Skip to content
arrow_back
search
Annex A 5.9 verified ISO/IEC 27001:2022

Inventory management of information and associated assets

Keep an updated list of information and assets, specifying who owns and manages each.

record_voice_over

Plain language

This control is about keeping a current and detailed list of all the important information and assets your organisation owns, like computers, data, and software. It's important because without it, you might lose track of who is responsible for what, which can lead to data breaches, misplaced technology, or lost information.

Framework

ISO/IEC 27001:2022

Control effect

Preventative

ISO 27001 domain

Organisational controls

Classifications

N/A

Official last update

24 Oct 2022

Control Stack last updated

19 Mar 2026

Maturity levels

N/A

Official control statement

An inventory of information and other associated assets, including owners, shall be developed and maintained.
verified ISO/IEC 27001:2022 Annex A 5.9
priority_high

Why it matters

If asset inventories lack completeness and owners, systems and data are missed, leaving unmanaged risks, delayed patching and undetected compromise.

settings

Operational notes

Update the asset register on change events; record owner, location and classification; integrate CMDB/ITSM discovery to reconcile and report inventory gaps.

Mapping detail

Mapping

Direction

Controls