In this guide you will learn how to implement ISO 27001 Annex A 5.9 Inventory of Information and Other Associated Assets and pass your audit from ISO 27001 Lead Auditor Stuart Barker – author of the ultimate ISO 27001 Toolkit.
ISO 27001 Annex A 5.9 is an ISO 27001 control that requires an organisation to develop and maintain an inventory of information and other associated assets.
Table of contents
- Purpose & Definition
- FREE ISO 27001 Annex A 5.9 Training Video
- ISO 27001 Annex A 5.9 Requirements and Guidance
- How to implement ISO 27001 Annex A 5.9
- How to comply
- How to audit ISO 27001 Annex A 5.9
- How to pass the ISO 27001 Annex A 5.9 audit
- What will an audit check?
- Top 3 Mistakes People Make and How to Avoid Them
- ISO 27001 Annex A 5.9 FAQ
- ISO 27001 Relate Controls and Further Reading
- ISO 27001 Controls and Attribute Values
- About the author
Purpose & Definition
The purpose of ISO 27001 Annex A 5.9 is to ensure you identify the organisations information and other associated assets in order to preserve their information security and assign appropriate ownership.
The ISO 27001 standard defines ISO 27001 Annex A 5.9 as:
An inventory of information and other associated assets, including owners, should be developed and maintained.
ISO 27001:2022 Annex A 5.9 Inventory of information and other associated assets
ISO 27001 Starter Kit
Instant download of mandatory ISMS core policies and documentation. Verified by Lead Auditors and used by 5,000+ businesses worldwide to pass Stage 1 certification first time.
FREE ISO 27001 Annex A 5.9 Training Video
In this free training video you will learn How to implement ISO 27001 Inventory Assets (Annex A 5.9) and Pass Your Audit
ISO 27001 Annex A 5.9 Requirements and Guidance
You are going to have to ensure that
- information and assets are identified
- the importance of information and assets is determined
- information and assets are documented
- documentation is accurate, up to date and consistent
- the location of assets is recorded
- assets are classified
- ownership of assets is allocated when created or transferred to the organisation and reassigned when current owners leave or change role
Topic specific policy on asset management
You are going to implement a topic specific policy on asset management. You can learn more in our Beginner’s Guide to the Asset Management Policy.
Asset Management Policy Template
The asset management policy sets out your approach to asset management.

Data Asset Register
You will implement a Data Asset Register.
Data Asset Register Template
The data asset register is where you record your data assets. It is a data inventory.

Physical Asset Register
You will implement a Physical Asset Register that will include virtual machines. You can learn more in our Beginner’s Guide to the Physical Asset Register.
Physical Asset Register Template
The physical asset register is where you record your physical assets. It is a physical inventory.

Return of assets
You will implement a process for the return of assets in line with the guidance in ISO 27001 Annex A 5.11 Return of Assets
Acceptable use of assets
You will implement a process for the acceptable use of assets in line with the guidance in ISO 27001 Annex A 5.10 Acceptable use of information and other associated assets.
What about virtual machines?
The standard has been updated to account for virtual machines. It sets out that the level of detail required should be appropriate of the needs of the organisation.
Sometimes it just isn’t feasible to document instances of virtual machines especially if they are short lived as is the case with some virtual machines that can be short lived and have a short duration. That is ok.
Asset Ownership
Assets need to be assigned an owner. The standard allows for ownership to be individuals or groups. Where possible you should try to identify individuals. This can be either named individuals or the job title of the role. By allocating to an individual it will drive more accountability than assigning to a group of people.
What are asset owners duties?
The asset owner is going to be responsible for the management and protection of the asset over its entire lifecycle. They are going to
- Make sure assets are document and in asset registers
- Ensure assets have the correct classification and protection
- Review assets and set intervals which will include access to the asset and the controls protecting the asset
- Put in place the acceptable use requirements for the asset
- Be responsible for the correct deletion / disposal of the asset and the documentation recording it including removing from asset registers.
