You cannot protect what you do not know you have. Over my 30 years in governance, risk, and compliance, I have seen far too many organisations invest heavily in advanced cyber defenses while remaining completely blind to unmapped cloud storage buckets, orphaned databases, legacy physical servers, or unvetted SaaS applications (“shadow IT”). When an incident occurs, you cannot defend, back up, or prove compliance for assets that do not officially exist in your records. Annex A 5.9 is the absolute bedrock control of your entire Information Security Management System (ISMS)—every risk assessment, classification decision, access control rule, and incident response playbook depends directly on maintaining complete visibility and clear ownership over your information assets.
ISO 27001:2022 includes Annex A 5.9 to ensure your organisation identifies, catalogs, and assigns explicit ownership to all information and associated assets. This control updates former 2013 requirements (8.1.1 and 8.1.2) and acts as the foundational inventory engine that powers information classification (Annex A 5.12), asset handling rules (Annex A 5.10), asset return (Annex A 5.11), and risk treatment (Annex A 8.9).
Quick Summary: What ISO 27001 Annex A 5.9 Requires
At a practical level, Annex A 5.9 is about establishing an accurate, usable, and regularly updated inventory of all information, software, hardware, cloud services, and physical media that support your business. It does not force you to buy an expensive, automated Configuration Management Database (CMDB) on day one; it expects a structured, risk-proportionate approach that gives you complete visibility and accountability. Here is what you need to do in plain English:
- Catalog Primary Information & Data Assets: Identify key data collections, customer PII (Annex A 5.34), commercial source code, financial databases, and intellectual property.
- Map Supporting Hardware & Infrastructure Assets: Inventory physical servers, network firewalls, employee laptops, mobile devices, and physical facilities.
- Track Software, Applications & Cloud Tenants: Catalog all commercial off-the-shelf software, internal applications, SaaS tools, and cloud infrastructure (AWS/Azure/GCP) (Annex A 5.23).
- Assign Explicit Information Asset Owners: Assign C-suite or department-level owners accountable for defining security safeguards, access rules, and lifecycle handling for every asset.
- Record Critical Asset Metadata: Track essential asset details: asset name, description, owner, location/hosting region, classification tier (Annex A 5.12), and business criticality.
- Keep the Inventory Current via Lifecycle Triggers: Update the inventory automatically during IT provisioning, cloud deployment, vendor onboarding (Annex A 5.19), and asset disposal (Annex A 8.10).
Why Operating Without an Asset Inventory Is a Critical Hazard
When an organisation attempts to manage security without a comprehensive asset inventory, security controls are applied inconsistently. Untracked assets become primary targets for attackers because they lack security monitoring, automated patching, and backup enforcement.
Ignoring structured asset inventory controls exposes your business to severe hazards:
- Rogue “Shadow IT” & Unmonitored Cloud Exposure: Staff subscribing to unvetted SaaS tools or provisioning cloud storage buckets that sit open to the public internet without security oversight (Annex A 5.23).
- Unpatched Vulnerabilities on Orphaned Assets: Legacy servers or abandoned virtual machines running end-of-life operating systems that fall outside routine vulnerability patching cycles (Annex A 8.8).
- Incomplete Incident Response & Data Recovery: Being completely unable to determine the scope of a data breach or restore operations because IT teams did not know which databases contained critical client records (Annex A 5.26).
- Immediate Certification Failure: Facing instant major non-conformities during ISO 27001 surveillance audits because you cannot produce a complete asset register or demonstrate asset ownership.
My 8 Step Plan to Implement Annex A 5.9 Fast
You do not need a complex enterprise CMDB platform to satisfy an ISO 27001 auditor. Here is my pragmatic, 8-step plan to establish an audit-ready asset inventory framework.
1. Publish a Clear Asset Management Policy
Document explicit rules defining how information assets are identified, cataloged, owned, and maintained throughout their lifecycle (Annex A 5.1):
- Define what constitutes an “information asset” across data, software, hardware, cloud, and physical media categories.
- Mandate that no new system, application, or cloud tenant may be deployed into production without being registered in the central asset inventory.
- Establish explicit expectations for Asset Owners regarding risk assessments, access approvals, and annual reviews.
2. Categorize Assets into Logical Inventory Streams
Structure your inventory to reflect real-world operational categories so it remains readable and practical:
- Information Assets: Customer databases, employee records, financial ledgers, commercial source code, research & development IP.
- Software & SaaS Assets: Enterprise SaaS (Microsoft 365, Salesforce, Jira), custom applications, commercial software licenses, operating systems.
- Physical & Hardware Assets: Laptops, desktops, smartphones, firewalls, switches, physical servers, backup appliances, security badges (Annex A 7.2).
- Service & Cloud Assets: AWS/Azure cloud tenants, managed IT service providers (MSPs), web hosting environments (Annex A 5.23).
3. Assign Accountability to Named Asset Owners
An asset without an owner is an unmanaged vulnerability. Assign explicit ownership to specific roles or individuals:
- Assign C-suite or Department Leads as Asset Owners based on business impact (e.g., CFO owns Financial Ledgers; VP of Engineering owns Source Code & AWS Tenants; HR Lead owns Employee PII).
