| Integrated asset register | Exact products, versions, locations, functions, suppliers, criticality, lifecycle state and identifiers. |
| Dependency map | Relationships among components, interfaces, runtimes, applications, libraries, tools, certificates and retained systems. |
| Accepted baseline manifest | The authoritative combination of software, firmware, configuration, applications and approved deviations. |
| Source and build package | Everything needed to rebuild, test and deploy owner-controlled applications and configurations. |
| Identity and certificate register | Ownership, purpose, issuer, location, privilege, expiration, renewal and revocation method. |
| Backup and recovery set | Protected copies, restoration order, required tools, recovery dependencies, procedures and tested results. |
| Change and release procedure | How changes are assessed, built, verified, approved, deployed, rolled back and reconciled. |
| Lifecycle regression set | Which tests repeat after each class of update, replacement, application change or security modification. |
| Supplier support register | Support periods, notification duties, escalation paths, response obligations, replacement options and open limitations. |
| Training and competency record | Who is authorized and competent to operate, maintain, secure, recover and modify the delivered system. |