Certain®-Assets
Certain®-Assets is a unified enterprise asset and risk management platform that provides organisations with complete visibility, control, and assurance across all asset types, not just IT. Built with strong alignment to ISO 27001:2022, it transforms fragmented asset data into a
structured, risk-driven system that supports both operational decisions and audit readiness.
At its core is a centralised asset register capturing physical, digital, human, and intangible assets within a configurable taxonomy. Each asset is uniquely identified, ownership is assigned, and relationships
between systems, data, and people are mapped, creating a dynamic view of the
organisation’s information landscape.
This foundation is enhanced by robust classification and valuation capabilities, enabling assets to be assessed using CIA principles and data sensitivity categories. Business impact and risk exposure are clearly
defined, ensuring consistent prioritisation.
The integrated risk management engine links assets to threats, vulnerabilities, and controls. It supports flexible risk scoring, tracks inherent and residual risk, and enables structured treatment planning, turning static inventories into actionable risk intelligence. Built-in ISO 27001:2022 alignment maps assets to Annex A
controls, supports gap analysis, and enables automatic generation of an audit-ready Statement of Applicability (SoA), including justification, status tracking, and exportable outputs. With audit trails, evidence management, and real-time dashboards, Certain®-Assets delivers continuous compliance monitoring and clear executive insight. Integration with CMDBs, cloud platforms, and HR systems ensures accuracy through automation. The result is a deeply connected platform where assets, risks, controls, and compliance are fully aligned, enabling organisations to manage and defend their environment with confidence.