PV
PilotVantage

Asset Register

Keep an accurate inventory of your information assets — the foundation that every risk assessment and control decision builds on.

Maintaining an asset register is a core ISO 27001 requirement. You can't protect what you don't know you have, so the register gives you a single, up-to-date view of the hardware, software, information, and services your organisation relies on — and who is responsible for each one.

What you record for each asset

Every asset entry captures a few essential details so you always know what it is, who owns it, and how sensitive it is:

  • Name and identifier — a clear label and a unique reference so the asset is easy to find and can't be confused with another.
  • Type — the category of asset, such as hardware, software, information, or service.
  • Owner — the person accountable for the asset, its protection, and decisions about it.
  • Classification — how sensitive the asset is, which drives the level of protection it needs.

Classification levels

Classification tells everyone how carefully an asset must be handled. You apply a consistent set of levels, ranging from information that can be shared openly through to your most sensitive material. A typical scheme looks like this:

ClassificationMeaningExample
PublicCan be shared freely with anyone.Published marketing material
InternalFor staff use; not for external release.Internal process guides
ConfidentialSensitive; limited to those who need it.Customer records
RestrictedHighly sensitive; tightly controlled access.Financial or security keys
Why classification matters
An asset's classification guides how it should be stored, shared, and protected — and helps you prioritise which assets need the strongest controls.

Connecting assets to your wider programme

An accurate register underpins the rest of your ISO 27001 work. Link each asset to the risks that threaten it and the controls that protect it, so you can see at a glance how well each asset is defended and where gaps remain.

Works with

  • Risk Register — link assets to the risks that could affect them.
  • Controls — show which controls protect each asset.
  • Evidence — attach records that demonstrate your assets are managed.