# Asset Inventory & Classification

> ISO/IEC 27001:2022 A.5.9 (inventory of information + associated
> assets) + A.5.12 (classification). The inventory is the foundation
> the risk register is built on.

| Field | Value |
|-------|-------|
| Document ID | DOC-ISMS-012 |
| Owner | Asset management |
| Review | Quarterly |

## Classification scheme (A.5.12)

| Level | Definition | Handling rules |
|-------|------------|----------------|
| Public | No harm if disclosed | none |
| Internal | Minor harm | access on need-to-know |
| Confidential | Significant harm | encryption, limited access |
| Restricted | Severe harm/legal | strict controls, audit access |

## Information assets

| ID | Asset | Type | Owner | Location | Classification | CIA rating | Dependencies |
|----|-------|------|-------|----------|----------------|------------|--------------|
| IA-01 | Customer DB | Data | @name | cloud region | Restricted | C3 I3 A2 | srv-01, backup |
| IA-02 | Source code | IP | @name | repo host | Confidential | C2 I3 A1 | CI system |
| IA-03 | HR records | Data | @name | HRIS SaaS | Restricted | C3 I2 A1 | vendor |

## Associated assets (hardware/software/services)

| ID | Asset | Type | Supports | Owner | Location | Notes |
|----|-------|------|----------|-------|----------|-------|
| AA-01 | Production cluster | Infrastructure | IA-01 | @ops | cloud AZ | redundancy NN |
| AA-02 | Laptop fleet | Hardware | staff | @it | distributed | MDM enrolled |
| AA-03 | SaaS vendor X | Service | IA-03 | @proc | external | contract ref |

## Lifecycle tracking

| Change | Date | By | Record |
|--------|------|-----|--------|
| Asset added/retired/transferred | | | ticket ref |
