The first step in any risk analysis methodology is to determine what an asset is to the organization. An asset can be anything that is physical (such as a building, a computer, etc.), logical (such as data or an application, etc.), or it can be an intangible (such as your public image). Any organization asset must be of some value or it should be scrapped or never created in the first place. A key question to ask during an information systems risk analysis process is: what is it worth to the enterprise to continue to run the current application or system?