Skip to main content

Proof of competence

ISO/IEC 27001:2022 Annex A · Control 5.9

Inventory of Information and Other Associated Assets: A Practical Implementation Guide

Know which information and supporting assets matter, who owns them and how they must be protected.

This control concerns developing and maintaining an inventory of information and other assets associated with information processing.

Practical interpretation: The inventory should support decisions, not become a static spreadsheet. It must connect assets to owners, criticality, classification, location, dependencies and lifecycle status.

What should the control achieve?

  • In-scope information and supporting assets are identifiable.
  • Each important asset has an accountable owner.
  • Inventories stay current through operational processes.
  • Asset data supports risk, access, continuity and incident decisions.

Step-by-step implementation

1

Define asset categories

Include information sets, applications, infrastructure, devices, cloud services, facilities, people roles and critical suppliers as relevant.

2

Set required attributes

Record owner, custodian, location, classification, criticality, lifecycle state and key dependencies.

3

Use authoritative sources

Integrate CMDB, cloud inventory, procurement, HR and data catalogues instead of duplicating everything manually.

4

Assign ownership

Owners approve protection requirements, access and lifecycle decisions.

5

Embed updates

Trigger inventory changes through procurement, deployment, change, transfer and disposal processes.

6

Reconcile and verify

Compare records with discovery tools, invoices, network scans and owner attestations.

What this could look like in practice

A fintech combines its CMDB, cloud asset discovery and information register. Application records link to data classifications, service owners, suppliers and recovery objectives. Monthly reconciliation identifies unknown cloud resources and tickets them for ownership or removal.

ActivityPractical implementationEvidence
New cloud serviceProcurement and architecture workflow creates an owned inventory record.Service record and approval
Application changeChange process updates dependencies and data handling.Updated CMDB relationship
RetirementOwner confirms data migration, retention and secure disposal.Decommission record

Implementation evidence

  • Asset management procedure
  • Information asset register
  • Technical asset inventory
  • Named owners
  • Classification and criticality
  • Discovery reconciliation reports
  • Lifecycle records
  • Exception tickets

Useful metrics

  • Assets with named owners
  • Unknown assets discovered
  • Inventory discrepancies overdue
  • Retired assets still active

Common mistakes

  • Inventorying hardware but not information or cloud services.
  • Assigning IT as owner for every asset.
  • Recording assets without dependencies or criticality.
  • Relying entirely on manual updates.
  • Keeping retired assets indefinitely.

Questions an auditor may ask

  • Which asset inventories are authoritative?
  • How are new assets added and retired?
  • Show how ownership and classification influence controls.
  • How do you detect unknown assets?
Implementation test: Select a critical business service and trace its information, application, infrastructure, supplier and facility dependencies to current owned records.

Continue through Annex A

Explore the growing library of practical guides for all 93 Annex A controls.

Open the ISO 27001 Annex A Control Library

This independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.