ISO 27001 And Asset Management: What The 2022 Standard Requires

hero image
Join IT Pulse

Receive the latest news of the IT world once per week.

ISO 27001 is the internationally recognized standard for Information Security Management, and its 2022 revision significantly reorganized how Asset Management is addressed. If your organization is working toward certification or maintaining compliance, understanding what the updated standard requires and how it differs from the 2013 version is the necessary starting point.

This article covers the ISO 27001:2022 controls directly related to IT Asset Management: what they require, how they map to ITAM practices, and how to build an ISO 27001 asset inventory that satisfies the standard. It also includes a step-by-step approach and a practical compliance checklist.

Note on versioning: The previous version of this article referenced ISO 27001:2013 (Annex A.8.1). The transition deadline to ISO 27001:2022 passed in October 2025. This article reflects the current version of the standard.

An overview of ISO 27001:2022 and Asset Management

ISO 27001:2022 restructured the Annex A controls from 14 domains and 114 controls (2013) to 4 themes and 93 controls. The four themes are: Organizational, People, Physical, and Technological. Asset Management controls moved from the former A.8 domain into the Organizational theme, now found at A.5.9, A.5.10, and A.5.11.

This restructuring did not change the underlying intent. Organizations are still required to identify their information assets, assign ownership, define acceptable use, and ensure return of assets at the end of an employment or contract. What changed is the numbering, the grouping, and some of the language, particularly the shift from "assets" to "information and other associated assets," which clarifies that the standard's scope extends to everything connected to information, not only the information itself.

What are "assets" according to ISO 27001:2022?

ISO 27001:2022 uses the phrase "information and other associated assets" throughout its Asset Management controls. This framing captures two distinct layers.

The first is information itself: data in all its forms, whether stored digitally, printed on paper, or transmitted across a network. The second is everything associated with that information: the hardware that stores or processes it, the software that runs on that hardware, the services that deliver or protect it, the people who handle it, and the intangible assets (reputation, intellectual property, certifications) that depend on its integrity.

In practice, for IT teams applying ISO 27001 to their Asset Management program, the relevant asset categories typically include:

  • Endpoints and servers.
  • Network infrastructure.
  • Cloud services and SaaS platforms.
  • Software licenses.
  • Databases and repositories.
  • Any physical media that stores information.

The standard does not prescribe an exhaustive taxonomy. What it requires is that each organization identifies the assets within the scope of its Information Security Management System (ISMS) and manages them accordingly.

ISO 27001 Asset Management controls: Annex A.5.9 to A.5.11

The three controls that govern Asset Management in ISO 27001:2022 are A.5.9, A.5.10, and A.5.11. Together they cover the full Asset Management cycle: identifying and inventorying assets, defining how they may be used and who owns them, and ensuring they are returned when no longer needed by the person or party holding them.

A.5.9: Inventory of information and other associated assets

Control A.5.9 requires organizations to identify information and other associated assets within the ISMS scope and maintain an inventory of those assets. Each asset in the inventory must have an assigned owner and be classified according to its importance to information security.

The inventory must be kept current. New assets must be added when they are introduced, changes to existing assets must be reflected when they occur, and retired assets must be removed at the time of disposal or decommission. A static spreadsheet updated during annual audits does not satisfy this control in environments where assets change regularly. The standard expects the inventory to reflect the actual state of the environment, not the state it was in at the last audit date.

A.5.10: Acceptable use of information and other associated assets

Control A.5.10 combines what the 2013 standard addressed separately as ownership and acceptable use. It requires organizations to identify, document, and implement rules for the acceptable use and handling of information and other associated assets.

Asset owners are responsible for managing assets throughout their lifecycle, keeping classification current, reviewing associated access rights, and ensuring proper disposal when assets are retired. Acceptable use rules must be communicated to all personnel and relevant third parties who access or handle the organization's assets. These rules should cover what users may and may not do with assets, what security requirements apply during use, and how to report incidents or policy violations.

A.5.11: Return of assets

Control A.5.11 requires that all assets held by employees, contractors, and third parties are returned when their employment, contract, or agreement ends. The process must be documented, and non-returns must be treated as security incidents unless they have been formally agreed upon as part of the offboarding process. 

