Skip to main content

Asset Catalog

This catalog lists the primary assets identified within the Scheol Lab environment. Each asset is evaluated based on confidentiality, integrity and availability requirements and assigned to a responsible role. Detailed descriptions of each asset are documented in dedicated asset pages.

Owner roles:

  • Sec: Security Role - responsible for hardening, monitoring, risk & compliance simulation.
  • Ops: Operations - deployment, patching, backups.
  • Dev: Development - CI/CD, code management, orchestration.

Status legend:

  • Deployed: fully implemented, controls applied.
  • In Progress: partially deployed, some controls active.
  • Planned: roadmap, future deployment.

Exposure: Exposure indicates the level of accessibility of the asset. For infrastructure assets it reflects network exposure (e.g. internal, perimeter, internet-facing). For information assets it reflects data access restrictions (e.g. internal, restricted).

Criticality Score: Criticality reflects the potential impact of a compromise or service disruption on the lab environment.

Business Assets

Asset IDAsset NameDescriptionOwnerStatus
BUS-ACC-01Secure Remote AccessControlled administrative access to infrastructure through a bastion and identity management system.Sec🚧 Planned
BUS-IDM-01Identity & Access ManagementCentralized authentication and identity lifecycle management.Sec🚧 Planned
BUS-MON-01Security Monitoring & DetectionCollection and analysis of logs and security events to detect malicious activity.Sec🚧 Planned
BUS-AUT-01Infrastructure AutomationAutomated deployment and configuration management of infrastructure components.Dev🚧 Planned
BUS-DOC-01Governance & DocumentationDocumentation of infrastructure, governance processes, and security procedures.Dev In Progress

Infrastructure Assets

Asset IDAsset NameAsset CategoryCriticality ScoreExposureOwnerLocationStatus
INF-PRX-01Proxmox HostVirtualization Platform🟥 HighInternalOpsOn-Premise✔️ Deployed
INF-OPN-01OPNsense FirewallNetwork Security🟥 HighPerimeterSecProxmox VM In Progress
INF-INF-01InfrastructureCore Infrastructure (Aggregate)🟥 HighInternalOpsScheol Lab In Progress
INF-VPS-01Public VPSWeb Hosting🟥 HighInternet-facingOpsWeb Hosting Service In Progress
Inf-DOC-01Documentation ServerWeb Hosting🟥 HighInternet-facingDevPublic VPS In Progress
INF-BCK-01Backup StorageData Protection🟥 HighInternalOpsOn-Premise / Proxmox VM🚧 Planned

Infrastructure asset: this asset represents the overall lab infrastructure and is used for risks affecting multiple infrastructure components simultaneously.

Security & Service Platforms

Asset IDAsset NameAsset CategoryCriticality ScoreExposureOwnerLocationStatus
PLT-VIR-01Proxmox Virtualization PlatformVirtualization Platform🟥 HighInternalOpsInternal infrastructure In Progress
PLT-BST-01Teleport Access PlatformRemote Access / Bastion🟥 HighRestrictedSecProxmox VM🚧 Planned
PLT-SIEM-01Logging & Monitoring PlatformSecurity Monitoring🟥 HighInternalSecProxmox VM / CT🚧 Planned
PLT-AUT-01Automation PlatformOrchestration / CI-CD🟨 MediumInternalDevProxmox VM / CT🚧 Planned
PLT-IMP-01Identity Management PlatformIdentity Service🟥 HighInternalSecProxmox VM🚧 Planned
PLT-DOC-01Documentation PlatformKnowledge Management🟥 HighInternet-facingDevPublic VPS In Progress
PLT-NET-01Network Security PlatformNetwork Security🟥 HighInternet-facingSecPublic VPS✔️ Deployed
PLT-EXT-01Public Infrastructure PlatformExternal Infrastructure🟥 HighInternet-facingOpsPublic VPS✔️ Deployed

Information Assets

Asset IDAsset NameAsset CategoryCriticality ScoreExposureOwnerAuthoritative SourceStatus
DAT-CFG-01Infrastructure Configuration DataInfrastructure Configuration🟥 HighRestrictedDevConfiguration Repositories In Progress
DAT-CDT-01Secrets & CredentialsAuthentication Data🟥 HighRestrictedSecSecure Secrets Storage / Vault In Progress
DAT-BCK-01BackupsData Backups🟥 HighRestrictedOpsBackup Storage🚧 Planned
DAT-LOG-01Log DataSecurity Monitoring🟥 HighInternalSecLogging & Monitoring Platform🚧 Planned
DAT-PPI-01Identity & Access DataIdentity Management🟥 HighRestrictedSecIdentity Management Platform (LDAP Directory)🚧 Planned
DAT-DOC-01Security DocumentationGovernance & Technical Documentation🟥 HighRestrictedDevDocumentation Platform In Progress
DAT-AUT-01Automation PlaybooksInfrastructure Automation🟥 HighRestrictedDevInternal repositories (Git / CI/CD) In Progress
DAT-RES-01Research NotesKnowledge Asset🟨 MediumInternalDevInternal Documentation Repositories🚧 Planned

Notes

  • Criticality Score is derived from the highest impact among C, I, and A.
  • This catalog is living and will be updated as assets are deployed, hardened, or retired.
  • For assets with multiple components (e.g., Logging hosts: Wazuh, Prometheus, Grafana), creating sub-pages is actually considered for detailed configuration, which would then be linked in the sidebar.

Methodological References:

  • ISO 27001 - Control 5.9 Inventory of information and other associated assets ; Control 5.10 Acceptable use of information and other associated assets.
  • NIST CSF - ID.AM Asset Management.
  • GDPR - Definition and protection of personal data.
  • EBIOS RM - Asset identification as an early step of the risk analysis process.