ISO 27001

Information asset register

Inventory your information and associated assets with an owner, a classification, and a CIA rating, the ISO 27001 Annex A 5.9 and 5.12 register your whole ISMS is built on.

Start free See pricing
app.keelgrc.com/information-assets
Compliance
Information assets
42
Assets
38
Owners assigned
40
Classified
4
Review due
AssetTypeOwnerClassificationReview
Customer databaseData storeA. RiveraConfidentialCurrent
Payroll systemSaaSJ. OkaforRestrictedDue
Office laptopsEndpointIT teamInternalCurrent
Marketing siteApplicationM. LinPublicCurrent

An information asset register is the foundation of an ISMS, the inventory every risk, control, and Statement of Applicability decision traces back to. Keel covers ISO 27001 Annex A 5.9 (inventory of information and other associated assets) and 5.12 (classification of information): record each asset with a type, an accountable owner, and a classification, then rate it for confidentiality, integrity, and availability so its protection needs are explicit.

The register auditors expect, usually kept in a stale spreadsheet

Annex A 5.9 asks for an inventory of assets with owners, and 5.12 asks you to classify information by sensitivity, but most teams keep it in a spreadsheet nobody owns, where classifications are inconsistent and half the assets have no owner. It’s the first thing an ISO 27001 auditor traces your controls back to, and the easiest one to let drift.

What information asset register does

Inventory every asset type (Annex A 5.9)

Record information, software, hardware, services, people, and facilities in one register, the “information and other associated assets” Annex A 5.9 asks you to inventory, each with a description and where it lives.

Classify by sensitivity (Annex A 5.12)

Assign each asset a classification (public, internal, confidential, or restricted), so its handling requirements are explicit. This is exactly what Annex A 5.12 (classification of information) requires.

An accountable owner on every asset

Annex A 5.9 requires assets to have owners. Keel flags assets that are still missing one, so accountability gaps are obvious before an auditor points them out.

A CIA rating for each asset

Rate confidentiality, integrity, and availability (low, moderate, or high), so the protection each asset needs is captured in the register and feeds your risk assessment.

Gaps visible at a glance

See how many assets are confidential or restricted, how many carry a high CIA rating, and which have no owner, the coverage view that tells you your inventory is real, not aspirational.

The backbone of the rest of your ISMS

Your risk register, controls, and Statement of Applicability all reference the assets you’re protecting. Keeping the inventory in Keel means those decisions trace back to a single, current source of truth.

Why it matters

  • Cover ISO 27001 Annex A 5.9 and 5.12 with one living register
  • Classify every asset and rate it for confidentiality, integrity, and availability
  • Catch assets with no owner before an auditor does
  • Give your risks, controls, and SoA a single source of truth to reference

Get audit-ready, and prove it

Information asset register is one module of a full GRC platform: controls crosswalked across every framework, so you collect evidence once and comply everywhere. Start free, no credit card, no sales call.

Start free

Frequently asked questions

What is an information asset register?

It’s the inventory of the information and associated assets your ISMS protects (data, systems, hardware, services, people, and facilities), each with an owner and a classification. ISO 27001 Annex A 5.9 asks for the inventory, and 5.12 asks you to classify information by sensitivity.

Which ISO 27001 controls does it map to?

Annex A 5.9 (inventory of information and other associated assets) and Annex A 5.12 (classification of information) in ISO/IEC 27001:2022. The CIA rating on each asset also supports your risk assessment under Clause 6.1.

What is a CIA rating?

A rating of how much each asset needs confidentiality, integrity, and availability (low, moderate, or high). It captures the protection the asset requires and informs which risks and controls apply to it.

Do assets need an owner?

Yes. Annex A 5.9 requires assets to have owners accountable for them. Keel highlights active assets that are still missing an owner so you can close the gap.