- Be part of the risk identification and risk management of the assets
How to implement ISO 27001 Annex A 5.9
Implementing Annex A 5.9 requires a systematic approach to identifying and documenting every asset that supports your Information Security Management System (ISMS). Following these steps ensures that protection levels remain proportionate to the value and risk of each specific asset, satisfying the core requirements of ISO 27001.
1. Define the Asset Taxonomy and Scope
- Identify all categories of assets including hardware, software, information, and outsourced services.
- Establish clear boundaries for what constitutes an asset within the ISMS scope.
- Result: A comprehensive classification framework that ensures no critical data or hardware is overlooked during the inventory process.
2. Assign Formal Asset Ownership
- Designate an individual owner for every identified asset or asset group.
- Define the owner’s responsibilities for classification, access authorisation, and periodic reviews.
- Result: Clear accountability for the protection and maintenance of assets throughout their operational life.
3. Build a Centralised Asset Register
- Create a single source of truth, such as a database or spreadsheet, to host all asset records.
- Ensure the register is accessible to relevant security personnel but protected against unauthorised modification.
- Result: A searchable, managed repository that facilitates rapid incident response and risk assessment.
4. Classify Information and Associated Assets
- Apply classification labels based on the sensitivity and value of the information stored on or processed by the asset.
- Align these labels with your organisational Information Classification Policy.
- Result: The application of security controls that are commensurate with the asset’s importance to the business.
5. Document Technical Metadata and Physical Location
- Record specific technical details including serial numbers, software versions, and physical or logical locations.
- Include cloud service regions for virtual assets to satisfy data residency requirements.
- Result: Granular visibility into the technical environment, enabling better patch management and physical security.
6. Link Assets to IAM Roles and Access Governance
- Map each asset to specific Identity and Access Management (IAM) roles and groups.
- Enforce Multi-Factor Authentication (MFA) for assets containing highly sensitive or “Confidential” information.
- Result: A hardened security posture where access is restricted based on the principle of least privilege.
7. Manage Mobile and Removable Media Assets
- Include laptops, mobile phones, and encrypted USB drives in the inventory.
- Track the issuance of these devices to specific employees or contractors.
- Result: Reduced risk of data loss from portable devices and improved tracking of hardware outside the office.
8. Formalise the Asset Lifecycle and ROE
- Develop a Record of Equipment (ROE) to track assets from procurement to decommissioning.
- Implement secure disposal procedures to ensure all data is wiped before hardware leaves the organisation.
- Result: An auditable trail of asset movement that prevents “ghost” assets from remaining in the register.
9. Map Asset Dependencies to Business Processes
- Identify which business processes rely on specific assets to function.
- Document dependencies between hardware, software, and the data they process.
- Result: Enhanced Business Continuity Planning (BCP) and more accurate Business Impact Analysis (BIA).
10. Schedule Periodic Reconciliations and Audits
- Conduct quarterly or annual physical and logical audits to verify the accuracy of the register.
- Update the inventory immediately following significant changes or infrastructure migrations.
- Result: Continuous compliance with Annex A 5.9 and a reliable foundation for the internal audit process.
Check Your Work?
You buit it yourself. Maybe with AI. But will it pass the audit?
Don’t gamble – let a trained ISO 27001 auditor check your work.

How to comply
To comply with ISO 27001 Annex A 5.9 Inventory of information and other associated assets you are going to implement the ‘how’ to the ‘what’ the control is expecting. In short measure you are going to:
- Establish and document asset inventories
- Identify, list and document the assets
- Assign owners to assets
- Protect and ensure adequate controls for assets based on risk and classification
- Review asset inventories and access to assets
How to audit ISO 27001 Annex A 5.9
Auditing Annex A 5.9 requires a rigorous examination of how an organisation identifies, tracks, and manages its information assets. As a Lead Auditor, I look for evidence that the inventory is not merely a static document but a living record that accurately reflects the technical and operational landscape of the business. Use the following steps to verify compliance and ensure asset accountability.
