ISO 27001 Asset Management Policy Explained + Template

Stuart And Fay High Table

In this guide, you will learn what an ISO 27001 Asset Management Policy is, how to write it yourself and I give you a template you can download and use right away

ISO 27001 Asset Management Policy Explained

The ISO 27001 Asset Management Policy sets out the guidelines and framework for how identify, protect and manage assets. It covers the entire lifecycle from acquiring the asset, using the asset to ultimately destroying the asst. It ensures the correct assets are identified and protected. We cannot protect what we do not know.

Think of an ISO 27001 Asset Management Policy as a rulebook for all your company’s valuable stuff. This isn’t just about computers and desks; it’s about anything that has value to your business. This includes your customer data, software, intellectual property, and even the skills of your employees. The policy helps you keep track of these assets, protect them from harm, and ensure you know who’s responsible for what. It’s a key part of the ISO 27001 information security standard, which is all about keeping your sensitive information safe.

DimensionRequirement & Technical Best Practice
WhyProtects the organisation by preventing security incidents, ensuring GDPR compliance, and increasing efficiency through precise asset tracking.
WhenEstablish during the initial ISMS setup. Implement as early as possible to provide a foundation for risk assessment and control selection.
WhoAuthored by the CISO or IT Manager; however, 100% of staff must understand their personal responsibility for protecting assigned assets.
WhereApplies across all operational environments: physical offices, remote working setups, cloud instances, and all digital data storage.
HowProvision clear communication, execute mandatory employee training, enforce policy compliance, and conduct annual reviews for continual improvement.

Walkthrough

Template

The ISO 27001 Asset Management Policy Template is designed to fast track your implementation and give you an exclusive, industry best practice policy template that is pre written and ready to go. It is included in the ISO 27001 toolkit.

ISO 27001 Asset Management Policy Template

Example

Here is an extract.

ISO 27001 Asset Management Policy Example Page 1
ISO 27001 Asset Management Policy Page 1
ISO 27001 Asset Management Policy Example Page 2
ISO 27001 Asset Management Policy Page 2
ISO 27001 Asset Management Policy Example Page 3
ISO 27001 Asset Management Policy Page 3
ISO 27001 Asset Management Policy Example Page 4
ISO 27001 Asset Management Policy Page 4
ISO 27001 Asset Management Policy Example Page 5
ISO 27001 Asset Management Policy Page 5
ISO 27001 Asset Management Policy Example Page 6
ISO 27001 Asset Management Policy Page 6

How to write it yourself

To write an ISO 27001 Asset Management Policy, you must define the technical scope of information assets, assign individual ownership, and establish a formal classification scheme. This process ensures compliance with ISO 27001 Annex A 5.9 by documenting the entire asset lifecycle.

1. Define Technical Asset Scope and Purpose

Formalise what an “asset” is for your specific business environment. Provision a scope that encompasses all physical hardware (servers, laptops), virtual resources (cloud instances, databases), and intangible intellectual property (patents, software code). Clearly state that the purpose of the policy is the identification and managed protection of these assets across all business functions.

2. Assign Ownership and Individual Accountability

Assign every asset to a specific individual, job role, or team. Asset owners are technically accountable for ensuring assets are inventoried, classified, and handled in accordance with the Information Classification Policy. While routine tasks may be delegated, the formal responsibility for the asset’s security remains with the designated owner.

3. Inventory Physical and Virtual Assets

Establish a documented inventory for all processing devices. For every item, record the asset name, owner, and importance. For physical hardware, you must additionally provision fields for asset numbers, serial numbers, current usage status, and the date of the last technical health check to satisfy audit requirements for physical security.

4. Catalogue Data and Information Assets

Identify and record all data assets within a dedicated Information Asset Register (IAR). Provision fields for the name of the data controller, categories of data subjects, and data retention periods. For high-rigour compliance, include technical details such as international transfer status, lawful basis for processing (GDPR), and the volume of data processed.

5. Manage Software and Licence Assets

Provision a sub-inventory specifically for software versions and licences. Record whether the software is free or paid, the number of licences purchased versus used, and the precise deployment location. This ensures the organisation avoids legal risks associated with unlicensed software and maintains an accurate Software Bill of Materials (SBOM).

6. Establish Classification and Handling Schemes

Formalise a classification scheme (e.g., Public, Internal, Confidential) based on the asset’s importance to the business. Describe technical handling requirements for each level, such as mandatory full-disk encryption for “Confidential” data, to ensure that protection rigour scales with the level of risk identified.

