A practical path from empty spreadsheet to a living model — sized for one division, not the whole campus. Start with the systems you own, capture enough to be useful, and sustain it on a cadence.
Every phase delivers value on its own. Stop after Phase 1 and you already have an inventory no one had before.
List the systems the unit owns or funds — 20–40, not everything. Capture the minimum-viable record below and map each to one BRM capability. The deliverable is a single trustworthy list.
Add data classification, recovery tier, source-of-record, application type (ARM), hosting (TRM), and lifecycle touchpoints. Then run the first overlap-and-gap review.
Assign an owner and a data steward to every record, set a quarterly review, and hook intake to your procurement and renewal calendar so nothing enters or leaves the estate unrecorded. Publish the views your stakeholders actually ask for.
Offer the model as a shared pattern to peer units, feed it into roadmap and budget cycles, and align on common capability and classification vocabularies so unit models can roll up to a division and campus view. Your unit becomes the proof of concept.
A model earns its keep the moment someone makes a decision with it. Ten plays — each a question a leader asks, the lens that answers it, and the decision it drives — are written up as their own pages.
Twelve fields. If you can fill these for every system your unit owns, you can answer almost every question this model promises. Everything else is refinement.
Download the template (CSV)Sets the mandate and reviews the roll-up. Usually a CIO or deputy CIO: someone who can make the model matter to peers.
Owns the vocabulary and keeps the model coherent — usually one architect or analyst, part-time.
Keep their own systems' records current — the people who already run them.
Confirm classification and source-of-record for the data each system holds.
No new system is procured without a record. Tie it to the purchase-approval step so the model can't fall behind.
Owners confirm their records; curator runs the gap/overlap and renewals-due views for leadership.
Roll up to a division view for budget and roadmap; reconcile against DR and security registers.
The generic dimensions map cleanly onto your institution's existing frameworks — so this augments your compliance posture rather than adding a parallel one.
Map the four sensitivity levels onto your information security policy's protection levels, so a "restricted" system reads directly in institutional terms.
Align criticality tiers with your availability levels and the continuity plan's target recovery windows.
Use the CAUDIT HERM as the shared capability vocabulary, so your unit model can roll up and compare across peer institutions.
Confirm your institution's protection and availability level definitions and target recovery windows against its own policy implementation before publishing.
Pick ten systems you own and fill the twelve fields. That's the whole first step.
Everything on this site works off that same record — so the moment it exists, the catalog, the views, and the roll-ups become yours to use.