Information Asset Register

Created by Venkat Pothamsetty, Modified on Mon, 25 Aug at 8:39 AM by Venkat Pothamsetty

 Information Asset Register

SquareX Holdings, Inc.
ISO/IEC 27001:2022 Annex A.8.1 Compliance


Document Control Information

  • Document Version: 1.0

  • Last Updated: 2025-08-22

  • Next Review: 2026-02-01

  • Owner: CISO (Jeswin Mathai)

  • Custodian: ISMS Lead

  • Classification: Internal Use

  • Review Frequency: Quarterly


Classification & Risk Level Legend

Classification Levels:

  • Confidential (restricted to authorized users only)

  • Internal (employees/contractors)

  • Public (available externally)

Risk Levels:

  • High Risk – critical asset, major impact if compromised

  • Medium Risk – important, but limited exposure

  • Low Risk – minimal impact on security posture

Value/Impact:

  • High Impact – significant operational, reputational, or legal consequences

  • Medium Impact – moderate disruption or loss

  • Low Impact – minimal disruption


Complete Asset Inventory

Asset IDAsset NameCategoryDescriptionLocationOwnerCustodianClassificationValue/ImpactAccess MechanismsRisk LevelProtection ControlsProcured OnRetention/DisposalReview Date
A-002AWS Cloud ServicesCloud PlatformProduction workloads for BDR and Browser DLP backendAWS Regions (US/EU/Asia)CISOCloud Ops LeadConfidentialHighIAM with MFA, VPC isolation, AWS KMS encryptionHighA.5.23 Cloud service security, A.8.9 Configuration management, A.10.1 Cryptographic policy2022-04-01Per AWS lifecycle / contract2025-11-01
A-003Azure Cloud ServicesCloud PlatformHosting for Secure Access & enterprise integrationsAzure GlobalCISOCloud Ops LeadConfidentialHighAzure AD, conditional access, Key Vault encryptionHighA.5.23 Cloud services, A.8.8 Data leakage prevention, A.13.1 Network security controls2022-08-01Per Azure lifecycle / contract2025-11-01
A-004Google Cloud Platform (GCP)Cloud PlatformSandbox analysis environments, ML/AI workloadsGCP US/EUCISOCloud Ops LeadConfidentialHighIAM with SSO, VPC, Cloud KMSHighA.5.36 Cloud usage policy, A.8.10 Malware defenses, A.6.4 Monitoring activities2023-01-01Per GCP lifecycle / contract2025-11-01
A-005Google Workspace (Gsuite)SaaS ServiceEmail, Docs, Drive for corporate collaborationGoogle Data CentersCISOIT ManagerConfidentialHighSSO, enforced MFA, DLP rules, conditional accessHighA.9.1 Access control, A.8.2.3 Media handling, A.5.23 Cloud governance2022-05-01Per retention policy2025-11-01
A-009Security Monitoring (SIEM/EDR Logs)LogsEvent logs, alerts, and telemetry from BDR/DLPAWS S3, Splunk, CrowdStrikeSOC LeadSecurity TeamConfidentialHighRBAC, encryption, immutable logs, alertingMediumA.12.4 Logging & monitoring, A.6.4 Monitoring activities, A.8.16 Logging2023-07-0112–24 months2025-11-01

Notes & Compliance Context

  • Cloud Services: Unlike the Disruptive Edge example, SquareX uses AWS, Azure, and GCP extensively. Thus Annex A.5.23 and A.5.36 are fully applicable.

  • Hardware: Consultant laptops are protected with encryption and MFA.

  • Cloud/SaaS: Workspace, DevOps tools, and client repositories are high-value and high-risk.

  • Logs & Monitoring: Event telemetry and SIEM integration are part of Annex A.12.4 compliance.

  • End-user Browsers: As SquareX’s core product area, browsers are treated as critical customer-facing assets with layered security.


✅ Best Practices & Recommendations

  1. Lifecycle Management:

    • Automate asset discovery in AWS/Azure/GCP.

    • Use tagging for cost/security accountability.

  2. Ownership & Accountability:

    • Every asset mapped to an owner/custodian (per A.8.1.2).

  3. Reviews:

    • Quarterly ISMS-led reviews of all cloud + SaaS assets.

  4. Integration with ISMS:

    • Asset Register links to Risk Register, SoA, and RART.

  5. Continuous Improvement:

    • Integrate with CMDB and extend SIEM coverage to Azure/GCP.

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article