iso-27001-asset-management

By July 25th, 2026ISO Audit And Certificate9 min read

ISO 27001 Asset Management: Identifying and Protecting Information Assets

You cannot protect what you do not know you have. This principle sits at the heart of ISO 27001 asset management, covered by Annex A.8. Before you can apply security controls to your information, you must identify your assets, classify them according to their importance, and assign ownership. This article provides a practical walkthrough of Annex A.8 requirements and shows you how to build an asset management process that supports your entire ISMS.

Annex A.8: An Overview

Annex A.8 of ISO 27001:2022 is titled “Asset management” and contains four controls:

  • A.8.1 – Inventory of assets: Identify information assets and document them in an inventory.
  • A.8.2 – Ownership of assets: Assign ownership to all identified assets.
  • A.8.3 – Acceptable use of assets: Define and document rules for acceptable use of information assets.
  • A.8.4 – Return of assets: Ensure employees and contractors return assets upon termination of their engagement.
  • A.8.5 – Disposal of assets: Securely dispose of assets when they are no longer needed.

These controls are foundational. Every other security control in the Standard assumes that you have a complete and accurate asset inventory. If you miss an asset, you cannot assess its risk, apply the right controls, or detect incidents affecting it.

Building an Information Asset Inventory (A.8.1)

The inventory is the central record of everything that needs protection. It is not just a list of computers and servers. Information assets include data, documents, software, hardware, cloud services, intellectual property, and even people with specialist knowledge.

Asset CategoryExamplesWhat to Record
Information / dataCustomer databases, contracts, financial records, intellectual propertyData classification, format, location, retention period
SoftwareERP system, email server, CRM, antivirus, office productivity suiteVersion, licence details, patch status, vendor
HardwareLaptops, servers, firewalls, switches, mobile devicesSerial number, location, user, configuration baseline
Cloud servicesSaaS applications, IaaS accounts, PaaS environmentsSubscription tier, data stored, access controls, SLA
MediaBackup tapes, USB drives, external hard disksContents, classification, physical location
Personnel / knowledgeSubject matter experts, process documentation, training materialsRole, knowledge domain, criticality to operations

For each asset, the inventory should include, at minimum:

  • Unique identifier
  • Name and description
  • Owner (see A.8.2)
  • Classification (see below)
  • Location (physical or logical)
  • Retention or disposal date

Asset Classification

Once assets are inventoried, they must be classified according to their sensitivity, criticality, and regulatory requirements. Classification drives the level of protection applied to each asset.

Classification LevelDescriptionExamplesMinimum Controls
PublicInformation approved for public disclosureMarketing brochures, published annual reportsIntegrity controls to prevent unauthorised modification
InternalInformation for internal use only; low sensitivityInternal policies, org charts, meeting minutesAccess limited to employees; basic confidentiality
ConfidentialSensitive information that could cause harm if disclosedCustomer contracts, financial data, strategic plansEncryption at rest; access on need-to-know basis; logging
RestrictedHighly sensitive information with legal or regulatory protectionPersonal data under PDPL, trade secrets, board communicationsStrong encryption; strict access control; audit trails; annual review

Asset Ownership (A.8.2)

Every asset must have a nominated owner. The owner is not necessarily the person who uses the asset daily; they are the person accountable for its protection throughout its lifecycle.

Asset owner responsibilities include:

  • Ensuring the asset is classified and labelled correctly.
  • Approving access requests to the asset.
  • Reviewing the asset’s classification and controls periodically.
  • Initiating disposal when the asset is no longer required.
  • Ensuring that risk assessments are performed for the asset.

Assign ownership formally, ideally through your asset inventory tool or a signed acknowledgement. Avoid the common mistake of assigning IT as the owner for everything. IT may be the custodian of hardware and systems, but the business function that generates or uses the information should be the owner.

Acceptable Use (A.8.3)

An acceptable use policy (AUP) defines how employees and contractors may use the organisation’s information assets. This policy should cover:

  • Permitted and prohibited uses of IT systems, internet, and email.
  • Rules for personal devices (BYOD).
  • Data handling requirements (e.g. no storing confidential data on personal devices).
  • Consequences of policy violations.

The AUP must be communicated to all users, and evidence of acknowledgement should be retained in personnel records. Review the policy at least annually to ensure it remains relevant to the organisation’s risk profile.

Return of Assets (A.8.4)

When an employee leaves the organisation or a contractor’s engagement ends, all company assets in their possession must be returned. This includes hardware (laptops, phones, access cards), documents, and any information stored on personal devices or cloud accounts.

