ISO 27001 Physical Asset Register Explained + Template

Stuart Barker - High Table - ISO27001 Director

In this guide, you will learn what an ISO 27001 Physical Asset Register is, how to write it yourself and I give you a template you can download and use right away.

ISO 27001 Physical Asset Register Explained

Physical Asset Register is just a fancy name for an inventory of all your physical assets. We’re talking about things you can touch and see. This isn’t just a list, though; it’s a way to keep track of who uses what, where it’s located, and how important it is. It’s an essential document for showing you’re serious about protecting your assets.

Compliance AspectStrategic Description & PurposeTechnical Application & Technical Scope
Why You Need ItDemonstrates technical oversight to auditors. It facilitates risk identification, theft prevention, and lifecycle maintenance tracking.Annex A 5.9 Compliance & Risk Management
When You Need ItRequired from the point of hardware procurement. It is a fundamental component for achieving and maintaining ISO 27001 certification.Asset Onboarding & ISMS Planning
Where You Need ItApplicable to every physical and virtual item that supports business operations, including laptops, servers, routers, and secure access keys.Comprehensive Infrastructure Inventory
How to Write ItConstruct a centralised register (spreadsheet or tool) capturing Asset Name, Unique ID, Location, Responsible Owner, and Business Importance Level.Asset Classification & Accountability Mapping

You cannot control what you do not know so the ISO 27001 physical asset register is the register of all things that store, transmit or process data. There are some key things to record about assets.

Think of it as a detailed list of all your company’s physical stuff. It’s a key part of keeping your business’s information safe and sound, especially if you’re aiming for an ISO 27001 certification.

Template

The ISO 27001:2022 Physical Asset Register Template is designed to fast track your implementation and give you an exclusive, industry best practice policy template that is pre written and ready to go. It is included in the ISO 27001 toolkit.

ISO27001 Physical Asset Register Template

How to write it yourself

To implement an ISO 27001 asset register, you must identify every physical and virtual item that processes information. This formalised inventory satisfies Annex A 5.9 and Annex A 5.10, ensuring that technical accountability and acceptable use rules are enforced across your entire infrastructure.

Step 1: Define Inventory Scope and Categories

Provision a centralised list to categorise all hardware, software, and information assets within the ISMS boundary. This prevents “Shadow Assets” from creating unmanaged security risks.

  • Action: Audit server rooms, cloud consoles, and HR equipment logs.
  • Result: A formalised categorisation of assets including laptops, cloud instances, and proprietary datasets.

Step 2: Assign Technical and Business Ownership

Formalise accountability by assigning a specific owner to every asset entry. Owners are responsible for the security maintenance and lifecycle of the items they control.

  • Action: Map assets to specific IAM roles or department heads in the register.
  • Result: Clear accountability that satisfies the auditor’s requirement for asset governance.

Step 3: Classify Asset Criticality and CIA Values

Determine the importance of each asset based on Confidentiality, Integrity, and Availability (CIA). This classification dictates the level of technical protection required.

  • Action: Assign “High”, “Medium”, or “Low” tags based on data sensitivity levels.
  • Result: A prioritised risk profile that informs your Statement of Applicability (SoA).

Step 4: Establish Acceptable Use Policies

Link every asset class to an Acceptable Use Policy (AUP) to satisfy Annex A 5.10. Users must know the technical constraints for handling company assets.

  • Action: Distribute usage guidelines and require MFA for all virtual asset access.
  • Result: Reduced internal threat profile and documented proof of user compliance.

Step 5: Define Secure Disposal Procedures

Revoke access and sanitise hardware when assets reach end-of-life. You must prove to auditors that data remains protected during equipment decommissioning.

  • Action: Provision secure wipe protocols and collect serialised destruction certificates.
  • Result: A closed-loop lifecycle that prevents accidental data leakage.

Applicability to Small Businesses, Tech Startups, and AI Companies

This asset register is useful for businesses of all sizes, including small businesses, tech startups, and AI companies.

Organisation TypeStrategic Benefit & Compliance ValuePractical Inventory Examples
Small BusinessesVital for tracking even limited hardware suites. Ensures foundational protection for customer data stored on local laptops and servers.Individual developer laptops mapped to specific users, unique asset IDs for hardware, and physical location logs for on-site servers.
Tech StartupsBuilds a scalable security culture by accounting for physical innovation infrastructure and facility security systems.High-performance developer workstations, server racks located in co-location facilities, and biometric office access control systems.
AI CompaniesCritical for protecting high-capital core business assets including machine learning hardware and massive storage arrays.Specialised GPU clusters (High-end graphics cards), dedicated servers for AI model training, and high-speed network interconnects.

