TemplatesFree

IT Asset Register Template

A complete IT asset inventory with classification, ownership, and lifecycle status — aligned with ISO 27001 control A.5.9.

In short

An IT asset register is the inventory of every device, application, and service that stores or processes organisational information, together with its owner and classification. ISO 27001 control A.5.9 requires this inventory, and almost every other technical control depends on it — a control cannot be applied to an asset nobody knows exists.

Format
XLSX
Size
33 KB
Price
Free

Your data is handled in accordance with Indonesia's Personal Data Protection Law. We only send the document you requested and the occasional relevant GRC insight — no spam.

What This Document Is For

The question organisations most often cannot answer during an incident is not 'who attacked us' but 'which systems are affected'. Answering it requires an inventory, and an inventory built after the incident is always too late.

This template covers more than hardware. SaaS subscribed by one team without IT's knowledge, code repositories, domains, and certificates are the assets most often missing from an inventory and most often the way in. The columns are arranged so those assets have a place from the start.

Most Useful For

  • Organisations beginning ISO 27001 implementation with no central inventory
  • IT teams mapping shadow SaaS before applying access controls
  • Companies building incident response capability who need an asset map first

What's Inside

01

Asset identity

Name, type, identifier, physical or logical location, and operational status.

02

Ownership

Asset owner and operational custodian — two roles frequently conflated, leaving assets unowned.

03

Information classification

The classification level of information the asset handles, the basis for the protective controls applied.

04

Software & licensing

Version, licence expiry, and vendor support status, to track software reaching end of support.

05

Cloud & SaaS services

Subscriptions, account owners, and the data held in them — the category most often missing from inventories.

06

Lifecycle

Acquisition date, review schedule, and the disposal or return plan.

Standards & Regulations It Helps Satisfy

Standard / RegulationClause / ArticleWhat this document covers
ISO/IEC 27001:2022Control A.5.9Inventory of information and associated assets, including ownership.
ISO/IEC 27001:2022Control A.5.10Acceptable use of information and associated assets.
ISO/IEC 27001:2022Control A.5.11Return of assets on termination of employment or contract.

This document helps satisfy the requirements above, but does not by itself make an organisation compliant. Compliance is judged on practice in operation, not on documents held.

Questions About This Document

Do employee-owned (BYOD) devices need recording?

If they access organisational information, yes — at least as a category with the controls that apply, even if not every unit is listed individually. What matters is that an auditor can see their existence is known and managed rather than ignored.

How often should the inventory be updated?

Continuously for events (assets added, removed, reassigned) and reviewed in full at least annually. An inventory updated only before an audit is obvious: its update dates all cluster in one week.

Can this template replace an ITAM tool?

Below roughly a hundred assets this worksheet is adequate and, in practice, more likely to stay current. Above that, manual upkeep starts losing to the rate of change and a tool with automated discovery becomes the sensible option.

Related Reading

Background that helps you fill this document in correctly, rather than merely filling it in.

Need guidance, not just a template?

A template speeds up producing the document. What decides whether an audit passes is whether its contents genuinely reflect how your organisation works — and that is what we support.