An engineering firm holds patent filings, proprietary CAD models, and a portfolio of registered trademarks. A new security manager notes that physical laptops and servers are tracked in detail but the intellectual property itself appears nowhere in the asset register. Senior management asks how this should be addressed. What is the BEST recommendation?
- ATreat the existing endpoint inventory as sufficient because the intellectual property is stored on those tracked devices.
- BMove all intellectual property to an encrypted file share so that a single technical control protects it consistently.
- CRely on the legal team's patent and trademark registers as the authoritative record for security purposes.
- DExtend the inventory to record intangible assets such as patents, designs, and trademarks, each with a named owner and classification. Correct
Why A is wrong: Tracking the container is not the same as tracking the asset; the same CAD model may exist on many endpoints, in backups, and with partners, so device-level inventory cannot drive classification, retention, or licensing decisions about the underlying information asset.
Why B is wrong: Centralising on an encrypted share is a reasonable handling control, but it presumes a governance baseline that does not yet exist; without an inventory and owners, the share's access decisions, retention, and incident scope remain undefined.
Why C is wrong: Legal registers track filing status and renewals, not the security attributes the organisation needs, such as classification, custodianship, handling rules, and dependency on supporting systems, so they cannot substitute for the security asset inventory.
Why D is correct: Asset security covers tangible and intangible assets alike. Recording intellectual property in the register with ownership and classification allows the firm to apply appropriate protection, value risk exposure, and meet legal obligations around patents and trademarks.