In this guide, you will learn what an ISO 27001 Asset Management Policy is, how to write it yourself and I give you a template you can download and use right away
Table of contents
- ISO 27001 Asset Management Policy Explained
- Walkthrough
- Template
- Example
- How to write it yourself
- BYOD
- How the ISO 27001 toolkit can help
- How it applies to Small Businesses, Tech Startups, and AI Companies
- Information security standards that need an Asset Management Policy
- List of relevant ISO 27001 controls
- FAQ
ISO 27001 Asset Management Policy Explained
The ISO 27001 Asset Management Policy sets out the guidelines and framework for how identify, protect and manage assets. It covers the entire lifecycle from acquiring the asset, using the asset to ultimately destroying the asst. It ensures the correct assets are identified and protected. We cannot protect what we do not know.
Think of an ISO 27001 Asset Management Policy as a rulebook for all your company’s valuable stuff. This isn’t just about computers and desks; it’s about anything that has value to your business. This includes your customer data, software, intellectual property, and even the skills of your employees. The policy helps you keep track of these assets, protect them from harm, and ensure you know who’s responsible for what. It’s a key part of the ISO 27001 information security standard, which is all about keeping your sensitive information safe.
| Dimension | Requirement & Technical Best Practice |
|---|---|
| Why | Protects the organisation by preventing security incidents, ensuring GDPR compliance, and increasing efficiency through precise asset tracking. |
| When | Establish during the initial ISMS setup. Implement as early as possible to provide a foundation for risk assessment and control selection. |
| Who | Authored by the CISO or IT Manager; however, 100% of staff must understand their personal responsibility for protecting assigned assets. |
| Where | Applies across all operational environments: physical offices, remote working setups, cloud instances, and all digital data storage. |
| How | Provision clear communication, execute mandatory employee training, enforce policy compliance, and conduct annual reviews for continual improvement. |
Walkthrough
Template
The ISO 27001 Asset Management Policy Template is designed to fast track your implementation and give you an exclusive, industry best practice policy template that is pre written and ready to go. It is included in the ISO 27001 toolkit.

Example
Here is an extract.
How to write it yourself
To write an ISO 27001 Asset Management Policy, you must define the technical scope of information assets, assign individual ownership, and establish a formal classification scheme. This process ensures compliance with ISO 27001 Annex A 5.9 by documenting the entire asset lifecycle.
1. Define Technical Asset Scope and Purpose
Formalise what an “asset” is for your specific business environment. Provision a scope that encompasses all physical hardware (servers, laptops), virtual resources (cloud instances, databases), and intangible intellectual property (patents, software code). Clearly state that the purpose of the policy is the identification and managed protection of these assets across all business functions.
2. Assign Ownership and Individual Accountability
Assign every asset to a specific individual, job role, or team. Asset owners are technically accountable for ensuring assets are inventoried, classified, and handled in accordance with the Information Classification Policy. While routine tasks may be delegated, the formal responsibility for the asset’s security remains with the designated owner.
3. Inventory Physical and Virtual Assets
Establish a documented inventory for all processing devices. For every item, record the asset name, owner, and importance. For physical hardware, you must additionally provision fields for asset numbers, serial numbers, current usage status, and the date of the last technical health check to satisfy audit requirements for physical security.
4. Catalogue Data and Information Assets
Identify and record all data assets within a dedicated Information Asset Register (IAR). Provision fields for the name of the data controller, categories of data subjects, and data retention periods. For high-rigour compliance, include technical details such as international transfer status, lawful basis for processing (GDPR), and the volume of data processed.
5. Manage Software and Licence Assets
Provision a sub-inventory specifically for software versions and licences. Record whether the software is free or paid, the number of licences purchased versus used, and the precise deployment location. This ensures the organisation avoids legal risks associated with unlicensed software and maintains an accurate Software Bill of Materials (SBOM).
6. Establish Classification and Handling Schemes
Formalise a classification scheme (e.g., Public, Internal, Confidential) based on the asset’s importance to the business. Describe technical handling requirements for each level, such as mandatory full-disk encryption for “Confidential” data, to ensure that protection rigour scales with the level of risk identified.
