IT Asset Register Template
A complete IT asset inventory with classification, ownership, and lifecycle status — aligned with ISO 27001 control A.5.9.
In short
An IT asset register is the inventory of every device, application, and service that stores or processes organisational information, together with its owner and classification. ISO 27001 control A.5.9 requires this inventory, and almost every other technical control depends on it — a control cannot be applied to an asset nobody knows exists.
- Format
- XLSX
- Size
- 33 KB
- Price
- Free
Your data is handled in accordance with Indonesia's Personal Data Protection Law. We only send the document you requested and the occasional relevant GRC insight — no spam.
What This Document Is For
The question organisations most often cannot answer during an incident is not 'who attacked us' but 'which systems are affected'. Answering it requires an inventory, and an inventory built after the incident is always too late.
This template covers more than hardware. SaaS subscribed by one team without IT's knowledge, code repositories, domains, and certificates are the assets most often missing from an inventory and most often the way in. The columns are arranged so those assets have a place from the start.
Most Useful For
- Organisations beginning ISO 27001 implementation with no central inventory
- IT teams mapping shadow SaaS before applying access controls
- Companies building incident response capability who need an asset map first
What's Inside
Asset identity
Name, type, identifier, physical or logical location, and operational status.
Ownership
Asset owner and operational custodian — two roles frequently conflated, leaving assets unowned.
Information classification
The classification level of information the asset handles, the basis for the protective controls applied.
Software & licensing
Version, licence expiry, and vendor support status, to track software reaching end of support.
Cloud & SaaS services
Subscriptions, account owners, and the data held in them — the category most often missing from inventories.
Lifecycle
Acquisition date, review schedule, and the disposal or return plan.
Standards & Regulations It Helps Satisfy
| Standard / Regulation | Clause / Article | What this document covers |
|---|---|---|
| ISO/IEC 27001:2022 | Control A.5.9 | Inventory of information and associated assets, including ownership. |
| ISO/IEC 27001:2022 | Control A.5.10 | Acceptable use of information and associated assets. |
| ISO/IEC 27001:2022 | Control A.5.11 | Return of assets on termination of employment or contract. |
This document helps satisfy the requirements above, but does not by itself make an organisation compliant. Compliance is judged on practice in operation, not on documents held.
Questions About This Document
Do employee-owned (BYOD) devices need recording?
If they access organisational information, yes — at least as a category with the controls that apply, even if not every unit is listed individually. What matters is that an auditor can see their existence is known and managed rather than ignored.
How often should the inventory be updated?
Continuously for events (assets added, removed, reassigned) and reviewed in full at least annually. An inventory updated only before an audit is obvious: its update dates all cluster in one week.
Can this template replace an ITAM tool?
Below roughly a hundred assets this worksheet is adequate and, in practice, more likely to stay current. Above that, manual upkeep starts losing to the rate of change and a tool with automated discovery becomes the sensible option.
Related Reading
Background that helps you fill this document in correctly, rather than merely filling it in.
Documents Often Taken Together With This One
Risk Register Template
Manage information security risk identification, assessment, and mitigation in one structured worksheet.
Free DownloadStatement of Applicability (SoA) Template — ISO 27001:2022
Document the applicability of all 93 ISO 27001:2022 Annex A controls along with their justifications.
Free DownloadInformation Security Policy Template
An organization-level information security policy framework ready to tailor to your business context.
Free DownloadNeed guidance, not just a template?
A template speeds up producing the document. What decides whether an audit passes is whether its contents genuinely reflect how your organisation works — and that is what we support.