by instantiating the asset concept and providing the
necessary attributes to detail things like the internal
identification code (e.g. from the inventory system or a
configuration item database like used in ITIL), vendor name
or version. By adding a recursive reference to the asset
concept in our metamodel certain dependencies between assets
could be modeled as well, e.g. the asset “web server” could be
running on an asset “blade server”. If the web server was to be
compromised, other assets depending on the underlying
(physical) system could be exposed to threats that would not
be identified outside of this broader context.