7. Formalise the Asset Return and Disposal Lifecycle
Provision strict protocols for the return of organisational assets upon termination of employment or contracts. Implement technical procedures to ensure that if personal equipment was used, all company data is securely erased. During notice periods, execute controls to prevent unauthorised copying of company information by departing users.
8. Secure Senior Management Policy Approval
Formalise the policy with a Document Version Control table and a comprehensive contents page. Submit the completed Asset Management Policy to a senior leader or the CISO for formal review and sign-off. This approval provides the governance mandate required to enforce compliance across the organisation.
BYOD
To implement BYOD technical controls within an ISO 27001 framework, you must formalise a registration process, enforce Mobile Device Management (MDM) enrolment, and provision technical containerisation. This ensures that 100% of corporate data remains secured and wipeable without compromising employee privacy on personal hardware, satisfying the high-rigour demands of Annex A 7.9 and 8.1.
1. Formalise Device Registration and User Agreements
Provision a formal registration workflow where employees must declare personal devices used for business. Execute a signed BYOD Agreement that grants the organisation the technical right to manage corporate data on the device, ensuring a clear legal and technical mandate for security enforcement.
2. Enforce Mandatory MDM Enrollment
Execute a technical policy that mandates Mobile Device Management (MDM) enrollment for any device accessing corporate resources. Provision “Compliance Check” gates that block access to email or SaaS tools if the device is jailbroken, lacks a PIN, or has outdated firmware.
3. Provision Technical Data Containerisation
Implement technical containerisation (e.g., Work Profiles or Managed Apps) to create a logical partition between personal and corporate data. This ensures that the organisation can apply strict IAM roles and encryption to business data while remaining technically unable to access the user’s personal photos or messages.
4. Automate Selective Remote Wipe Protocols
Formalise an automated workflow for selective remote wipes. Provision the technical capability to delete 100% of corporate data from a personal device immediately upon an employee’s termination or if the device is reported lost, ensuring zero data leakage without affecting the user’s personal files.
How the ISO 27001 toolkit can help
The ISO 27001 toolkit is a collection of pre-written documents, policies, and templates. It’s like having a security expert guide you through the process. The toolkit provides you with a ready-made Asset Management Policy that you can easily adapt to your company, saving you a ton of time and effort.
How it applies to Small Businesses, Tech Startups, and AI Companies
| Sector | Strategic Benefit | Implementation Example |
|---|---|---|
| Small Businesses | Provides a smart, organised framework to protect critical information like customer lists and financial records without requiring a massive budget. | Classifying a customer list as “confidential” to ensure it is never shared externally without formal management approval. |
| Tech Startups | Secures the “lifeblood” of the company—code and intellectual property—to build competitive edge and investor trust. | Storing source code in encrypted repositories with limited access and formalising access revocation for departing developers. |
| AI Companies | Safeguards high-value models, training data, and algorithms that are subject to strict privacy rules and proprietary value. | Ensuring training datasets are anonymised and encrypted, with access restricted solely to authorised data scientists. |
Information security standards that need an Asset Management Policy
This asset management policy is a key part of ISO 27001, which is an international standard for managing information security. Other standards that need it include:
| Standard / Regulation | Requirement & Technical Context |
|---|---|
| ISO 27001 | The core international standard requirement under Clause 5.9 for identifying, documenting, and protecting information assets. |
| GDPR | Mandates an inventory of processing activities (ROPA), requiring clear identification of where personal data assets are stored and handled. |
| CCPA | Requires safeguarding consumer privacy through systematic asset identification and the implementation of reasonable security procedures. |
| DORA | Essential for financial sector operational resilience, requiring detailed mapping of critical ICT assets and third-party dependencies. |
| NIS2 | Enhances supply chain security and risk management requirements, mandating strict asset governance for essential and important entities. |
| SOC 2 | Forms a key component of the Trust Services Criteria (TSC) regarding how an organisation identifies and manages its technical inventory. |
| NIST | Aligned with the NIST Cybersecurity Framework (CSF) ‘Identify’ function, focusing on asset management as the foundation of risk strategy. |
| HIPAA | Required for protecting PHI (Protected Health Information) through formal administrative safeguards and rigorous device and media controls. |
List of relevant ISO 27001 controls
The ISO 27001 standard has specific controls that relate to asset management. Here are a few key ones:
| ISO 27001:2022 Control | Implementation Objective & Linkage |
|---|---|
| Annex A 5.9 | Inventory of information and other associated assets: Identification and documentation of all technical resources to ensure 100% visibility of the ISMS perimeter. |
| Annex A 5.10 | Acceptable use of information and other associated assets: Formalisation of rules and technical handling protocols for all staff and third-party users. |
| Annex A 5.11 | Return of assets: Managed decommissioning and technical recovery of hardware and data sets upon termination of employment or contracts. |
| Annex A 7.9 | Security of assets off-premises: Technical protection and physical security requirements for organisational assets used in remote or mobile environments. |
FAQ
What is an asset management policy?
