The asset register is one of those ISO 27001 requirements that sounds straightforward but often catches organisations out in the audit. Either itâs too high-level to be useful, or itâs so granular that it becomes impossible to maintain.
Virtually everyone assumes itâs just about tracking laptops, desktops, phones, etc. Itâs more than that. It includes âInformation Assetsâ (your data).
This guide explains what an ISO 27001 asset register needs to contain, how to build one that works in practice, and the common mistakes to avoid.
What Is an ISO 27001 Asset Register?
An asset register (sometimes called an information asset register or asset inventory) is a documented list of the information assets your organisation holds, along with key details for each.
Itâs required by ISO 27001 Control 5.9 (Inventory of information and other associated assets), which states that your organisation shall identify information and other associated assets and maintain an inventory of them.
The register serves two purposes: it helps you understand what you have (so you can protect it), and it gives auditors the evidence they need to verify that you know your own information landscape.
What Counts as an Information Asset?
This is where many organisations get confused. âAssetâ in ISO 27001 means more than just laptops and servers. Information assets fall into several categories:
ISO 27001 Asset Register â Asset Types
Control 5.9 requires an inventory of all information and associated assets. Here are the five main categories.
Register
- Laptops & desktops
- Servers
- Mobile devices
- Printers & scanners
- Network equipment
- Removable media
- Office premises
- Customer data
- Employee records
- Financial data
- Contracts & legal docs
- Intellectual property
- ISMS documentation
- Backup data
- Operating systems
- Business applications
- Security software
- Databases
- Development tools
- Source code
- Licences
- Cloud platforms
- SaaS applications
- Internet & connectivity
- Email & collaboration
- Managed IT services
- Data centres
- Payment processing
- Key personnel
- Roles & skills
- Contractors
- Third-party staff
- Knowledge holders
- Security contacts
You donât need to include every single item. The register should cover assets that are material to your ISMS scope â the things that, if compromised, would have a meaningful impact on your business or your clients.
What Information Should the Register Capture?
For each asset, the register should capture:
Asset name â what is it? (e.g. âCustomer CRM databaseâ, âStaff laptopsâ, âMicrosoft 365 subscriptionâ)
Asset type â information, software, physical, or service
Description â a brief note on what the asset contains or does
Owner â who is responsible for the asset? This should be a named individual, not a team or department.
Classification â how sensitive is the information? (e.g. Confidential, Internal, Public â using whatever classification scheme youâve defined)
Location â where is the asset held? (e.g. Azure UK South, on-premises server room, staff home offices)
Risk level â a high-level indication of the risk associated with this asset, often derived from your risk assessment
Applicable controls â a reference to the controls in place to protect the asset
Some organisations also include:
- The legal basis for holding the data (relevant for GDPR)
- Retention period (how long you keep it)
- Disposal method
How Granular Should You Go?
This is the question that trips people up often, and the answer matters more than people realise.
The key principle is this: you need to know what you have, whoâs responsible for it, and where it is.
Without that, you canât manage risk, you canât respond to incidents, and you canât demonstrate control to an auditor.
For physical devices in particular, individual-level tracking isnât optional â itâs essential. If John Smith leaves and you donât know which laptop was his, you canât verify that itâs been returned, wiped, or decommissioned. Thatâs not a documentation problem, itâs a security problem. Individual devices â laptops, phones, tablets â should be recorded individually with an assigned user or location.
Where you can afford to be less granular is with asset classes that donât carry individual risk profiles. Good examples:
- âStaff laptops (Windows 11) â 12 devices, each assigned to named userâ â Right level
- âMicrosoft 365 (Teams, Exchange, SharePoint, OneDrive)â â Right level
- âEach individual SharePoint siteâ â Too granular for most ISMSs
- âLaptops â general poolâ with no user assignment â Not enough
The test is: if a security incident occurred, or an employee left tomorrow, would this register tell you everything you need to know to respond? If yes, the granularity is right. If youâd have to go hunting for basic information, you need more detail.
For most small organisations, the practical approach is to track physical devices individually, cloud services and software at the system level, and information assets by category â then link each to a named owner.
Who Should Own Each Asset?
Asset ownership is a crucial and misunderstood aspect of the register.
Every asset should have a named owner. The owner is responsible for:
- Ensuring the asset is appropriately protected
- Approving changes to how the asset is used or accessed
- Making decisions about risk acceptance for that asset
- Keeping the register entry accurate
In small organisations, one person might own many assets. Thatâs fine. Whatâs not fine is having no named owner â auditors will flag this.
Avoid making the IT team or the âIT managerâ the default owner of every asset.
Business-owned data (customer records, financial data) should be owned by business people. The CRM database isnât an IT asset â itâs a sales or operations asset that IT happens to manage.