1. Review the Asset Management Policy and Governance
- Examine the formal policy to ensure it defines the scope of assets, including hardware, software, information, and cloud services.
- Verify that the policy has been approved by management and communicated to all relevant stakeholders.
- Result: Confirmation that a structured framework exists to govern the identification and protection of assets.
2. Inspect the Master Asset Register for Completeness
- Evaluate the central Asset Register to ensure it captures mandatory fields such as asset name, description, and location.
- Check that the inventory includes intangible assets, such as intellectual property and proprietary data, alongside physical hardware.
- Result: Assurance that the organisation has a single source of truth for its information security environment.
3. Validate Individual Asset Ownership and Accountability
- Sample items from the register to verify that a specific individual or role is assigned as the formal asset owner.
- Confirm that owners understand their responsibilities for classification and periodic access reviews.
- Result: Evidence of clear accountability for the lifecycle and security of each documented asset.
4. Audit the Record of Equipment (ROE) and Procurement Links
- Cross-reference the Asset Register with procurement records and Record of Equipment (ROE) logs to identify “ghost” assets.
- Verify that new purchases are automatically triggered for inclusion in the inventory during the provisioning phase.
- Result: Proof that the inventory process is integrated into the wider organisational procurement lifecycle.
5. Examine Identification and Unique Labelling Protocols
- Assess the methods used to uniquely identify assets, such as serial numbers, asset tags, or digital identifiers.
- Verify that logical assets, like databases or virtual machines, are uniquely identified within system management tools.
- Result: Assurance that assets can be specifically identified during incident response or maintenance activities.
6. Verify Mobile Device and Removable Media Tracking
- Review the specific controls for tracking high-risk portable assets like laptops, mobile phones, and encrypted USB drives.
- Check the issuance logs to ensure these assets are mapped to specific employees or contractors.
- Result: Mitigation of data loss risks through strict oversight of portable and removable equipment.
7. Analyse Virtual and Cloud-Based Asset Listings
- Inspect the inventory of cloud-based assets, including SaaS subscriptions, IaaS instances, and PaaS environments.
- Verify that cloud assets are reviewed with the same level of scrutiny as physical, on-site hardware.
- Result: Comprehensive visibility into the modern, distributed technical stack and associated security risks.
8. Assess Asset Classification and IAM Alignment
- Verify that each asset in the inventory is assigned a classification level in accordance with the Information Classification Policy.
- Check that access to high-value assets is governed by Identity and Access Management (IAM) roles and enforced via MFA.
- Result: Confirmation that security controls are proportionate to the sensitivity and value of the information.
9. Perform Physical and Logical Spot Checks
- Conduct “floor-to-list” and “list-to-floor” audits by physically verifying hardware or logically checking software versions.
- Note any discrepancies between the observed state and the data recorded in the Asset Register.
- Result: Real-world validation of the accuracy and integrity of the asset management system.
10. Review Reconciliation and Maintenance Records
- Examine evidence of periodic inventory reconciliations to ensure the register is updated following disposals or migrations.
- Check for exception reports that identify missing or unauthorised assets within the network.
- Result: Demonstration of a mature, continuously monitored process that maintains compliance with ISO 27001 requirements.
How to pass the ISO 27001 Annex A 5.9 audit
To pass an audit of ISO 27001 Annex A 5.9 Inventory of information and other associated assets you are going to make sure that you have followed the steps above in how to comply.
What will an audit check?
The audit is going to check a number of areas. Lets go through the main ones
1. That you have an inventory of assets
What this means is that you need to show that you have asset inventories in place. It does not need to be one inventory but every asset must be in an inventory.
2. That you have taken action as a result of asset inventories
Your asset registers and asset inventories are going to be living documents with asset owners documented and assigned and the key controls and required components of the registers recorded. The audit will check that reviews are performed and that access to assets has been performed. It will check the implemented and documented controls that protect those assets.