An asset management policy is a formal document that lays out the high-level strategy for managing an organisation’s physical and data assets. It serves as a statement of what you do (strategic intent), rather than how you do it (operational procedures). Detailed technical instructions are kept in separate operating documents to ensure the policy remains a stable governance anchor.
What is included in an asset management policy?
An ISO 27001 compliant asset management policy must contain, as a minimum:
- Document Version Control and Contents Page
- Defined Purpose and Scope
- Core Principles and Asset Inventory requirements
- Asset Ownership and Acceptable Use rules
- Return of Assets protocols
- Compliance measurement and Non-Compliance protocols
- Commitment to Continual Improvement
What is the purpose of the asset management policy?
The primary purpose of the asset management policy is the systematic identification and managed protection of assets. By defining what constitutes an asset and who is responsible for it, the policy eliminates “Shadow IT” and ensures that 100% of information processing devices are secured against unauthorised access or loss.
What is the scope of the asset management policy?
The scope of the asset management policy covers all company employees, external contractors, and third-party users. It applies to all organisational information and physical assets, including cloud data, hardware used for remote work, and proprietary intellectual property, ensuring a consistent security posture across the entire ISMS perimeter.
What is the principle behind the asset management policy?
The fundamental asset management principle is that all organisational assets must be known, identified, and managed with appropriate technical protections in place. This lifecycle approach ensures that information is secured from initial acquisition through to final secure disposal.
How do you record and manage assets?
Assets are recorded and managed via a formal Information Asset Register (IAR). This inventory must identify all processing, storing, and transmitting devices. For every asset, you must record the asset name, the designated owner, its business importance, and its technical classification (e.g. Confidential or Public).
What extra data is needed for physical assets?
For physical hardware, auditors expect to see additional technical metadata in your register, including the unique asset/serial number, current usage status, the date of the last technical check, and a functional description of the asset’s role in processing or transmitting data.
Who owns assets and what are they responsible for?
Assets are assigned to specific individuals, roles, or teams known as Asset Owners. These owners are technically accountable for ensuring assets are inventoried, correctly classified, and protected. They must also manage the secure deletion or destruction of the asset in line with the Information Handling Policy, though they may delegate routine maintenance tasks.
Is the asset management policy required for ISO 27001 certification?
Yes, the asset management policy is a mandatory requirement for ISO 27001 certification. It provides the governance framework needed to satisfy Annex A Controls 5.9, 5.10, and 5.11, which are critical for passing a Stage 2 certification audit.
Why is IT asset management important?
IT asset management (ITAM) is critical because you cannot secure what you do not know. 65% of security breaches involve unmanaged assets. Having an effective lifecycle—from purchase to disposal—allows you to apply consistent technical controls, reduce financial waste, and protect the data on which your business relies.
What is the difference between an asset and a resource?
In ISO 27001, an asset is something of specific value that you own or control (like a database), while a resource is a broader term for tools, funding, or personnel used to achieve a task. Your policy focuses on protecting assets to ensure business continuity.
What happens if we lose an asset?
The policy must include a response plan for lost assets, such as immediate reporting to the IT department. Technical controls like Remote Wipe (MDM) should be triggered immediately to prevent data leakage from lost hardware like encrypted laptops or mobile devices.
How often is the asset management policy reviewed?
The policy must be reviewed after any significant technical change and at least annually. This ensures the ISMS remains effective against new threats, such as AI-driven social engineering or infrastructure risks introduced by the 2024 Climate Action Amendment to ISO 27001.

