Skip to content

Commit 3948bbc

Browse files
authored
Merge pull request #4963 from MicrosoftDocs/DebLanger-patch-2
Add criticality note - US487724
2 parents 772479e + b1825e6 commit 3948bbc

File tree

2 files changed

+8
-1
lines changed

2 files changed

+8
-1
lines changed

exposure-management/classify-critical-assets.md

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@ author: dlanger
66
manager: ornat-spodek
77
ms.topic: overview
88
ms.service: exposure-management
9-
ms.date: 07/23/2025
9+
ms.date: 09/08/2025
1010
---
1111

1212
# Review and classify critical assets
@@ -34,6 +34,9 @@ Impact analysis and crown jewels analysis are essential methodologies for identi
3434

3535
The NIST Cybersecurity Framework (CSF) 800-53 also emphasizes guidance for asset management and criticality analysis, as outlined in ID.AM-05, which can be found at: [https://csf.tools/reference/nist-cybersecurity-framework/v2-0/id/id-am/id-am-05/](https://csf.tools/reference/nist-cybersecurity-framework/v2-0/id/id-am/id-am-05/).
3636

37+
> [!NOTE]
38+
> When multiple classification rules apply to an asset, the rule with the highest criticality level takes precedence. This classification remains in effect until the asset no longer meets the criteria for that rule, at which point it will automatically revert to the next applicable classification level.
39+
3740
## Prerequisites
3841

3942
Before you begin, ensure you meet the following requirements for working with critical assets in Microsoft Security Exposure Management.

exposure-management/predefined-classification-rules-and-levels.md

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -25,6 +25,10 @@ Current asset types are:
2525

2626
> [!Note]
2727
> The critical asset out-of-the-box classification logic classifies your assets based on asset behavior accumulated from Microsoft Defender workloads and third-party integrations set up in your environment.
28+
>
29+
> When multiple classification rules apply to an asset, the rule with the highest criticality level takes precedence. This classification remains in effect until the asset no longer meets the criteria for that rule, at which point it will automatically revert to the next applicable classification level.
30+
31+
2832

2933
##### Device
3034

0 commit comments

Comments
 (0)