This control applies to all asset categories: hardware (laptops, mobile devices, access cards), software licenses, digital credentials, and physical documents or media. Organizations must have a defined procedure for initiating and completing asset return, verifying that all items have been received, and updating the asset inventory to reflect returned or decommissioned assets.

ISO 27001 asset inventory: a step-by-step approach

Building and maintaining an ISO 27001 asset inventory that satisfies controls A.5.9 to A.5.11 requires a structured process. The steps below reflect the sequence of decisions and actions that turn a compliance requirement into an operational system.

Step 1: Define the ISMS scope

Before identifying assets, the organization must define the boundaries of its ISMS. The scope determines which processes, locations, and systems fall under the standard's requirements. Assets outside the scope do not need to be inventoried for ISO 27001 purposes, but the scope definition itself must be documented and defensible.

Step 2: Identify information assets and associated assets

For each area within the scope, identify what information exists, where it lives, and what assets are associated with it. This typically starts with data flows: where is information created, processed, stored, and transmitted? The physical and logical assets supporting each flow become the candidates for the inventory.

Step 3: Assign ownership to every asset

Every asset in the inventory must have a named owner: an individual, a team, or a department responsible for its management and protection. Ownership without specificity does not satisfy A.5.10. "IT department" is not an owner. "Head of IT Infrastructure" or a specific role title is.

Step 4: Classify assets by information security importance

Apply the organization's classification scheme to each asset, based on the sensitivity of the information it holds or processes and the impact of a security breach involving that asset. Classification determines what controls apply and at what priority.

Step 5: Build and populate the asset register

Document each asset with at minimum: asset name and type, owner, location, classification, lifecycle status, and the date of the last review. For IT assets, include hardware details (make, model, serial number), software details, and any associated contracts or warranties. This is the ISO 27001 asset inventory that auditors will examine.

Step 6: Document acceptable use rules and communicate them

For each asset category, define what constitutes acceptable and unacceptable use. Document the rules and ensure they reach all personnel and third parties who handle the assets. Undocumented rules do not satisfy A.5.10.

Step 7: Establish the return of assets procedure

Define the process for recovering assets when employment or contracts end: what is returned, in what timeframe, who initiates the process, and what happens if an asset is not returned. Integrate this process with HR offboarding workflows.

Step 8: Review and update the inventory on a defined cadence

Set a review frequency appropriate to how often your environment changes. The standard requires the inventory to be accurate and current, without prescribing a specific interval. High-change environments may require continuous automated discovery. Lower-change environments may sustain quarterly manual reviews.

ISO 27001 Asset Management compliance checklist

Use the checklist below to evaluate your organization's coverage of controls A.5.9 to A.5.11. Each item corresponds to a specific requirement of the 2022 standard.

Scope and inventory (A.5.9)

  • ISMS scope is defined and documented
  • Information assets within scope have been identified
  • Associated assets (hardware, software, services, people) have been catalogued
  • An asset register is maintained and kept current
  • Each asset record includes: name, type, owner, classification, location, and status
  • New assets are added to the inventory when introduced
  • Retired or disposed assets are removed from the active inventory

Ownership and acceptable use (A.5.10)

  • Every asset has a named, responsible owner (individual or role)
  • Asset owners have been informed of their responsibilities
  • An acceptable use policy exists for information and associated assets
  • The policy has been communicated to all personnel and relevant third parties
  • Asset classification is reviewed by owners at a defined interval
  • Disposal procedures are defined and applied when assets are retired

Return of assets (A.5.11)

  • A documented procedure exists for the return of assets at end of employment or contract
  • The procedure covers all asset categories: hardware, software, credentials, documents
  • Non-returns are flagged and treated as security incidents unless formally agreed
  • The asset inventory is updated when assets are returned or decommissioned
  • Return procedures are integrated with HR offboarding workflows

Why is ISO 27001 important for Asset Management?

ISO 27001 matters for Asset Management because it provides a systematic, risk-based framework for protecting the assets an organization depends on. Without a standard, Asset Management programs tend to address whatever is most visible: devices that someone remembered to add to a spreadsheet, software that IT happened to track, contracts that were renewed in time by chance rather than by process.