3. That asset inventory forms part of risk management and operations
Your asset register will factor in and evidence risk management. This could be management of the risks associated with assets or the risks that the assets themselves pose.
Top 3 Mistakes People Make and How to Avoid Them
The top 3 Mistakes People Make For ISO 27001 Annex A 5.9 are
1. Your asset register and asset inventory does not include all assets
Remembering the scope is the scope statement and your ISO 27001 scope it is easy to focus on data assets that relate to data protection and miss the wider data assets. Code repositories are a good example. Focusing on productions assets and not considering development and test. Stating that VMS are not assets or are too hard to manage and document.
2. You do not evidence ownership or actions
Be sure owners are assigned and that actions such as access reviews and asset reviews can be evidenced. Do not overlook end of life processes, destruction of assets or when asset owners leave or change role.
3. Your document and version control is wrong
Keeping your document version control up to date, making sure that version numbers match where used, having a review evidenced in the last 12 months, having documents that have no comments in are all good practices.
ISO 27001 Annex A 5.9 FAQ
Yes, maintaining an accurate inventory of information assets is a mandatory requirement for ISO 27001:2022 compliance under control 5.9.
Auditors will expect to see a documented Information Asset Register (IAR).
Failure to track assets is often cited as a major non-conformity.
It serves as the foundation for Annex A 5.12 (Classification) and Annex A 5.10 (Acceptable Use).
Without an inventory, an organisation cannot prove it has identified all relevant security risks.
An ISO 27001 inventory must include all assets that store, process, or transmit sensitive organisational information.
Information Assets: Databases, system documentation, and intellectual property.
Software Assets: Application software, system software, and development tools.
Physical Assets: Laptops, servers, mobile devices, and removable media.
Services: Cloud services (SaaS/PaaS) and outsourced utilities.
The ultimate responsibility for maintaining the inventory lies with the organisation, but day-to-day accountability is assigned to individual Asset Owners.
Management must ensure that roles and responsibilities are clearly defined.
Asset Owners are responsible for the classification and protection of their assigned assets.
IT teams typically manage the technical tracking of hardware and software.
Compliance officers ensure the inventory is reviewed and updated periodically.
The Asset Register should be updated in real-time as assets are commissioned or decommissioned, with a formal review occurring at least annually.
Changes should be captured during the “Joiner, Mover, Leaver” (JML) process.
Updates are required following major infrastructure changes or software migrations.
Quarterly reviews are considered best practice for high-growth organisations.
Annual audits ensure that “shadow IT” or orphaned assets are identified and removed.
The primary difference is that an Asset Register focuses on ownership and security value (ISO 27001), while a CMDB focuses on technical relationships and service management (ITIL).
Asset Register: Tracks who owns the data and its classification level.
CMDB: Tracks how a server connects to a database and its technical configuration.
Integration: Many organisations use their CMDB to automatically populate the technical portions of their Asset Register.
ISO 27001 Relate Controls and Further Reading
- How to Implement ISO 27001:2022 Annex A 5.9: Inventory of Information and Other Associated Assets
- How to Audit ISO 27001:2022 Annex A 5.9: Inventory of Information and Other Associated Assets
- ISO 27001 Return of Assets Beginner’s Guide
- ISO 27001:2022 Annex A 5.9 for Small Business: You Can’t Protect What You Can’t See
- ISO 27001:2022 Annex A 5.9 for AI Companies: Where Are Your Models?
- ISO 27001:2022 Annex A 5.9 for Tech Startups: Taming the SaaS Chaos

ISO 27001 Controls and Attribute Values
| Control type | Information security properties | Cybersecurity concepts | Operational capabilities | Security domains |
|---|---|---|---|---|
| Preventive | Confidentiality | Identify | Asset management | Governance and Ecosystem |
| Integrity | Protection | |||
| Availability |