How the ISO 27001 Toolkit Can Help

Instead of starting from scratch, you can get a head start with an ISO 27001 toolkit. This includes pre-made templates for things like your physical asset register. They can save you tons of time and make sure you’ve got all the right fields and information to comply with the standard.

ISO 27001 Toolkit Business Edition

Information security standards that need it

This asst register is a key part of ISO 27001, which is an international standard for managing information security. Other standards that need it include:

Standard / RegulationFramework CategoryInventory Requirement Summary
ISO 27001International Standard (ISMS)Mandatory inventory of information and associated assets under Annex A 5.9.
GDPRStatutory Regulation (UK/EU)Requirement to maintain a Record of Processing Activities (ROPA) and hardware oversight.
CCPAStatutory Regulation (US)Mandates data mapping and inventory of consumer personal information assets.
DORAFinancial Regulation (EU)Strict requirements for the register of ICT assets and third-party service dependencies.
NIS2Critical Infrastructure DirectiveEnhanced inventory management for essential and important entities across member states.
SOC 2Attestation FrameworkTrust Services Criteria require the identification of all system components and assets.
NISTSecurity Framework (US)The ‘Identify’ function prioritises physical and software asset inventory (ID.AM).
HIPAAHealthcare Regulation (US)Mandates a hardware and electronic media inventory for PHI protection.

List of relevant ISO 27001 controls

The ISO 27001:2022 standard has specific controls that relate to a physical asset register. Some of the most important ones include:

Control ReferenceControl Title & Implementation LinkTechnical Requirement Summary
Annex A 5.9Inventory Of Information And Other Associated AssetsMandates a formalised record of all information assets to ensure accountability and technical lifecycle management.
Annex A 5.10Acceptable Use Of Information And Other Associated AssetsRequires documented rules and technical constraints for personnel handling physical and virtual infrastructure.
Annex A 5.11Return Of AssetsEnsures that all hardware and storage media are successfully returned and decommissioned upon termination of employment.
Annex A 7.9Security Of Assets Off-PremisesFocuses on the technical protection of assets (laptops, mobile devices, media) while utilised outside the organisational perimeter.

ISO 27001 Asset Classification & Handling Matrix

Your Asset Register is technically incomplete without a defined classification schema. Under Annex A 5.12, you must categorise assets based on their sensitivity to ensure appropriate levels of protection are applied. Use the following criteria to standardise your inventory labels:

Classification LabelTechnical Description & CriteriaMandatory Handling Controls
Restricted / CriticalAssets containing “Crown Jewel” IP, root encryption keys, or regulated health data (PHI).MFA + Hardware Security Module (HSM) + Monthly Access Audit.
ConfidentialStandard customer PII, internal financial records, and proprietary source code.Encryption at Rest/Transit + RBAC + Signed NDA.
InternalEmployee handbooks, non-sensitive project plans, and company-wide communications.Standard Corporate IAM + Secure VPN Access.
PublicMarketing materials, published whitepapers, and public website hardware.No specific integrity controls required beyond standard server hardening.

Lead Auditor Tip: If I see every asset marked as “Confidential” by default, I know you haven’t performed a real classification exercise. Effective classification allows you to focus your security budget on the Restricted assets that actually matter. Ensure your physical labels (asset tags) match these register entries.

ISO 27001 BYOD & Remote Asset Governance Matrix

Managing assets in a remote environment requires a transition from physical location tracking to Technical State Management. Under Annex A 6.7, you must implement measures to protect information accessed, processed, or stored at remote sites. If your staff use personal devices for work (BYOD), those devices must be governed by your register.