7. Formalise the Asset Return and Disposal Lifecycle

Provision strict protocols for the return of organisational assets upon termination of employment or contracts. Implement technical procedures to ensure that if personal equipment was used, all company data is securely erased. During notice periods, execute controls to prevent unauthorised copying of company information by departing users.

8. Secure Senior Management Policy Approval

Formalise the policy with a Document Version Control table and a comprehensive contents page. Submit the completed Asset Management Policy to a senior leader or the CISO for formal review and sign-off. This approval provides the governance mandate required to enforce compliance across the organisation.

BYOD

To implement BYOD technical controls within an ISO 27001 framework, you must formalise a registration process, enforce Mobile Device Management (MDM) enrolment, and provision technical containerisation. This ensures that 100% of corporate data remains secured and wipeable without compromising employee privacy on personal hardware, satisfying the high-rigour demands of Annex A 7.9 and 8.1.

1. Formalise Device Registration and User Agreements

Provision a formal registration workflow where employees must declare personal devices used for business. Execute a signed BYOD Agreement that grants the organisation the technical right to manage corporate data on the device, ensuring a clear legal and technical mandate for security enforcement.

2. Enforce Mandatory MDM Enrollment

Execute a technical policy that mandates Mobile Device Management (MDM) enrollment for any device accessing corporate resources. Provision “Compliance Check” gates that block access to email or SaaS tools if the device is jailbroken, lacks a PIN, or has outdated firmware.

3. Provision Technical Data Containerisation

Implement technical containerisation (e.g., Work Profiles or Managed Apps) to create a logical partition between personal and corporate data. This ensures that the organisation can apply strict IAM roles and encryption to business data while remaining technically unable to access the user’s personal photos or messages.

4. Automate Selective Remote Wipe Protocols

Formalise an automated workflow for selective remote wipes. Provision the technical capability to delete 100% of corporate data from a personal device immediately upon an employee’s termination or if the device is reported lost, ensuring zero data leakage without affecting the user’s personal files.

How the ISO 27001 toolkit can help

The ISO 27001 toolkit is a collection of pre-written documents, policies, and templates. It’s like having a security expert guide you through the process. The toolkit provides you with a ready-made Asset Management Policy that you can easily adapt to your company, saving you a ton of time and effort.

ISO 27001 Toolkit Business Edition

How it applies to Small Businesses, Tech Startups, and AI Companies

SectorStrategic BenefitImplementation Example
Small BusinessesProvides a smart, organised framework to protect critical information like customer lists and financial records without requiring a massive budget.Classifying a customer list as “confidential” to ensure it is never shared externally without formal management approval.
Tech StartupsSecures the “lifeblood” of the company—code and intellectual property—to build competitive edge and investor trust.Storing source code in encrypted repositories with limited access and formalising access revocation for departing developers.
AI CompaniesSafeguards high-value models, training data, and algorithms that are subject to strict privacy rules and proprietary value.Ensuring training datasets are anonymised and encrypted, with access restricted solely to authorised data scientists.

Information security standards that need an Asset Management Policy

This asset management policy is a key part of ISO 27001, which is an international standard for managing information security. Other standards that need it include:

Standard / RegulationRequirement & Technical Context
ISO 27001The core international standard requirement under Clause 5.9 for identifying, documenting, and protecting information assets.
GDPRMandates an inventory of processing activities (ROPA), requiring clear identification of where personal data assets are stored and handled.
CCPARequires safeguarding consumer privacy through systematic asset identification and the implementation of reasonable security procedures.
DORAEssential for financial sector operational resilience, requiring detailed mapping of critical ICT assets and third-party dependencies.
NIS2Enhances supply chain security and risk management requirements, mandating strict asset governance for essential and important entities.
SOC 2Forms a key component of the Trust Services Criteria (TSC) regarding how an organisation identifies and manages its technical inventory.
NISTAligned with the NIST Cybersecurity Framework (CSF) ‘Identify’ function, focusing on asset management as the foundation of risk strategy.
HIPAARequired for protecting PHI (Protected Health Information) through formal administrative safeguards and rigorous device and media controls.

List of relevant ISO 27001 controls

The ISO 27001 standard has specific controls that relate to asset management. Here are a few key ones:

ISO 27001:2022 ControlImplementation Objective & Linkage
Annex A 5.9Inventory of information and other associated assets: Identification and documentation of all technical resources to ensure 100% visibility of the ISMS perimeter.
Annex A 5.10Acceptable use of information and other associated assets: Formalisation of rules and technical handling protocols for all staff and third-party users.
Annex A 5.11Return of assets: Managed decommissioning and technical recovery of hardware and data sets upon termination of employment or contracts.
Annex A 7.9Security of assets off-premises: Technical protection and physical security requirements for organisational assets used in remote or mobile environments.

