A.5.9
    Organizational Controls

    Inventory of information and other associated assets

    An inventory of information and other associated assets, including owners, should be developed and maintained.

    Purpose

    To identify organizational assets and define appropriate protection responsibilities to ensure they receive an appropriate level of protection.

    Implementation Guidance

    Maintain a comprehensive inventory of all information assets

    Document asset owners and custodians for each asset

    Classify assets according to their importance and sensitivity

    Review and update the asset inventory regularly

    Include hardware, software, data, services, and documentation in the inventory

    Recommended Tools

    ISO 27001 Services from the Directory

    These providers can help you implement A.5.9 and achieve ISO 27001 certification.

    By the team behind ISMS Directory

    Implementing A.5.9 for a client?

    ISMS Copilot drafts policies, evidence, and SoA wording for A.5.9 Inventory of information and other associated assets. Built for compliance professionals.

    Try ISMS Copilot free