An offboarding checklist should include:

  • Collecting all physical assets (laptop, phone, badge, keys).
  • Revoking access to all systems and applications.
  • Removing company data from personal devices.
  • Transferring or deleting files from cloud storage.
  • Confirming return of assets with a signed acknowledgement.

Disposal of Assets (A.8.5)

Secure disposal ensures that sensitive information is not recoverable after an asset is decommissioned. Disposal methods must match the asset classification:

Asset TypeRecommended Disposal MethodNotes
Paper documents (Confidential / Restricted)Cross-cut shredding or incinerationUse a certified destruction service; obtain a certificate of destruction
Hard drives and SSDsDegaussing or physical shreddingSoftware wiping alone may not be sufficient for SSDs; physical destruction is preferred
Optical media (CDs, DVDs)Physical shredding or crushing 
Mobile devicesFactory reset followed by physical destructionRemove SIM and SD cards; verify that encryption was enabled before reset
Cloud dataSecure deletion per provider procedure; confirmation of deletion obtainedEnsure backups are also deleted; check provider data retention policies
Licensed softwareDeactivation or licence transfer per vendor termsDocument deactivation and remove from asset inventory

Asset Management Tools

While a spreadsheet can work for a small organisation, most businesses benefit from a dedicated tool. Consider the following when choosing an asset management solution:

  • Integration with existing systems: Can it pull data from Active Directory, cloud consoles, or your CMDB?
  • Classification and labelling: Does it support custom classification levels and automated labelling?
  • Lifecycle tracking: Can it track assets from procurement through to disposal?
  • Access control: Can you restrict who can view or modify asset records?
  • Reporting: Can it generate reports for auditors and management reviews?

Popular tools include Snipe-IT (open-source), ServiceNow, ManageEngine, and specialized ISMS platforms that bundle asset management with risk assessment and compliance workflows.

Keeping the Inventory Alive

The biggest challenge in asset management is keeping the inventory accurate over time. Assets are added, moved, changed, and retired constantly. Build processes to keep the inventory current:

  • Require asset registration as part of procurement and onboarding.
  • Run periodic physical or network-based asset discovery sweeps.
  • Integrate with HR systems to trigger asset return processes on employee offboarding.
  • Schedule regular inventory reviews (quarterly for critical assets, annually for all assets).

Frequently Asked Questions

What qualifies as an information asset in ISO 27001?

An information asset is any data, information, or knowledge that has value to the organisation. This includes data in electronic and physical form, software, hardware, cloud services, intellectual property, and personnel knowledge. If it supports your business processes and requires protection, it is an asset.

How often should I update my asset inventory?

The inventory should be updated continuously as assets are added, changed, or retired. In practice, you need a process that captures changes at the point of procurement, movement, and disposal. Full inventory audits should be conducted at least annually, with critical and confidential assets reviewed more frequently (e.g. quarterly).

Can one person own multiple assets?

Yes. An individual can own many assets. In most organisations, department heads or process owners own the information assets within their domain. The key is that ownership is formally assigned and the owner understands and accepts their responsibilities for classification, access control, and lifecycle management.

Do I need to include personal devices in my asset inventory?

If your organisation allows BYOD and company data is accessed or stored on personal devices, those devices should be captured in your asset management process. You can use a separate register or a mobile device management (MDM) tool to track them. The acceptable use policy should clearly define what data may be stored on personal devices and what controls apply.

What records do I need to keep for disposal?

For each disposal, retain a record showing the asset identifier, disposal method, date of disposal, the person who authorised the disposal, and a certificate of destruction if one is obtained from a third-party service. These records demonstrate to auditors that you have controlled disposal in accordance with your policy and classification levels.

How do I handle assets stored in the cloud?

Cloud assets must be included in your inventory just like on-premises assets. Record the cloud service provider, the type of service (IaaS, PaaS, SaaS), the data stored or processed, the data location, and who has access. The shared responsibility model means that some controls are the provider’s responsibility, but you remain accountable for classifying and managing the data you put into the cloud.

How Bitrixme Can Help

Building and maintaining an asset inventory that satisfies ISO 27001 requirements can be a significant undertaking, especially for organisations that have never formally documented their information assets. Bitrixme provides expert ISMS consulting services across Bahrain and the Middle East.

We can help you identify and classify your information assets, establish ownership structures, draft acceptable use policies, and implement lifecycle management processes that keep your inventory accurate. Our consultants have hands-on experience helping organisations pass ISO 27001 certification audits.

Contact Bitrixme today to discuss your ISO 27001 asset management needs. You can also reach us directly on WhatsApp for a quick consultation.