ISO 27001 Asset Management: Identifying and Protecting Information Assets
You cannot protect what you do not know you have. This principle sits at the heart of ISO 27001 asset management, covered by Annex A.8. Before you can apply security controls to your information, you must identify your assets, classify them according to their importance, and assign ownership. This article provides a practical walkthrough of Annex A.8 requirements and shows you how to build an asset management process that supports your entire ISMS.
Annex A.8: An Overview
Annex A.8 of ISO 27001:2022 is titled “Asset management” and contains four controls:
- A.8.1 – Inventory of assets: Identify information assets and document them in an inventory.
- A.8.2 – Ownership of assets: Assign ownership to all identified assets.
- A.8.3 – Acceptable use of assets: Define and document rules for acceptable use of information assets.
- A.8.4 – Return of assets: Ensure employees and contractors return assets upon termination of their engagement.
- A.8.5 – Disposal of assets: Securely dispose of assets when they are no longer needed.
These controls are foundational. Every other security control in the Standard assumes that you have a complete and accurate asset inventory. If you miss an asset, you cannot assess its risk, apply the right controls, or detect incidents affecting it.
Building an Information Asset Inventory (A.8.1)
The inventory is the central record of everything that needs protection. It is not just a list of computers and servers. Information assets include data, documents, software, hardware, cloud services, intellectual property, and even people with specialist knowledge.
| Asset Category | Examples | What to Record |
|---|---|---|
| Information / data | Customer databases, contracts, financial records, intellectual property | Data classification, format, location, retention period |
| Software | ERP system, email server, CRM, antivirus, office productivity suite | Version, licence details, patch status, vendor |
| Hardware | Laptops, servers, firewalls, switches, mobile devices | Serial number, location, user, configuration baseline |
| Cloud services | SaaS applications, IaaS accounts, PaaS environments | Subscription tier, data stored, access controls, SLA |
| Media | Backup tapes, USB drives, external hard disks | Contents, classification, physical location |
| Personnel / knowledge | Subject matter experts, process documentation, training materials | Role, knowledge domain, criticality to operations |
For each asset, the inventory should include, at minimum:
- Unique identifier
- Name and description
- Owner (see A.8.2)
- Classification (see below)
- Location (physical or logical)
- Retention or disposal date
Asset Classification
Once assets are inventoried, they must be classified according to their sensitivity, criticality, and regulatory requirements. Classification drives the level of protection applied to each asset.
| Classification Level | Description | Examples | Minimum Controls |
|---|---|---|---|
| Public | Information approved for public disclosure | Marketing brochures, published annual reports | Integrity controls to prevent unauthorised modification |
| Internal | Information for internal use only; low sensitivity | Internal policies, org charts, meeting minutes | Access limited to employees; basic confidentiality |
| Confidential | Sensitive information that could cause harm if disclosed | Customer contracts, financial data, strategic plans | Encryption at rest; access on need-to-know basis; logging |
| Restricted | Highly sensitive information with legal or regulatory protection | Personal data under PDPL, trade secrets, board communications | Strong encryption; strict access control; audit trails; annual review |
Asset Ownership (A.8.2)
Every asset must have a nominated owner. The owner is not necessarily the person who uses the asset daily; they are the person accountable for its protection throughout its lifecycle.
Asset owner responsibilities include:
- Ensuring the asset is classified and labelled correctly.
- Approving access requests to the asset.
- Reviewing the asset’s classification and controls periodically.
- Initiating disposal when the asset is no longer required.
- Ensuring that risk assessments are performed for the asset.
Assign ownership formally, ideally through your asset inventory tool or a signed acknowledgement. Avoid the common mistake of assigning IT as the owner for everything. IT may be the custodian of hardware and systems, but the business function that generates or uses the information should be the owner.
Acceptable Use (A.8.3)
An acceptable use policy (AUP) defines how employees and contractors may use the organisation’s information assets. This policy should cover:
- Permitted and prohibited uses of IT systems, internet, and email.
- Rules for personal devices (BYOD).
- Data handling requirements (e.g. no storing confidential data on personal devices).
- Consequences of policy violations.
The AUP must be communicated to all users, and evidence of acknowledgement should be retained in personnel records. Review the policy at least annually to ensure it remains relevant to the organisation’s risk profile.
Return of Assets (A.8.4)
When an employee leaves the organisation or a contractor’s engagement ends, all company assets in their possession must be returned. This includes hardware (laptops, phones, access cards), documents, and any information stored on personal devices or cloud accounts.
An offboarding checklist should include:
- Collecting all physical assets (laptop, phone, badge, keys).
