TL;DR
  • The 2022 restructuring: ISO 27001:2022 restructured from 14 domains and 114 controls (2013) to 4 themes and 93 controls. Asset management moved from Annex A.8 into the new Organizational Controls theme at A.5.9, A.5.10, and A.5.11. The numbering changed; the requirements did not become less demanding.
  • Three controls govern asset management: A.5.9 requires a complete, maintained inventory with named owners. A.5.10 defines rules for acceptable use of information assets. A.5.11 requires return of assets at end of employment or contract. Together they cover the full asset lifecycle from identification through recovery.
  • A.5.9 is the foundation control: Without a complete, current inventory with named owners, no other information security control can be fully demonstrated. You cannot apply access controls to assets you have not inventoried. You cannot enforce acceptable use policies on assets you do not know about. You cannot return assets that are not recorded as having been assigned.
  • The "current" requirement is what breaks spreadsheets: ISO 27001:2022's updated points of focus require that the asset inventory be kept current — new assets added when introduced, changes reflected when they occur, retired assets removed at disposal. A static spreadsheet updated at annual audits does not satisfy this control in environments where assets change regularly.
  • Scope matters: ISO 27001's definition of "information and other associated assets" extends beyond devices. It includes databases, software, SaaS applications, credentials, certificates, cloud instances, and services. The scope of the asset inventory must match the ISMS scope — if a SaaS application is in scope, it must be in the inventory with a named owner.
  • Multi-framework efficiency: ISO 27001 A.5.9 maps directly to SOC 2 CC6.1, NIST CSF ID.AM, and HIPAA Security Rule § 164.310(d). A single, well-maintained ITAM inventory satisfies the asset management control across multiple frameworks simultaneously.

Introduction: Asset Management as the ISMS Foundation

ISO 27001:2022 is explicit about why asset management appears first in the operational controls: "You cannot protect what you do not know." The principle is simple, but the implementation requirement is demanding. Organizations pursuing ISO 27001 certification must demonstrate not just that an asset inventory policy exists, but that a current, complete, owned inventory actually exists — and that it is maintained continuously rather than updated periodically in response to audit pressure.

The 2022 revision of ISO 27001 made this requirement more precise. The standard moved from the language of "asset management" to "inventory of information and other associated assets" — a deliberate expansion of scope that makes clear the inventory must include software, SaaS applications, credentials, certificates, and cloud resources, not just physical hardware. Organizations that interpreted the 2013 standard as requiring only a hardware inventory now have explicit 2022 language requiring the full information asset scope.

This guide explains the three ISO 27001:2022 asset management controls in operational terms — what each control requires, how auditors test it, what evidence satisfies it, and how the controls connect to the broader security management system. For the practical ITAM implementation that satisfies these requirements, see IT Asset Management: Complete Guide to Tracking, Compliance and Cost Control.

The 2022 Restructuring: What Changed and What Didn't

ISO 27001 was significantly restructured in the 2022 revision. The 2013 version organized 114 controls across 14 domains — categories such as Access Control, Asset Management, and Communications Security. The 2022 revision consolidated those into 4 themes and 93 controls: Organizational Controls (A.5, 37 controls), People Controls (A.6, 8 controls), Physical Controls (A.7, 14 controls), and Technological Controls (A.8, 34 controls).

2013 Control2022 ControlDescription
A.8.1.1A.5.9Inventory of Information and Other Associated Assets
A.8.1.2A.5.9Ownership of Assets (consolidated into A.5.9)
A.8.1.3A.5.10Acceptable Use of Information and Other Assets
A.8.1.4A.5.11Return of Assets

The restructuring consolidated the 2013 asset management controls without reducing their requirements. Organizations certified under ISO 27001:2013 must map old controls to the new structure and update their Statement of Applicability for recertification under the 2022 standard. The compliance deadline for transitioning from 2013 to 2022 certification was October 2025.

The 2022 Scope Expansion

The shift from "assets" to "information and other associated assets" in 2022 is not cosmetic. The 2013 standard was widely interpreted as primarily requiring hardware inventory. The 2022 language explicitly encompasses information assets (databases, documents, contracts), software assets (applications, systems), physical assets (hardware, infrastructure), services (cloud services, SaaS, IT utilities), and associated assets (credentials, certificates, API keys). If a SaaS application processes data within your ISMS scope, it must appear in the inventory with a named owner. Auditors following the 2022 standard will test SaaS application coverage explicitly.

The Three Asset Management Controls Explained

A.5.9
Inventory of Information and Other Associated Assets

A.5.9 is the foundational control. It requires that organizations identify information and other associated assets within the ISMS scope and maintain an inventory of those assets. Each asset must have an assigned owner. The inventory must be kept current — new assets added when they are introduced, changes reflected when they occur, retired assets removed at disposal.

The inventory must capture, at minimum: asset name and description, asset type and classification, assigned owner, location or hosting environment, and current lifecycle status. Classification categories typically range from Public to Restricted or Confidential, reflecting the asset's sensitivity to information security. The classification determines which security controls apply — assets classified as containing confidential data require stronger access controls than public-facing assets.

What Auditors Test for A.5.9

Auditors verify that an inventory exists and is current. They will select a sample of known systems from other evidence sources (network diagrams, incident records, change management records) and verify they appear in the inventory with current ownership. They will check that assets added to the environment in the past 6–12 months appear in the inventory. They will check that decommissioned systems have been removed or marked as retired. A spreadsheet that was current at the time of the last audit but has not been updated since fails A.5.9 in dynamic environments where new systems are regularly introduced. According to ISO 27001 Lead Auditor guidance, maintaining an accurate inventory is a mandatory and non-negotiable requirement — not an aspirational goal.

