Identification: the foundation of everything else
What Article 8 really asks
The requirement is not "keep an asset inventory". It is to link:
business function → criticality → ICT assets supporting it → third parties providing them → interdependencies
Most organisations have an asset inventory (IT side) and a process map (business side). These two objects exist separately and do not talk to each other. Article 8 requires precisely the link between them.
The build sequence
1. Identify critical or important functions. A function is critical or important if its disruption would materially impair financial performance, soundness or continuity of services, or compliance with authorisation conditions. The qualification is a documented decision, not a given.
2. Attach the ICT assets. For each function, the applications, databases, infrastructure, networks and endpoints supporting it. The useful granularity is the application service, not the server.
3. Attach the third parties. Every asset provided or operated by a third party is identified as such, with the contract reference. It is this chain that will feed the Article 28 register of information.
4. Document interdependencies. Which functions share an asset? Which assets depend on the same third party? This is where concentrations appear.
Articles 11 and 12: response, recovery, backup
Article 11 requires an ICT business continuity policy and response and recovery plans, tested at least annually and after any substantial change. It also requires estimating the impact, losses and damages of every major incident — a quantification requirement many organisations discover late.
Article 12 covers backups: scope and frequency based on criticality, restoration systems physically and logically separated from the source system, periodic restoration testing, and adequate redundant capacity.
Logical separation is the most frequently non-compliant point. A backup administered with the same identities as production is not logically separated, whatever its physical location.
Board reporting
The management body must receive periodic reporting. A format that works, on one page:
- Major incidents in the period, with estimated impact;
- Tests performed and gaps found;
- Changes to the register of information and to concentrations;
- Progress on the remediation plan;
- Decisions requested from the board.
Item 5 is what turns reporting into governance. Reporting without a decision request is information; Article 5 expects oversight.
Key takeaways
- The function → asset → third party chain is the real requirement
- A technical inventory alone does not satisfy Article 8
- Review is annual and after any major change