ISO27001:2022 – A5.9 Inventory of Information and Other Associated Assets
ISO 27001 – A5.9 Inventory of Information and Other Associated Assets
You will often hear us say that you cannot protect what you don’t understand. This control supports that concept by requiring you to build and maintain an inventory (a “list”) of information and associated assets
Watch our video below to get further insights into what’s needed in this important control.
What does ISO 27001 – A5.9 require?
The standard states that:
“An inventory of information and other associated assets, including owners, should be developed and maintained.” (A5.9 Inventory of Information and Other Associated Assets)
This means you’re expected to create a list of both information assets and associated assets. These include physical and technical items such as:
- Laptops
- Mobile phones
- Servers
- Software licences
- Cloud services (SaaS platforms)
But it’s not just about creating the list — it must be regularly maintained and updated, with the frequency depending on the size and complexity of your organisation.
Why is this required?
You can’t secure assets you don’t know you have. This control ensures that you know what’s important to your business, where your data lives, and what needs protecting. That way, you can identify risks and apply appropriate security controls.
What the auditor is looking for
The auditor will want to see a structured, regularly maintained asset inventory or register, along with clearly assigned owners for each asset.
What you need to do
Start with your most obvious assets:
- Laptops
- Mobile phones
- Tablets
- Servers
- Printers
Use a spreadsheet to log:
- Asset name
- Serial number
- Owner
Your IT team may already hold much of this data, making it easier to compile. This register is also useful when addressing A5.11 (Return of Assets) and A6.5 (Termination or Change of Employment Responsibilities).
Next, record software licences and assign owners. Describe each asset clearly so you can evaluate the associated risks — such as unsupported software that poses a security risk.
Eventually, expand your register to include intangible assets like Intellectual Property (e.g., patents, trademarks, proprietary software).
In one organisation we worked with, this review uncovered outdated software still in use on legacy systems. The leadership team had no idea until the inventory was completed — they promptly authorised an upgrade to mitigate the risk.
If your organisation maintains a Records of Processing Activities (RoPA) as required under data protection laws, this can act as your informational asset register. Coordinate with your DPO to ensure this data aligns with your technical asset inventory.
Q & A
How often should the list be updated?
It depends. Small businesses may only need quarterly reviews. Larger businesses may need more frequent updates. The key is showing the auditor that the list is actively maintained.
Why do we need to classify the assets?
Classification helps prioritise protection. Not all assets carry the same risk. For example, a laptop storing no local data is less critical than a cloud-based payroll database. Use classification to guide your control measures.
Is it possible to get this wrong?
Yes — especially by ignoring the control altogether. Start small: focus on physical assets first, then add information-related data. Your IT department is a good place to start gathering details like device types and serial numbers.
Difficulty rating
We rate this control a 1 out of 5. It doesn’t require deep technical knowledge — just organisational communication and basic recordkeeping.
More questions?
ISO27001 controls are interconnected. Review our FAQ to see how this control aligns with others. Still confused? Contact us — we’re happy to help.
We are ISO 27001 Consultants who provide ‘Compliance without Complexity’® and we know we can help you… we even wrote a book about it. For more information on how to implement ISO 27001, written by ISO 27001 consultants like us, you should buy our book.. “The Real Easy Guide to ISO27001”, available on Amazon.