The standard creates accountability at every stage: assets must be inventoried, owned, used according to defined rules, and returned when the need ends. Each requirement maps directly to an ITAM function. The inventory requirement (A.5.9) is the foundation. The ownership and acceptable use requirement (A.5.10) is the governance layer. The return requirement (A.5.11) closes the lifecycle loop.

Organizations most likely to benefit from implementing ISO 27001 Asset Management controls include those in regulated industries: healthcare, financial services, and government agencies handling sensitive data. However, any organization seeking cyber insurance, enterprise contracts, or supply chain trust increasingly encounters ISO 27001 as a prerequisite, making the controls relevant well beyond traditionally regulated sectors.

In conclusion

ISO 27001:2022 reorganized its Asset Management controls from the former A.8.1 structure into three controls: A.5.9 (inventory), A.5.10 (ownership and acceptable use), and A.5.11 (return of assets). The underlying requirements are consistent with the 2013 version, but organizations still referencing the old numbering are working from a superseded framework.

The activities that the controls require are:

  • Building and maintaining an accurate asset inventory (A.5.9).
  • Assigning ownership and defining acceptable use for every asset (A.5.10).
  • Ensuring assets are returned at the end of employment or contract (A.5.11).
  • Reviewing and updating the inventory on a defined cadence (A.5.9).

An ITAM platform that maintains a continuously updated inventory, assigns owners to every asset, and integrates with offboarding workflows addresses all three controls operationally. InvGate Asset Management covers each of these requirements: automated discovery keeps the inventory current across agent-based and agentless methods, ownership fields and custom classification are built into every asset record, and integration with InvGate Service Management connects asset return to offboarding tickets and workflows.

Start a 30-day free trial or talk to Sales to see how it fits your compliance environment.

Frequently Asked Questions (FAQs)

What is ISO 27001 Asset Management?

ISO 27001 Asset Management refers to the controls within the ISO 27001:2022 standard that govern how organizations identify, own, use, and return information and associated assets within the scope of their Information Security Management System. The relevant controls in the 2022 version are A.5.9 (inventory), A.5.10 (acceptable use and ownership), and A.5.11 (return of assets).

What changed in ISO 27001:2022 for Asset Management?

The 2022 revision renumbered the Asset Management controls from Annex A.8.1 (2013) to A.5.9, A.5.10, and A.5.11 (2022). The former four sub-controls were consolidated into three. The language shifted to "information and other associated assets" to clarify that the standard covers all assets connected to information, not only information itself. Organizations certified to the 2013 version had until October 2025 to transition.

What is an ISO 27001 asset inventory?

An ISO 27001 asset inventory is a documented register of all information and associated assets within the ISMS scope. Control A.5.9 requires that each entry includes the asset name and type, an assigned owner, its classification, current lifecycle status, and the date of last review. The inventory must be kept current as assets are added, changed, or retired.

Who is responsible for assets under ISO 27001?

Control A.5.10 requires that every asset has a named owner: a specific individual, role, or department responsible for managing the asset throughout its lifecycle. Asset owners are responsible for keeping classification current, ensuring appropriate controls are in place, and overseeing disposal when the asset is retired.

Does ISO 27001 require an ITAM tool?

The standard does not mandate a specific tool. It requires that the asset inventory is accurate, current, and auditable. In practice, organizations with more than a small number of assets find that maintaining a compliant inventory manually is not sustainable. An ITAM platform with automated discovery, owner assignment, and audit-ready reporting is the most practical way to satisfy controls A.5.9 to A.5.11 at scale.


Disclaimer: This article is provided for informational purposes only and does not constitute legal or compliance advice. ISO 27001 requirements should be validated against the official standard and reviewed with a qualified information security professional or certification body.

Simplify your IT ecosystem with InvGate Asset Management

30-day free trial - No credit card needed

Clear pricing

No surprises, no hidden fees — just clear, upfront pricing that fits your needs.

View Pricing

Easy migration

Our team ensures your transition to InvGate is fast, smooth, and hassle-free.

View Customer Experience