- Clarify that Asset Ownership means business accountability (approving access, assigning classification, determining retention), not necessarily performing day-to-day technical administration.
- Ensure delegates or technical custodians are assigned for operational maintenance (e.g., IT Lead acts as technical custodian for the server hardware owned by the VP of Ops).
4. Capture Essential Asset Metadata Fields
Avoid over-complicating the inventory with irrelevant technical noise. Record core, high-value metadata fields:
- Asset ID & Name: Unique identifier and readable asset name (e.g., `AST-DB-001: Customer Production Database`).
- Asset Description & Category: Concise summary of the asset and its primary business function.
- Designated Owner & Custodian: Accountable business lead and assigned technical administrator.
- Physical / Logical Location: Hosting region, cloud tenant ID, data center, or physical office address.
- Information Classification Level: Associated sensitivity tier (Public, Internal, Confidential, Restricted) (Annex A 5.12).
- Business Criticality Rating: High, Medium, or Low operational impact if the asset is lost or destroyed.
5. Automate Discovery to Catch Shadow IT and Cloud Drift
Manual spreadsheets fall out of date rapidly. Combine manual registers with automated discovery tools:
- Deploy Mobile Device Management (MDM) tools (Microsoft Intune, Jamf) to automatically inventory all laptops, desktops, and mobile endpoints.
- Utilize cloud-native asset discovery tools (AWS Config, Azure Asset Inventory) to map virtual machines, storage buckets, and API gateways automatically.
- Run SaaS management or Cloud Access Security Broker (CASB) discovery tools to spot unvetted shadow IT SaaS subscriptions across corporate networks (Annex A 8.23).
6. Integrate Asset Updates into Change and HR Workflows
Ensure the asset inventory updates dynamically alongside day-to-day operational events:
- Procurement & IT Onboarding: Require IT Helpdesk teams to log new laptops, firewalls, or SaaS subscriptions in the asset register during provisioning.
- Change Advisory Board (CAB): Include an explicit “Asset Inventory Updated?” check-box on all production system change requests (Annex A 8.32).
- HR Offboarding & Decommissioning: Update asset records immediately when hardware is returned or cloud tenants are decommissioned (Annex A 5.11 & Annex A 8.10).
7. Link Asset Inventory Directly to Risk and Response Controls
Ensure your asset inventory powers downstream ISMS security workflows:
- Use asset criticality and classification ratings directly when conducting annual ISMS Risk Assessments (Annex A 8.9).
- Incorporate asset locations and ownership details directly into Incident Response Playbooks to accelerate breach triage (Annex A 5.26).
- Verify that all high-criticality assets listed in the inventory have documented backup schedules (Annex A 8.13) and business continuity plans (Annex A 5.30).
8. Conduct Quarterly Reconciliations and Annual Reviews
Verify that your inventory matches operational reality through structured audit reviews (Annex A 5.36):
- Perform quarterly reconciliations comparing Active Directory / MDM endpoint logs against the master physical hardware inventory.
- Require Asset Owners to review and re-confirm their assigned assets annually, updating classification tiers and criticality ratings as needed.
- Present asset inventory coverage metrics and shadow IT discovery findings to executive leadership during formal ISMS Management Reviews.
Common Implementation Pitfalls and How to Fix Them
When preparing clients for ISO 27001 audits, I frequently spot the same asset inventory mistakes. Here are the main traps and how to solve them:
- Problem: Trying to Inventory Every Single Cable, Mouse, and Monitor in Painful Detail
Ninja Solution: Focus strictly on assets that handle, process, store, or protect information; group minor hardware commodities into generic categories. - Problem: Assigning 100% of Asset Ownership to the IT Manager or CISO
Ninja Solution: Assign business ownership to the C-suite or Department Leads who understand the data’s business value (e.g., HR owns employee PII, Finance owns ledgers). - Problem: Maintaining a Static Spreadsheet That Is Updated Once a Year for the Auditor
Ninja Solution: Integrate inventory updates into helpdesk ticketing, procurement gates, and change management workflows so it stays updated dynamically. - Problem: Inventorying Physical Laptops while Forgetting Information Assets and SaaS Cloud Tools
Ninja Solution: Structure your register into distinct streams; ensure software, cloud tenants, and primary datasets are cataloged alongside physical hardware.
The ISO 27001 Ninja Bottom Line
ISO 27001 Annex A 5.9 is about establishing complete visibility, explicit ownership, and informed decision-making across your entire technology ecosystem. You cannot protect, back up, classify, or defend assets that you do not know exist; building an accurate, dynamic asset inventory transforms security from blind guesswork into controlled, defensible governance.
By publishing an Asset Management Policy, structuring logical inventory streams, assigning business ownership to department leads, capturing core metadata fields, automating endpoint and cloud discovery, embedding updates into change workflows, linking assets to risk assessments, and conducting quarterly reconciliations, you eliminate shadow IT blind spots, streamline incident response, and satisfy your ISO 27001 auditor with complete confidence.
