A domain name, a collection of original illustrations, and a tested set of AI prompts can all matter to a digital project. They are useful for different reasons, and losing each one creates a different problem. A domain connects people to your work. An illustration supplies reusable creative material. A prompt may capture a repeatable way to approach a task.
Cyber assets is a useful umbrella term for these digital resources and the permissions, relationships, and systems needed to use them. Here, it is an editorial organizing term, not a claim that everything belongs to one legal or accounting class. The practical question is simple: what do you rely on, what can you actually do with it, and how would you recover if it stopped working? Our guide to cyber assets introduces the wider topic; this article turns it into a first working inventory.
1. Start with usefulness, not a price label
An asset can deserve attention without having an obvious resale price. A small documentation archive might save weeks of reconstruction. A domain used only for email could matter more to daily operations than a polished website. A set of evaluation examples might help a team catch mistakes before an AI workflow reaches customers.
The NIST glossary of asset definitions includes resources valued by people or organizations and distinguishes tangible from intangible examples. That broad framing is useful here: consider what supports your work and what the consequences of loss would be. It does not establish who owns a particular file or what a contract permits.
For your own inventory, finish this sentence for each entry: “We keep this because it enables…” If the answer is unclear, mark the entry for review. Avoid filling the value column with speculative sale estimates. A concrete purpose is easier to verify and more helpful when deciding where to spend maintenance effort.
2. Group resources by the role they play
Useful categories should help someone make a decision. They do not need to be perfectly separate. A training dataset might be both a licensed resource and part of an AI workflow. Give it one primary category and record its relationships to other entries instead of creating confusing duplicates.
- Identity and discovery: domain registrations, naming conventions, and the configuration connecting names to services.
- Creative materials: source illustrations, photographs, audio, 3D objects, and the files used to edit them.
- Software and automation: code repositories, scripts, reusable configurations, and supporting documentation.
- Data and knowledge: datasets, research notes, evaluation cases, and structured reference material.
- Platform resources: account-based virtual items, hosted workspaces, and access governed by service terms.
- AI workflow components: model access arrangements, prompts, retrieval collections, and evaluation records.
These groups suggest different questions. A creative file needs a format and rights check. A hosted resource needs an access and export check. A registration needs a renewal check. For the identity category, the domain name cyber assets guide explains how registration, hosting, and DNS fit together.
3. Separate possession, access, and permission
Having a file on a laptop answers only one question: where a copy exists. It does not by itself answer whether you may modify it, share it publicly, distribute the underlying source, or transfer rights to another person. Conversely, a resource can be important even when no downloadable copy exists, such as a hosted service configuration you are authorized to administer.
Record the evidence behind your intended use. This might be an original creation record, an applicable license, a contract reference, or the terms attached to an account. Keep a dated copy or reference where appropriate. Write a plain-language summary alongside it so a future collaborator can understand why the resource is in the inventory.
Use narrow labels such as “editable source available,” “access through team account,” or “redistribution needs review.” Do not replace an unresolved question with the word “owned.” The virtual assets guide explores these distinctions when platform access and export rights are involved.
4. Build a small inventory that someone will maintain
Begin with the resources needed to keep one real workflow running. Trying to catalogue every old download first can bury the items that need immediate attention. A spreadsheet, a structured document, or an existing project system is sufficient if authorized people can keep it accurate.
| Field | What to record |
|---|---|
| Resource and purpose | A clear name and the job it supports. |
| Responsible person | Who answers questions and approves changes. |
| Location | The repository, storage area, or provider account reference. |
| Rights evidence | Where to find the applicable permission or agreement. |
| Dependencies | Other resources needed for useful operation. |
| Recovery and review | The recovery procedure and next review trigger. |
Keep secrets outside the inventory. Point to an approved credential store without copying passwords, recovery codes, private keys, or access tokens into the record. Likewise, avoid putting private customer information in examples used to describe a dataset.
Mark unknown fields openly. “Exporter untested” is an actionable statement. An empty cell may look like an oversight, while “portable” may conceal an assumption nobody has examined.
5. Map the dependencies that make the resource useful
An isolated file may be easy to copy and difficult to use. A design needs its source fonts and linked media. A model workflow needs its input format, configuration, and evaluation cases. A website needs the right domain settings as well as the files served to visitors.
Write a short dependency chain in everyday language. For example: “The public guide uses illustrations exported from the design source; those sources use a licensed font; the website files are deployed through the project account.” This reveals where a missing account or license record could interrupt work.
Hypothetical example: a two-person studio carefully backs up finished product images but leaves the editable scenes in one person's personal account. The finished images are safe, yet future revisions depend on access nobody else has. The useful correction is to preserve authorized source access and test the editing workflow, rather than merely making another copy of the exports.
For AI work, the guide to data, models, and evaluation applies this same dependency thinking to reproducibility.
6. Prioritize by impact and recovery effort
A first inventory will probably reveal more tasks than you can complete immediately. Rank them by what would stop working and how difficult recovery would be. Avoid false precision: a simple high, medium, or low priority can be enough when accompanied by a reason.
A resource deserves early attention when several important workflows depend on it, only one person can administer it, or its recovery procedure has never been tried. Also flag deadlines that can change your ability to keep using it, including renewals, expiring access, and project handovers.
Test your inventory with a recovery exercise
Try a short recovery exercise. Ask someone authorized to locate a resource, identify the current version, find its permissions, and explain how to restore useful operation. Record where they get stuck. The exercise is valuable even without a full outage simulation because it tests the clarity of the inventory itself.
7. Turn stewardship into a routine
Assign a next action to each unresolved item: export a copy, clarify a license, transfer administration through the provider's supported process, or document a missing dependency. Give the action an owner and a review date. Otherwise, the inventory risks becoming a record of concerns rather than a tool for resolving them.
Review entries when something meaningful changes: a teammate leaves, a project launches, a provider changes, or a resource becomes part of a critical workflow. Retired resources need a decision too. Preserve what must remain available, remove unnecessary access, and record why an item was archived or deleted.
For names that support websites and email, the domain portfolio maintenance checklist provides a more specific recurring routine.
Conclusion: know what you depend on
A useful cyber asset inventory connects resources to purpose, permission, responsibility, and recovery. It helps you see where a project depends on a fragile account, an unexplained license, or a file that has never been restored. Start with one workflow, document its essentials, and fix the most consequential gap. Add detail when it helps someone make a better decision. The result should be a working map of your digital resources that stays understandable as the project grows.



