A5.9: Inventory of Information and Other Associated Assets
3 min read
An organization’s information and assets—such as hardware, software, databases, and even employee knowledge—are critical to business operations. Without an up-to-date asset inventory, it’s impossible to effectively manage security risks, detect unauthorized access, or ensure regulatory compliance.
ISO 27001 A.5.9 requires organizations to identify, classify, and maintain an inventory of all information assets to protect them from unauthorized access, loss, or misuse. This control ensures ownership, accountability, and proper risk management of all assets.
Implementation Guide #
Step 1: Identify All Information Assets
- List hardware assets (servers, workstations, mobile devices, etc.).
- Document software assets (applications, databases, cloud services).
- Identify data assets (customer records, financial reports, intellectual property).
- Include non-IT assets (paper records, employee knowledge).
Step 2: Classify and Categorize Assets
- Assign each asset a classification level (e.g., public, confidential, restricted).
- Determine asset ownership—who is responsible for its security?
- Establish the risk level associated with each asset.
Step 3: Maintain and Update the Inventory
- Use an Asset Management System (AMS) for tracking.
- Review and update the inventory regularly to ensure accuracy.
- Link assets to risk management and security controls.
Step 4: Implement Security Measures
- Apply encryption, access control, and backup policies for sensitive assets.
- Define disposal procedures for obsolete assets (e.g., data wiping, secure destruction).
- Conduct periodic audits to verify asset security.
Templates #
- Asset Inventory Register Template
- Asset Classification Policy
- Ownership and Responsibility Matrix
Example #
A financial company discovers that employees are using personal USB drives to store sensitive customer data. Since these devices were not listed in the asset inventory, they weren’t monitored or encrypted, posing a data breach risk.
After implementing ISO 27001 A.5.9, the company:
- Created a comprehensive asset register.
- Enforced encryption and usage policies for removable storage.
- Monitored and restricted unauthorized assets, reducing data exposure risks.
How to Comply #
To meet ISO 27001 A.5.9, organizations should:
- Maintain a centralized, up-to-date inventory of all assets.
- Ensure ownership is clearly assigned for accountability.
- Implement security controls based on asset classification.
How to Pass an Audit #
Key Documents to Prepare:
- Asset inventory list with classifications and ownership details.
- Security policies linked to asset protection.
- Audit records showing inventory updates and risk assessments.
What the Auditor Will Check:
- Does the organization maintain a complete asset inventory?
- Are assets classified according to sensitivity?
- Is there a clear process for tracking, updating, and securing assets?
Top 3 Mistakes People Make #
- Ignoring Non-Digital Assets – Companies often focus only on IT assets but forget about printed documents, backup tapes, or employee expertise.
- Not Updating the Inventory – If assets aren’t regularly reviewed, the inventory becomes outdated and loses its effectiveness.
- Lack of Ownership Assignment – Without clear responsibility, no one is accountable for securing assets, increasing the risk of loss or misuse.
ISO 27001 Return of Assets FAQ #
Q1: What is an asset in ISO 27001?
An asset is anything of value to an organization, including hardware, software, data, intellectual property, and personnel knowledge.
Q2: How often should asset inventories be updated?
Asset inventories should be reviewed quarterly and updated whenever assets are added, modified, or decommissioned.
Q3: What is the role of asset owners?
Asset owners are responsible for maintaining security, tracking usage, and ensuring compliance with organizational policies.
ISO 27001 Controls and Attribute Values #
| Control | Attribute Value |
| A.5.9 Inventory of Information and Other Associated Assets | Preventive, Risk-Based, Operational |
| Purpose | Ensure all assets are identified, classified, and protected |
| Applicability | IT infrastructure, data management, physical security |
| ISO 27001 Domains | Asset Management, Risk Management, Compliance |
Without a proper asset inventory, organizations risk data breaches, compliance failures, and financial losses. By systematically tracking all assets, businesses can reduce risk exposure and enhance information security.