expiry or depreciation date for anything that renews, such as a licence or a contract. This drives the renewal reminders described in Getting Started with Security Resources.

  6. Assign an Owner, and any additional assignees. The owner receives renewal reminders, so this is more than a label.

  7. Add the context that makes the record useful later: location, classification, the data types it handles, and tags.

  8. Where relevant, link the resource to related records. A Service Provider can be linked to the entity you assess them as, and a Technology resource can be linked to the technology it runs on.

  9. Click Save.

For People resources

A People resource carries three fields the others do not: what the person is responsible for, how many days a week they are available, and whether they are key personnel.

Mark key personnel accurately. It is how you identify a dependency that will not show up in any technology inventory: a single individual whose absence would leave a control unperformed.

Bulk uploading many Security Resources at once

To bring in an existing inventory, use Upload Resources, download the template, complete a row per resource and upload the file. The process is the same as every other bulk upload in the platform and is covered in How to Bulk Upload your Data via CSV.

Exporting first is the quickest way to make bulk changes: export your resources, edit the spreadsheet, and upload it back.

Evidencing a control with a resource

A resource earns its place by evidencing something. From a control in your Capabilities Assessment you can link an existing resource, or create a new one without leaving the assessment. See How to Assess your Capabilities.

Where a resource evidences controls that also protect a Key Business System, linking it to that system carries its controls across. See How to Link a Key Business System to a Control.

Retiring a resource

When something is decommissioned, set its status rather than deleting the record, so its history stays attached to the controls it used to evidence.

Retiring a resource unlinks it from any business systems it supported and removes it from your Trust Portal if it appeared there. Those links are not restored if the resource is reinstated, so if something is only temporarily out of service, leave it in place.