Asset Inventory has not been properly identified.
1) The Asset Inventory of the organization covered only Servers as physical assets. It did not cover other types of information asset such as human, software and information.
2) It was not known whether how many types of information asset that the organization has. Asset value was not known.
3) There was no linkage between Asset Inventory and Risk Assessment results. The completeness of risk assessment results covering all importants asset could not be assured.