  • MDM Enrollment: All remote assets (Company or BYOD) should be enrolled in Mobile Device Management (MDM) to enforce encryption and allow for remote wipes.
  • Virtual Identification: Assign a unique ID to the “Virtual Instance” of a user’s workspace, not just the physical hardware.
  • Endpoint Verification: Use Zero-Trust principles to verify the security posture of an asset before allowing connection to the corporate VPN or SaaS environment.
  • De-provisioning Protocol: Establish a clear technical “Kill Switch” procedure to revoke access to all virtual assets immediately upon employee termination.
Control AreaCorporate-Owned AssetBYOD (Personal) Asset
Asset RegistrySerial Number + Technical SpecsVirtual UUID + User Agreement
Access ControlFull Admin Rights for ITContainerised / Managed App Level
Disposal / TerminationPhysical Return & Secure WipeRemote Revocation & Data Purge

Lead Auditor Tip: A common 2026 audit failure is the “BYOD Gap.” If your staff use personal phones for Slack or Email, but those phones aren’t on your register and aren’t governed by a Remote Working Policy, you are in breach of Annex A 6.7. Your register must reflect the logical asset, even if you don’t own the physical one.

FAQ

What is an ISO 27001 physical asset register used for?

An ISO 27001 physical asset register is used to record the physical devices that store, process or transmit data through an organisation. It records key control information because we cannot protect what we do not know about; therefore, we must record all devices to ensure 100% visibility across the ISMS.

How does an information security asset register differ from an accounting asset register?

An information security asset register only includes assets that process, store or transmit data. In contrast, an accounting asset register is a list of all fiscal assets and includes non-technical items such as screens, chairs, desks, and computer mice, which do not carry the same security risk profile.

What does an ISO 27001 physical asset register contain?

It contains a list of assets that process, store or transmit data along with control information: who owns the asset, its purpose, data processed, classification, criticality, physical characteristics, last review date/reviewer, and the current status of encryption and anti-virus software.

Where can I download an ISO 27001 physical asset register template?

An ISO 27001 physical asset register template can be downloaded from High Table: The ISO 27001 Company. This template is pre-configured to meet Annex A 5.9 requirements for technical audits.

What is the best format for an ISO 27001 physical asset register?

A spreadsheet works best for an ISO 27001 physical asset register (XLS/XLSX). This format allow for easy sorting, filtering by owner or review date, and simple integration into Risk Assessments (Clause 6.1.2) without the complexity of proprietary software.

What if I lose an item?

If an item is lost, you must mark it as “lost” in your register immediately, note the date, and initiate a search or incident response procedure. This provides a clear audit trail of the loss and triggers necessary security actions like remote wipes.

Does my physical asset register need to be digital?

No, it can be on paper, but a digital spreadsheet is significantly easier to manage, update, and secure. For ISO 27001 compliance, digital records provide better version control and accessibility during external audits.

What’s the difference between this and a regular inventory list?

This register is specifically focused on information security and is a mandatory requirement of the ISO 27001 standard. A regular inventory list tracks quantity and cost, whereas a security register tracks protection, ownership, and technical risk.

Do I need to track office furniture?

Not usually, unless the furniture holds a significant volume of sensitive information, such as a high-security filing cabinet. ISO 27001 focuses on the assets that present a risk to the Confidentiality, Integrity, or Availability of data.

Should I include software in this register?

No, software is documented in a different register. This inventory is dedicated exclusively to “physical stuff”—the hardware and tangible equipment that forms your infrastructure.

How often should I update the asset register?

You should update your register every time you add or remove an asset. Real-time updates are industry best practice, as statistics show 25% of audit failures occur due to “forgotten” hardware that was decommissioned but never removed from records.

What if an item is off-site?

You still track it and note its location, such as “Home Office” or “Remote.” Annex A 7.9 specifically requires the protection of assets off-premises, so documenting their location is vital for compliance.

Can one person manage the whole register?

Yes, but it is good business practice to have a backup person who understands the workflow. This ensures business continuity and prevents a single point of failure within your ISMS governance structure.

What if I have too many items?

You can group similar items together, such as “Dell Laptops (x15),” but for high-value or high-risk items, it is better to list each one separately with its own unique ID to ensure granular accountability.

What if a piece of equipment is old?

You must still track it! Even old equipment can be a security risk if it stores data or connects to your network. Tracking ensures it is properly sanitised and disposed of at the end of its lifecycle.

What if someone leaves the company?

You would update the owner field in the register and ensure the asset is successfully returned. This satisfies Annex A 5.11 (Return of Assets), which is a key check during termination of employment audits.

What if my company is all remote?

You still need to track all the equipment you have provided to your employees. Physical boundaries do not negate the requirement for an inventory; in fact, remote operations make a digital asset register even more critical.

Shopping Basket
Scroll to Top