Conducting an asset-based risk assessment in ISO 27001:2013