Asset Inventory & Classification
Assets + 4-level classification
Mode d'emploi: Foundation of the risk register: you can't assess risk on assets you haven't listed. Classification drives handling rules downstream.
Aperçu
Asset Inventory & Classification
ISO/IEC 27001:2022 A.5.9 (inventory of information + associated assets) + A.5.12 (classification). The inventory is the foundation the risk register is built on.
| Field | Value |
|---|---|
| Document ID | DOC-ISMS-012 |
| Owner | Asset management |
| Review | Quarterly |
Classification scheme (A.5.12)
| Level | Definition | Handling rules |
|---|---|---|
| Public | No harm if disclosed | none |
| Internal | Minor harm | access on need-to-know |
| Confidential | Significant harm | encryption, limited access |
| Restricted | Severe harm/legal | strict controls, audit access |
Information assets
| ID | Asset | Type | Owner | Location | Classification | CIA rating | Dependencies |
|---|---|---|---|---|---|---|---|
| IA-01 | Customer DB | Data | @name | cloud region | Restricted | C3 I3 A2 | srv-01, backup |
| IA-02 | Source code | IP | @name | repo host | Confidential | C2 I3 A1 | CI system |
| IA-03 | HR records | Data | @name | HRIS SaaS | Restricted | C3 I2 A1 | vendor |
Associated assets (hardware/software/services)
| ID | Asset | Type | Supports | Owner | Location | Notes |
|---|---|---|---|---|---|---|
| AA-01 | Production cluster | Infrastructure | IA-01 | @ops | cloud AZ | redundancy NN |
| AA-02 | Laptop fleet | Hardware | staff | @it | distributed | MDM enrolled |
| AA-03 | SaaS vendor X | Service | IA-03 | @proc | external | contract ref |
Lifecycle tracking
| Change | Date | By | Record |
|---|---|---|---|
| Asset added/retired/transferred | ticket ref |