ISO 27001 Annex A 5.9 Inventory of information and other associated assets requires organisations to identify and record all information assets. A complete asset inventory ensures teams track ownership, protect critical data, and maintain clear visibility across all business systems.
Table of contents
Key Takeaways
- Build a complete asset inventory: Identify and record all information, hardware, software, services, and physical assets across the business.
- Store registers centrally: Keep active asset registers, inventory policies, and review logs in a central document repository.
- Assign named asset owners: Designate a specific person or role responsible for protecting and managing each recorded asset.
- Track asset locations: Record where digital data, physical equipment, backups, and off-site services stay stored.
- Define asset criticality: Rate information assets by their business value, sensitivity level, and recovery priority.
- Manage full asset lifecycles: Track assets from initial purchase and setup through daily use to retirement and safe disposal.
- Run regular inventory checks: Audit asset registers periodically to remove obsolete entries and detect untracked equipment.
- Support risk management: Use accurate asset lists to run thorough risk assessments and select appropriate security safeguards.

How to Implement ISO 27001 Annex A 5.9
- Draft an asset management policy: Write clear guidelines for identifying, logging, and managing assets and store them centrally.
- Create an asset register template: Define standard fields including asset name, category, location, business owner, and sensitivity rating.
- Identify information assets: Catalog databases, source code, client records, intellectual property, contracts, and internal policies.
- Log supporting physical assets: Record company laptops, servers, network equipment, mobile devices, and physical filing systems.
- Include software and services: List operating systems, business applications, external service subscriptions, and utilities.
- Appoint asset custodians: Name operational leads who manage day-to-day access and maintenance under the asset owner’s direction.
- Integrate with procurement: Ensure purchasing workflows log new equipment and software in the inventory automatically.
- Set retirement procedures: Update inventory records when old assets are decommissioned, sanitized, or safely destroyed.
- Schedule annual reconciliation: Conduct physical and digital audits every year to verify register accuracy against real assets.
When you’re ready to bring compliance into one place

How to Audit ISO 27001 Annex A 5.9
- Review inventory policies: Inspect written procedures to verify standard methods exist for identifying and recording all asset types.
- Audit the central asset register: Sample inventory entries to confirm complete records exist for information, software, hardware, and services.
- Verify owner assignments: Check that every sampled asset links to an active, named individual or operational role.
- Conduct physical spot checks: Match a sample of physical laptops, servers, and office equipment against register entries.
- Perform digital asset sampling: Cross-check active software tools, databases, and network resources against the recorded register.
- Check decommissioned asset records: Verify that retired or disposed assets were promptly marked as retired in inventory logs.
- Interview asset owners: Speak with asset owners to verify they understand their responsibilities for asset protection and classification.
- Check reconciliation timestamps: Confirm that teams completed full inventory reviews and updates within the last twelve months.
Audit Evidence Checklist
- Asset management policy: Maintain a documented inventory policy with a complete version history in your central repository.
- Information asset register: Supply an up-to-date inventory listing all information assets, owners, locations, and sensitivity ratings.
- Hardware and software inventory: Provide active logs of physical devices, operating platforms, and third-party software subscriptions.
- Annual reconciliation reports: Provide records and sign-offs from periodic asset audits verifying physical and digital inventory accuracy.
- Asset onboarding forms: Supply procurement logs showing new hardware and software registrations upon purchase.
- Decommissioning tickets: Provide records showing the formal update and retirement of disposed assets in the register.
- Asset owner training records: Show sign-off sheets proving asset owners completed training on asset governance and security duties.
What to Teach Employees
- Report new assets: Teach workers to notify asset managers whenever they create new critical data stores or purchase tools.
- Understand asset ownership: Educate asset owners on their duties to define access rules, manage risks, and review permissions.
- Do not use shadow IT: Warn staff against adopting unapproved web tools, software, or personal storage for company data.
- Keep equipment tags intact: Instruct employees never to remove asset tags, serial stickers, or barcode labels from company hardware.
- Notify moves and changes: Remind staff to report when laptops, servers, or critical files move to new locations or teams.
- Report lost or damaged items: Ensure workers know to alert security teams fast if an asset goes missing or stops working.
Common Implementation Challenges
- Focusing only on hardware: Teams track physical laptops but forget data sets and software services. Catalog information assets first.
- Outdated static spreadsheets: Asset sheets get created once and never updated. Link inventory tools directly to procurement and ticketing.
- Missing asset ownership: Assets get listed without named owners. Assign clear business owners before adding assets to the register.
- Overly granular tracking: Logging every cable and mouse creates unmanageable lists. Group minor accessories and focus on risk-bearing assets.
- Untracked shadow software: Teams buy software tools on expense cards without registering them. Enforce strict expense approval checks.
- Neglecting asset disposal: Disposed equipment stays listed as active for years. Require inventory updates before closing disposal tickets.
How to Measure Effectiveness (KPIs)
- Asset register accuracy rate: Track the proportion of sampled assets matching inventory records during quarterly audits.
- Owner assignment coverage: Measure the percentage of recorded assets with assigned, verified, and active business owners.
- Unregistered asset discovery rate: Track the number of untracked devices or software services discovered during network scans.
- Annual inventory audit completion: Track the percentage of business departments completing annual asset reconciliation on time.
- Asset onboarding turnaround: Measure the average time taken to register newly purchased assets in the central inventory.
- Inventory audit finding count: Monitor the number of non-conformities raised against asset tracking during internal audits.
Related ISO 27001 Controls
ISO 27001 Control A 5.9 connects to several other ISO 27001 requirements:
Annex A 5.9 is the foundation for Annex A 5.12. Classification relies on accurate inventory data. It also supports Annex A 5.10 Acceptable Use. Without an inventory, you cannot enforce usage rules. Furthermore, it drives the risk assessment in Clause 6.1.2. Auditors check the link between assets and risks.