Building the Register: A Step-by-Step Approach
Step 1: Define the scope
Before you start listing assets, confirm which parts of your business are in scope for the ISMS. Assets outside the scope donât need to be in the register.
Step 2: Brainstorm with asset owners
Donât try to build the register alone. Run short conversations with the heads of each business function â sales, operations, finance, HR, IT â and ask: âWhat information do you use, create, or store in your work?â Youâll uncover assets you hadnât thought of.
Step 3: Map data flows
Understanding how information flows through your organisation helps you spot assets you might have missed. Trace a piece of customer data from initial contact to disposal â where does it go? What systems touch it?
You might think it overkill, but knowing this is really important if you have a complex business and lots of data. In smaller businesses, you may just know it â but it canât hurt to document.
Step 4: Categorise and classify
Once you have a list, categorise each entry (information, software, physical, service) and apply your classification scheme. This is also when you assign owners.
Step 5: Link to your risk assessment
The asset register and the risk assessment are closely linked. Once your register is built, use it to inform which assets you consider in your risk assessment. The risks you identify will, in turn, tell you what controls you need.
Step 6: Review and maintain
The register is a living document. Set a schedule to review it â at minimum annually, or whenever a significant change happens (new system, new supplier, new office). Outdated asset registers are a common audit finding.
Common Mistakes to Avoid
- No named owners. Every asset must have a named individual responsible for it.
- IT assets only. Non-IT staff often have information assets â printed records, shared drives, client files â that donât appear in IT-led asset inventories. Make sure youâve captured the full picture.
- Never reviewing it. An asset register from three years ago that hasnât been updated is worse than no register â it may actually mislead you about what you hold.
- Confusing the register with an ITAM database. Asset management tools are useful but serve a different purpose. Your ISO 27001 register should cover information assets across the business, not just hardware managed by IT.
- Classifying everything as âConfidential.â If everything is equally sensitive, the classification is meaningless. Be honest about whatâs actually sensitive and whatâs genuinely low-risk.
Free Templates
The ISO 27001 toolkit includes a pre-built asset register template in Excel, aligned to ISO/IEC 27001:2022. Itâs formatted with all the right columns, includes worked examples, and links to the other registers and documents in the toolkit.
You can also read more about Control 5.9 for a deeper look at what the standard specifically requires from this control.
/pattern
ISO 27001 Online Course + Full Toolkit
Stop guessing. Follow a proven step-by-step process.
âHighly recommended for anyone looking to understand ISO 27001, whether attempting it on your own or even using a consultant.â
Verified Trust.me Review
â Full toolkit included â Learn as you build â 12-month access â 6 hours of video â Email consultancy
FAQs
Does every laptop need its own entry in the asset register?
For physical devices like laptops, phones, and tablets â yes. Knowing that you have twelve laptops isnât enough; you need to know which device is assigned to which person. If an employee leaves and you canât identify which laptop was theirs, you canât verify itâs been returned and wiped. Thatâs not a documentation gap, itâs a security gap. Individual device tracking is essential. Where you can be less granular is with software and services â âMicrosoft 365â as a single entry is perfectly appropriate, rather than listing every mailbox or SharePoint site.
How do we keep the asset register up to date?
Build a review trigger into your onboarding and offboarding processes (Joiners/Movers/Leavers) â every time a device is issued or returned, the register should be updated. Beyond that, set a formal annual review where asset owners confirm their entries are still accurate, and review it whenever something significant changes: a new system, a new supplier, a new office location, or a major project that introduces new data flows. Outdated registers are one of the most common findings in certification audits.
Who should own assets in the register â IT or the business?
Both, depending on the asset. The default instinct is to make IT the owner of everything, but thatâs usually wrong. Customer records are owned by sales or operations. Financial data is owned by finance. HR data is owned by HR. IT manages the systems that hold the data, but the business function that uses and is accountable for the data should be the named owner. This matters because the owner is responsible for risk decisions, access approvals, and keeping the register entry accurate â those are business decisions, not purely IT ones.
Whatâs the difference between an asset register and an IT asset management database?
An IT asset management (ITAM) database tracks hardware and software for operational purposes â warranty dates, licence counts, hardware specs. An ISO 27001 asset register is broader: it covers information assets (the data itself), services, and people knowledge, not just physical hardware. The two can complement each other, but they serve different purposes. Your ITAM tool might be a useful source of data for the physical assets section of your register, but it wonât cover the rest of what ISO 27001 requires.
Does the asset register need to link to the risk assessment?
Yes â and this is where the register earns its value. The asset register tells you what you have; the risk assessment uses that information to identify what could go wrong with each asset and what controls are needed. If your register and risk assessment arenât connected, you may end up with risks that reference assets that donât exist in the register, or assets in the register that havenât been considered in the risk assessment. Build the register first, then use it as the foundation for your risk assessment.
