ISO 27001 and Asset Management Requirements
ISO/IEC 27001 is the international standard for information security management systems (ISMS). It defines a risk-based framework for protecting information assets, and a significant portion of its Annex A controls concern asset management specifically. For organisations pursuing or maintaining ISO 27001 certification, the ability to demonstrate accurate, up-to-date asset records is not optional – it is a core requirement of the audit.
This article explains what ISO 27001 requires for asset management, where the common gaps are, and how automated asset tracking helps meet the standard’s expectations.
The Structure of ISO 27001
ISO 27001 is structured in two parts:
- Clauses 4-10 define the management system requirements – how the organisation plans, operates, and improves its ISMS.
- Annex A contains the reference controls. These are the security measures organisations select based on their risk assessment, using the ISO 27002 standard for implementation guidance.
Asset management sits within Annex A.8. The 2022 revision of ISO 27001 reorganised the controls, and Annex A.8 now contains five controls covering identification, classification, and handling of information and assets.
Annex A.8 Controls
### A.8.1 – Identification of Assets
This is the foundational asset management control. It requires the organisation to identify all assets relevant to the ISMS and to maintain an inventory of them. The standard explicitly states that an asset inventory should be maintained throughout the asset lifecycle, from acquisition through to disposal.
Assets in scope include not only hardware but also software, data, services, and people. The inventory should identify each asset’s owner, location, and classification.
For most organisations, the asset inventory is the area where automated tracking delivers the most value. A spreadsheet that is updated quarterly cannot meaningfully satisfy “maintained throughout the lifecycle”. An API-driven register that polls MDM, cloud, and identity providers can.
### A.8.2 – Classification of Information
Information assets must be classified according to their sensitivity and criticality. Typical classifications include Public, Internal, Confidential, and Restricted. The classification determines how the information is handled, stored, and transmitted.
Asset tracking supports this control by providing the context needed for classification: knowing which device holds which data, and who has access to it, is a prerequisite for applying the right classification in the first place.
### A.8.3 – Handling of Assets
This control addresses the physical and logical handling of assets – storage, transmission, processing, and disposal. It requires procedures for secure media handling and for the secure deletion of data when assets are decommissioned.
An asset register that records lifecycle state – including when a device was retired and how its data was sanitised – directly supports an audit of this control.
### A.8.4 – Access to Information
Annex A.8.4 requires that access to information and associated assets be restricted to authorised users. Asset tracking contributes here by maintaining the mapping between users, devices, and the information they can access. When an employee leaves, the asset register should reflect which devices and licences need to be revoked.
### A.8.5 – Secure Development
While primarily aimed at development practices, this control has asset management implications: development environments and test data are themselves assets that must be inventoried and managed.
The 2013 vs 2022 Revision
Organisations certified under the older 2013 revision of ISO 27001 should note that Annex A.8 was restructured in the 2022 update. The 2013 version had a more granular set of controls under A.8, including separate controls for media handling (A.8.2) and access control (A.9). The 2022 revision consolidated and simplified these, but the underlying requirements are substantially the same: identify your assets, classify them, control access, and handle them securely.
All new certifications and surveillance audits now use the 2022 version. If your asset management practices satisfied the 2013 controls, they will largely satisfy the 2022 ones, but the mapping between controls has changed and your statement of applicability should be updated accordingly.
Where Organisations Fall Short
In audit experience, the most common asset management findings are:
- Incomplete inventories. Cloud instances spun up by developers, SaaS subscriptions bought on a corporate card, and contractor laptops enrolled in the MDM but not added to the asset register all represent untracked assets.
- No ownership assigned. An inventory that lists assets but does not identify an owner for each one fails to meet A.8.1. Without ownership, accountability for security and lifecycle management is unclear.
- Stale records. An inventory that lists devices retired months ago, or omits devices acquired since the last update, does not reflect reality. Auditors test this by comparing the inventory to live system data.
- No lifecycle tracking. The standard requires assets to be managed throughout their lifecycle. An inventory that records acquisition but not retirement, or that has no record of how decommissioned assets were disposed of, is incomplete.
How Automated Tracking Supports Compliance
Automated asset tracking addresses each of these gaps directly.
Completeness. By polling multiple authoritative sources – MDM, identity provider, cloud provider APIs, EDR – automated discovery captures assets that manual tracking misses. A cloud instance appears in the inventory the moment it is created, not the next time someone updates a spreadsheet.
Ownership. Identity-integrated asset tracking associates each device with the user registered in the identity provider, providing a natural owner for each asset. Where no user is associated, that itself is a signal worth investigating.
Currency. API-driven polling refreshes the inventory on a defined schedule – hourly, daily, or at whatever interval suits the organisation. The inventory reflects the current state of the estate, not a historical snapshot.
Lifecycle. By tracking lifecycle state explicitly – active, in maintenance, retired – and recording state transitions with timestamps, the system produces an audit trail that demonstrates compliance with the “throughout the lifecycle” requirement.
Evidence. Auditors do not take claims at face value. They want evidence: logs, exports, reconciliations. An automated system produces these as a by-product of its normal operation. A spreadsheet does not.
Preparing for Audit
If you are approaching an ISO 27001 audit, the asset management evidence you should be able to produce includes:
1. A current asset inventory covering hardware, software, and information assets 2. Evidence of ownership for each asset 3. Classification assignments for information assets 4. Records of asset lifecycle transitions, including retirement and disposal 5. Reconciliation between the inventory and live system data, demonstrating that the inventory is accurate
Automated tracking makes all of these straightforward to produce. The inventory is a query against the tracking system. Ownership comes from the identity integration. Lifecycle transitions are recorded as state changes with timestamps. Reconciliation is a comparison between the tracking system’s view and the underlying source APIs.
ISO 27001 does not prescribe how you maintain your asset inventory – it specifies what the inventory must contain and what it must demonstrate. Automated tracking is not a requirement of the standard, but it is the most reliable way to satisfy the standard’s expectations in a modern, dynamic IT estate where assets are created, changed, and retired continuously.
What this looks like in practice
Google Workspace: Google Admin shows every managed device. Gmail picks up procurement emails like “12 Chromebooks purchased, £449 each”. AssetGraph logs who has each device and when it was assigned – exactly what ISO 27001 Annex A.8 requires.
Microsoft 365: Intune provides the full device inventory. Outlook catches emails like “Surface Laptop 5, serial #ABC987, assigned to J. Smith”. Every device change is logged with a timestamp for your audit trail.
Both platforms feed the same audit-ready asset register, so ISO 27001 evidence is always current.
Leave a Reply