Overview
This article explains all the management around assets in ACSIA CRA
Prerequisites
To better understand what this article describes, we advise you to read the ACSIA CRA User Manual before diving into this one which will cover specific topics around assets management.
How to manually add a new asset
Every asset related to a Company is created after a Company check.
Assets can also be created after the recheck of a Company, if they were not present before (the frequency of the rechecks depends on your subscription. Read how many you have available here).
To manually add a new asset to a Company, click on the Company you're interested in, and then click on "Go to assets":
Then, we click on "Add an asset":
Then, we define its type and write the value. Finally, we click on "Create asset":
Changing the status of an asset
To change the status of an asset we have, first, to go to the assets associated with a particular Company.
Then, we select a particular asset and click on "Go to asset":
We can set the status of the asset as:
- Enabled.
- Disabled.
- Acknowledged.
Here's what happens to the status of an asset when we change it:
- Enabled. The asset is rechecked in accordance with the characteristics of the subscription and concurs with creating the calculation of the rating of the Company.
- Disabled. The asset is not rechecked in accordance with the characteristics of the subscription (but can be rechecked occasionally, due to some other criteria) and doesn't concur with creating the calculation of the rating of the Company.
- Acknowledged. The asset is rechecked in accordance with the characteristics of the subscription but doesn't concur with creating the calculation of the rating of the Company.
Since the attack perimeter is inferred from manually added assets, we advise to not mark them as disabled or acknowledged.
Checking the related assets
As described in the User Manual, the plots that are shown in the Company Overview show us how the assets of that particular Company are related.
We have also another way to visualize how the assets are related. We can go to the assets associated with a particular Company, and click on related assets:
When we click on the source asset, we can see all the derived assets:
Checking the Technologies
This table contains the list of technologies detected on the website. The technologies are grouped by environment (server, client, external, other) and category.
- Server technologies are running on the server side (PHP, Apache, Nginx, etc.)
- Client technologies are libraries running on the client's browser.
- External technologies are loaded from external domains (CDN, analytics, etc.).
Checking the Vulnerabilities
This table contains the list of vulnerabilities detected on the website. The vulnerabilities are ordered by weight.
The vulnerabilities that weigh the most are also indicated in the highlights of the asset.