Information system mapping: building it step by step
The six views proposed by ANSSI, the five-step approach, maturity levels and the precautions to take for such a sensitive document.
Information system mapping is the representation of an organisation's information system and its links with the outside world: an inventory of its components and a set of views, from business processes down to equipment. ANSSI, the French national cybersecurity agency, devotes a guide to it, with six views and a five-step approach. It is the starting point of any serious risk analysis, and an invaluable tool on the day of an incident.
What is an information system map?
In November 2018, ANSSI published the guide “Mapping the information system, how-to guide in 5 steps”. Written first for operators of vital importance, it is meant to be usable by any organisation. It defines the map as a representation of the information system and its connections with the outside world, combining two things:
- an inventory, the detailed list of the system's components: applications, servers, networks, accounts, suppliers;
- views, partial representations of the system, each from a specific angle.
The guide links mapping to four stakes. Control of the system: knowing what exists and who is responsible for it. Protection: choosing controls where they matter. Defence: quickly understanding the scope of an attack. Resilience: knowing in which order to rebuild. An organisation that discovers its dependencies during a crisis loses precious hours, as our article on the business continuity plan points out.
Beware of a common confusion: an information system map describes what exists; it does not assess risks. A risk map, built on top of it, rates what could go wrong. The first is the foundation of the second.
The six views of information system mapping according to ANSSI
The guide proposes six views, grouped into three visions, to move gradually from business to technology.
- Ecosystem view (business vision): internal or external entities that interact with the system, such as customers, suppliers and partners, with their relationships and security contacts.
- Business view of the IS (business vision): the organisation's processes, activities and tasks, the people who perform them and the information they handle.
- Application view (application vision): application blocks, applications, services, databases and the flows between them.
- Administration view (application vision): administration zones and means, directories and domains (Active Directory, LDAP) and privilege levels.
- Logical infrastructure view (infrastructure vision): networks, subnets, VLANs, address ranges, gateways, security devices, DNS and DHCP servers.
- Physical infrastructure view (infrastructure vision): sites, buildings, rooms, racks, servers, workstations, storage and physical links.
What gives the whole its value are pivot objects: elements that appear in two views and let you move between them. An application shows up in the business view, because it supports an activity, and in the logical view, because it runs in a network zone. Following these objects, you can go up from a server to the activities it keeps running, or down from a process to the room that hosts it. Try it in the diagram below: Active Directory, for instance, supports two activities on its own.
Follow a dependency from the business down to the server room
Click an object: the chain it belongs to lights up across all views.
Activities that depend on it
Invoicing
Only one activity relies on this object.
Linked objects
- Customers
- Bank
- Invoicing
- ERP
- Active Directory
- Server network
- Head office server room
This is exactly the reasoning you follow during an incident (“this server is compromised, which activities are affected?”) and in risk analysis (“this activity is critical, what does it depend on?”). The administration view deserves special attention: privileged accounts and directories are concentration points that attackers target first. Our article on incident management with ISO 27035 shows how this knowledge speeds up the response.
Building your information system map in five steps
ANSSI's guide organises the approach around five questions: how to get started, which model to adopt, which tools to use, how to build the map and how to keep it alive.
1. Get started
Everything starts with the stakes: why map, and to what end? The guide recommends an executive sponsor who approves the objectives, and a lead: the CISO when the approach focuses on security, the CIO when it is broader. Architects, business units, the data protection officer (DPO), physical security managers and audit teams are natural contributors. You then set the scope, the target and the roadmap to get there.
2. Choose the model
Before drawing anything, collect what exists (inventories, network diagrams, architecture documents, contracts) and define the model: which objects to represent, with which attributes, under which naming scheme. For each view, the guide proposes objects and attributes, flagging those that matter for security. A shared naming scheme prevents the ERP from being called three different things by different teams.
3. Choose the tools
ANSSI does not name any tool. It asks that the tools chosen make it possible to build the inventory, produce the views and their links, and manage updates. The point is not to replace what already exists; specialised software becomes useful when the volume of data or the number of contributors grows, and simplicity remains an asset to avoid parallel maps. The map must be exportable read-only in a common office format.
4. Build step by step
Start with the inventory, then build the views, working down from business to technology. The guide advises consulting existing risk analyses at this stage: they often show which activities and which equipment matter most.
5. Keep it alive
A map that is not kept up to date becomes dangerous, because it gives false assurance. The guide asks you to communicate about the approach from the outset, share the map with the teams that need it, and set up update governance: periodic campaigns and, above all, an update built into every project that changes the system.
Three maturity levels: start small
The guide distinguishes three levels, so you do not have to do everything at once.