FAQ

What is an asset management policy?

An asset management policy is a formal document that lays out the high-level strategy for managing an organisation’s physical and data assets. It serves as a statement of what you do (strategic intent), rather than how you do it (operational procedures). Detailed technical instructions are kept in separate operating documents to ensure the policy remains a stable governance anchor.

What is included in an asset management policy?

An ISO 27001 compliant asset management policy must contain, as a minimum:

  • Document Version Control and Contents Page
  • Defined Purpose and Scope
  • Core Principles and Asset Inventory requirements
  • Asset Ownership and Acceptable Use rules
  • Return of Assets protocols
  • Compliance measurement and Non-Compliance protocols
  • Commitment to Continual Improvement

What is the purpose of the asset management policy?

The primary purpose of the asset management policy is the systematic identification and managed protection of assets. By defining what constitutes an asset and who is responsible for it, the policy eliminates “Shadow IT” and ensures that 100% of information processing devices are secured against unauthorised access or loss.

What is the scope of the asset management policy?

The scope of the asset management policy covers all company employees, external contractors, and third-party users. It applies to all organisational information and physical assets, including cloud data, hardware used for remote work, and proprietary intellectual property, ensuring a consistent security posture across the entire ISMS perimeter.

What is the principle behind the asset management policy?

The fundamental asset management principle is that all organisational assets must be known, identified, and managed with appropriate technical protections in place. This lifecycle approach ensures that information is secured from initial acquisition through to final secure disposal.

How do you record and manage assets?

Assets are recorded and managed via a formal Information Asset Register (IAR). This inventory must identify all processing, storing, and transmitting devices. For every asset, you must record the asset name, the designated owner, its business importance, and its technical classification (e.g. Confidential or Public).

What extra data is needed for physical assets?

For physical hardware, auditors expect to see additional technical metadata in your register, including the unique asset/serial number, current usage status, the date of the last technical check, and a functional description of the asset’s role in processing or transmitting data.

Who owns assets and what are they responsible for?

Assets are assigned to specific individuals, roles, or teams known as Asset Owners. These owners are technically accountable for ensuring assets are inventoried, correctly classified, and protected. They must also manage the secure deletion or destruction of the asset in line with the Information Handling Policy, though they may delegate routine maintenance tasks.

Is the asset management policy required for ISO 27001 certification?

Yes, the asset management policy is a mandatory requirement for ISO 27001 certification. It provides the governance framework needed to satisfy Annex A Controls 5.9, 5.10, and 5.11, which are critical for passing a Stage 2 certification audit.

Why is IT asset management important?

IT asset management (ITAM) is critical because you cannot secure what you do not know. 65% of security breaches involve unmanaged assets. Having an effective lifecycle—from purchase to disposal—allows you to apply consistent technical controls, reduce financial waste, and protect the data on which your business relies.

What is the difference between an asset and a resource?

In ISO 27001, an asset is something of specific value that you own or control (like a database), while a resource is a broader term for tools, funding, or personnel used to achieve a task. Your policy focuses on protecting assets to ensure business continuity.

What happens if we lose an asset?

The policy must include a response plan for lost assets, such as immediate reporting to the IT department. Technical controls like Remote Wipe (MDM) should be triggered immediately to prevent data leakage from lost hardware like encrypted laptops or mobile devices.

How often is the asset management policy reviewed?

The policy must be reviewed after any significant technical change and at least annually. This ensures the ISMS remains effective against new threats, such as AI-driven social engineering or infrastructure risks introduced by the 2024 Climate Action Amendment to ISO 27001.

About the author

Stuart Barker
🎓 MSc Security 🛡️ Lead Auditor 30+ Years Exp 🏢 Ex-GE Leader

Stuart Barker

ISO 27001 Ninja

Stuart Barker is a veteran practitioner with over 30 years of experience in systems security and risk management. Holding an MSc in Software and Systems Security, he combines academic rigor with extensive operational experience, including a decade leading Data Governance for General Electric (GE).

As a qualified ISO 27001 Lead Auditor, Stuart possesses distinct insight into the specific evidence standards required by certification bodies. His toolkits represent an auditor-verified methodology designed to minimise operational friction while guaranteeing compliance.

Shopping Basket
Scroll to Top