(4/N) Having reflected a bit on your abstract assets, try to brainstorm as many of your related data and device assets as possible. Most of them will fall into one or more of the following categories:
For instance, your smartphone photo collection "asset" probably contains geospatial data (#GPS coordinates in #EXIF); data and metadata (phone brand and model, in EXIF); potentially also information about your social graph, in case your family, friends or acquaintances are on your photos.
It's probably best to track your data and device assets in a spreadsheet, with the above categories as additional columns, so you can place a checkmark, where appropriate. I'd also suggest to add a column to track where the data is stored / the device is located.
Here's a little list of Personally Identifiable Information (PII), to get you started (other categories in next posts):
Start of this thread:
https://mastodon.de/@tuxwise/113503228291818865
#ThreatModeling #4D