- Level 1: a security-oriented map limited to essential elements and a few views. It is an intermediate step.
- Level 2: a security-oriented map covering all views. This is the minimum expected for critical information systems of operators of vital importance.
- Level 3: an exhaustive and detailed map, as part of a broader approach that goes beyond security.
For an SME or a local authority just starting out, aiming for level 1 on a limited scope is realistic: the ecosystem and business views, plus the applications and administration of critical activities. The ecosystem view is also the starting point for third-party risk management, since it lists the suppliers you depend on.
Protecting the map: a sensitive document
An information system map is also a treasure map for an attacker: it shows where the servers, admin accounts and flows are. ANSSI's guide draws several rules from this.
- Give it a protection marking, such as “company confidential” or “restricted”; for critical information systems of operators of vital importance, it is at least marked restricted.
- Limit access on a need-to-know basis: the business view can be widely shared, the infrastructure views stay with IT. The CISO and the incident response team must always have access.
- Do not store it on the system it describes, and keep secure backups, down to a paper copy, so that it can still be consulted if the network is down.
This last point is often forgotten: the day ransomware encrypts the file server, a map stored on it is of no use.
The information system map, a prerequisite for EBIOS RM
The EBIOS Risk Manager method starts with a scoping workshop in which you identify business assets, what really matters to the organisation, and the supporting assets they rely on. ANSSI's mapping guide makes the link: objects in the business view correspond to business assets, technical objects to supporting assets. For its part, the EBIOS RM guide cites the information system map as the basis for identifying supporting assets.
The first EBIOS RM workshop recommends sticking to a limited number of business assets, around five to ten, and one to three supporting assets for each to begin with. A well-built level 1 map provides exactly that. It also helps express the security needs of each business asset, for example with the DICP criteria, then carry out the risk analysis and track residual risk once controls are applied.
The guide mentions other uses: the record of processing activities required by the General Data Protection Regulation (GDPR), for example, benefits from the business view, which already describes which information each activity handles.
Tips for a successful information system map
- Start from the business. A map that starts with the network often ends up as an architect's diagram that management never reads.
- Appoint owners. Each process has a business owner, each application a technical owner: they are the ones who approve updates.
- Tie updates to projects. A new supplier, a cloud migration or a new application should change the map before going live.
- Spot concentration points. An object that several critical activities depend on (a directory, a hosting provider, a network link) is a candidate for stronger protection.
- Test its availability. During a crisis exercise, check that the map can be consulted without the information system.
The business and supporting assets drawn from the map are the starting point of EBIOS RM analyses. To see how they connect with the following workshops, see our risk analysis module.
Summary
An inventory and views
An information system map combines a detailed list of components with six views, from the ecosystem to the physical infrastructure, linked by shared objects. It helps you control, protect, defend and restore the information system.
An approach, not a diagram
ANSSI's guide proposes five steps and three maturity levels. A level 1 map kept up to date is better than an exhaustive but outdated diagram: updating it is part of every project.
The foundation of risk analysis
The business view provides the business assets of EBIOS RM, the technical views its supporting assets. As a sensitive document, the map must be protected and stored outside the system it describes.
Frequently asked questions
What is an information system map?
It is a representation of the information system and its links with the outside world. According to ANSSI, it combines an inventory of components (applications, servers, networks, admin accounts, suppliers) and several views that show the system from different angles, from business to technology. It tells you what you need to protect and helps you react quickly to an incident.
What are the views of an information system map?
ANSSI's guide proposes six, grouped into three visions: the ecosystem and the business view (business vision), applications and administration (application vision), logical and physical infrastructure (infrastructure vision). Objects shared by several views let you move from one to another.
What is the difference between an IS map and a risk map?
An information system map describes what exists: what the system is made of and how the parts depend on each other. A risk map assesses what could go wrong in that scope and how severe it would be. The first is the foundation of the second.
Who should build the information system map?
ANSSI's guide calls for an executive sponsor and a lead: the CISO when the approach focuses on security, the CIO when it is broader. Business units, architects, the DPO and operations teams contribute, with business units remaining owners of their processes.
Which tool should you use?
ANSSI does not recommend a specific tool. It advises relying first on existing tools, moving to specialised software when the volume of data or number of contributors grows, and favouring simplicity to avoid parallel maps. The map must be exportable read-only in a common office format.
Is an information system map mandatory?
In France it is expected from operators of vital importance for their critical information systems, which must reach at least level 2 of ANSSI's guide. For other organisations no general rule requires it by that name, but it is hard to run a risk analysis, a security accreditation or an ISO 27001 project without knowing what your information system is made of.
A platform and service that adapt to you
Our platform is designed for fine-tuned configuration and broad adaptability to your needs.