- Revoking access to all systems and applications.
- Removing company data from personal devices.
- Transferring or deleting files from cloud storage.
- Confirming return of assets with a signed acknowledgement.
Disposal of Assets (A.8.5)
Secure disposal ensures that sensitive information is not recoverable after an asset is decommissioned. Disposal methods must match the asset classification:
| Asset Type | Recommended Disposal Method | Notes |
|---|---|---|
| Paper documents (Confidential / Restricted) | Cross-cut shredding or incineration | Use a certified destruction service; obtain a certificate of destruction |
| Hard drives and SSDs | Degaussing or physical shredding | Software wiping alone may not be sufficient for SSDs; physical destruction is preferred |
| Optical media (CDs, DVDs) | Physical shredding or crushing | |
| Mobile devices | Factory reset followed by physical destruction | Remove SIM and SD cards; verify that encryption was enabled before reset |
| Cloud data | Secure deletion per provider procedure; confirmation of deletion obtained | Ensure backups are also deleted; check provider data retention policies |
| Licensed software | Deactivation or licence transfer per vendor terms | Document deactivation and remove from asset inventory |
Asset Management Tools
While a spreadsheet can work for a small organisation, most businesses benefit from a dedicated tool. Consider the following when choosing an asset management solution:
- Integration with existing systems: Can it pull data from Active Directory, cloud consoles, or your CMDB?
- Classification and labelling: Does it support custom classification levels and automated labelling?
- Lifecycle tracking: Can it track assets from procurement through to disposal?
- Access control: Can you restrict who can view or modify asset records?
- Reporting: Can it generate reports for auditors and management reviews?
Popular tools include Snipe-IT (open-source), ServiceNow, ManageEngine, and specialized ISMS platforms that bundle asset management with risk assessment and compliance workflows.
Keeping the Inventory Alive
The biggest challenge in asset management is keeping the inventory accurate over time. Assets are added, moved, changed, and retired constantly. Build processes to keep the inventory current:
- Require asset registration as part of procurement and onboarding.
- Run periodic physical or network-based asset discovery sweeps.
- Integrate with HR systems to trigger asset return processes on employee offboarding.
- Schedule regular inventory reviews (quarterly for critical assets, annually for all assets).
Frequently Asked Questions
What qualifies as an information asset in ISO 27001?
An information asset is any data, information, or knowledge that has value to the organisation. This includes data in electronic and physical form, software, hardware, cloud services, intellectual property, and personnel knowledge. If it supports your business processes and requires protection, it is an asset.
How often should I update my asset inventory?
The inventory should be updated continuously as assets are added, changed, or retired. In practice, you need a process that captures changes at the point of procurement, movement, and disposal. Full inventory audits should be conducted at least annually, with critical and confidential assets reviewed more frequently (e.g. quarterly).
Can one person own multiple assets?
Yes. An individual can own many assets. In most organisations, department heads or process owners own the information assets within their domain. The key is that ownership is formally assigned and the owner understands and accepts their responsibilities for classification, access control, and lifecycle management.
Do I need to include personal devices in my asset inventory?
If your organisation allows BYOD and company data is accessed or stored on personal devices, those devices should be captured in your asset management process. You can use a separate register or a mobile device management (MDM) tool to track them. The acceptable use policy should clearly define what data may be stored on personal devices and what controls apply.
What records do I need to keep for disposal?
For each disposal, retain a record showing the asset identifier, disposal method, date of disposal, the person who authorised the disposal, and a certificate of destruction if one is obtained from a third-party service. These records demonstrate to auditors that you have controlled disposal in accordance with your policy and classification levels.
How do I handle assets stored in the cloud?
Cloud assets must be included in your inventory just like on-premises assets. Record the cloud service provider, the type of service (IaaS, PaaS, SaaS), the data stored or processed, the data location, and who has access. The shared responsibility model means that some controls are the provider’s responsibility, but you remain accountable for classifying and managing the data you put into the cloud.
How Bitrixme Can Help
Building and maintaining an asset inventory that satisfies ISO 27001 requirements can be a significant undertaking, especially for organisations that have never formally documented their information assets. Bitrixme provides expert ISMS consulting services across Bahrain and the Middle East.
We can help you identify and classify your information assets, establish ownership structures, draft acceptable use policies, and implement lifecycle management processes that keep your inventory accurate. Our consultants have hands-on experience helping organisations pass ISO 27001 certification audits.
Contact Bitrixme today to discuss your ISO 27001 asset management needs. You can also reach us directly on WhatsApp for a quick consultation.