Tidepool IT leverages internal tracking and some automation systems to maintain inventory of all company owned physical computing equipment
Physical Asset Inventory
Internally tracked computing equipment includes, but is not limited to:
workstations
laptops
external or removable hard drives
Each record includes details of the physical device such as manufacturer, model as well as ownership details.
The movement/transfer of computing hardware and electronic media is maintained as part of the records, including media re-use and ownership reassignment.
Tidepool IT is responsible for ensuring each new asset/resource has an up-to-date record in the IT asset management system.
All company-owned devices are subject to a complete data wipe if deemed necessary, such as in the case of device infection or repurpose. This data wipe will be carried out or documented by the IT Security Engineer
Digital Asset Inventory
Tidepool Security team uses an automated system to query across our cloud-based infrastructure, including but is not limited to AWS, to obtain detailed records of all digital assets:
Virtual machines
AWS EC2 instances
AWS S3 repositories
AWS Lambda functions
Security agents
Source code repositories
Document Shares
User accounts
The records are stored in a cloud database maintained by JupiterOne. Records are tagged with owner/project and classification when applicable. All records are kept up to date via automation.
Paper Records
Tidepool does not use paper records for any sensitive information. Use of paper for recording and storing sensitive data is against Tidepool policies.