Asset
PCIComplianceHubLast updated
Anything of value to an entity that its security programme has to account for: hardware, software, data, and the people and processes around them. In PCI DSS the assets that matter are the in-scope system components, which 12.5.1 requires to be inventoried with a description of each one's function, because a system nobody has listed is a system nobody is protecting.