The Ownership Requirement

Every asset in the inventory must have a named owner — a specific individual (not a team name, not a department) who is accountable for the asset's security posture and lifecycle decisions. Ownership should be documented at the time the asset enters the environment, not assigned retrospectively during audit preparation. When an asset owner leaves the organization, the ownership record must be updated to the successor. Unowned assets are an A.5.9 finding even if the asset is otherwise accurately recorded in the inventory.

A.5.10
Acceptable Use of Information and Other Assets

A.5.10 requires that rules for acceptable use of information and associated assets are identified, documented, and implemented. This is not simply a policy requirement — it requires that acceptable use rules exist for each asset type, that employees are informed of those rules, and that the rules are enforced rather than just documented.

In operational terms, A.5.10 means: for every asset in the A.5.9 inventory, there must be defined rules governing how it may be accessed, processed, transmitted, and stored. For a laptop, acceptable use rules might cover personal use limits, mandatory encryption, and required MDM enrollment. For a cloud storage bucket, acceptable use rules define what data classifications may be stored, who may access it, and what sharing restrictions apply. For a SaaS application, acceptable use rules define which employee roles may access it and what data may be processed within it.

What Auditors Test for A.5.10

Auditors typically verify that an acceptable use policy exists and has been communicated to relevant users, that specific asset types have specific use rules rather than a single generic policy, and that there is evidence of training or acknowledgment by employees. The A.5.10 finding most commonly cited is an organization with a generic "acceptable use policy" that does not address specific asset types or data classifications — technically existent but insufficiently specific to satisfy the control's intent.

A.5.11
Return of Assets

A.5.11 requires that employees and external parties return all organizational assets upon termination of employment or contract. The return requirement applies to all asset types — hardware devices, access credentials, software licenses, data stored on personal devices, and organizational documents. A.5.11 is the asset management control most directly connected to the offboarding process — and the one most frequently found deficient in audits where offboarding is handled informally.

The practical requirement is documented: at termination, each asset assigned to the departing employee should be explicitly recorded as returned, and the return should be confirmed by IT rather than assumed. For hardware devices, this means a physical confirmation record. For software licenses and SaaS access, this means verified revocation records rather than assumed removal. For credentials and certificates, this means confirmed rotation or revocation.

What Auditors Test for A.5.11

Auditors select a sample of terminated employees from the review period and verify that return confirmation records exist for each assigned asset. Missing return records, assets recorded as assigned in the inventory but with no return confirmation, and SaaS access with no revocation record for terminated users are all A.5.11 findings. The connection to ghost access — the most common security exposure from incomplete offboarding — is examined in detail in Why Ghost Access Is Your Biggest Security Threat.

What the ISO 27001 Asset Inventory Must Contain

The standard does not prescribe a specific format for the asset inventory — but auditors apply consistent expectations about the minimum data fields that a satisfactory inventory contains.

FieldRequired?Purpose
Asset name / IDRequiredUnique identification; enables cross-referencing with incident and change records
Asset typeRequiredHardware, software, SaaS, cloud resource, data, credential, certificate, service
Asset ownerRequired — named individualAccountability for security posture; not a team or department
ClassificationRequiredDetermines applicable security controls; typically Public / Internal / Confidential / Restricted
Location / hostingRequiredPhysical location for hardware; cloud region / provider for cloud; SaaS vendor for applications
Lifecycle statusRequiredActive / In maintenance / End of life / Decommissioned — enables scope management
Assigned user / departmentRequired where applicableConnects asset to access rights; enables A.5.11 return tracking
Purchase / contract dateRecommendedSupports lifecycle management, depreciation, renewal planning
Last verified dateRequired by implicationDemonstrates the "current" requirement is actively maintained, not static

The "last verified date" field is often absent in inventories that otherwise contain the required fields. Auditors use this field to assess whether the "current" requirement is met — an inventory with no verification dates cannot demonstrate recency. Automated discovery systems that continuously update asset records satisfy this requirement structurally.

Multi-Framework Efficiency: One Inventory, Multiple Standards

A well-maintained ISO 27001 asset inventory satisfies the asset management requirements of multiple frameworks simultaneously — reducing the operational overhead of maintaining separate compliance programs for each.

ISO 27001 A.5.9 → SOC 2 CC6.1

SOC 2's Common Criteria CC6.1 requires that "prior to issuing system credentials and granting system access, the entity registers and authorizes new internal and external users." The asset inventory that satisfies A.5.9 provides the system scope definition required for CC6.1 — demonstrating that all in-scope systems are known and that access controls are applied comprehensively. The connection is direct: an organization that cannot produce a complete asset inventory cannot demonstrate that CC6.1 access controls cover all in-scope systems.

ISO 27001 A.5.9 → NIST CSF ID.AM

NIST Cybersecurity Framework Identify function, Asset Management category (ID.AM) requires that physical devices and software in the organization are inventoried, business environment priorities are established, and resources are prioritized based on risk classification. A current, classified ISO 27001 A.5.9 inventory directly satisfies ID.AM-1 and ID.AM-2 without any additional documentation effort.

ISO 27001 A.5.11 → HIPAA § 164.310(d)

HIPAA Security Rule § 164.310(d) requires device and media controls including procedures for the final disposition of electronic protected health information and hardware containing it. The asset return documentation required by A.5.11 — confirmed hardware return at termination, confirmed data sanitization at disposal — satisfies the HIPAA device disposal requirements as part of the same operational process.

Organizations pursuing multiple framework certifications should design their asset management program to satisfy all of them from a single operational process rather than maintaining parallel compliance activities. The ITAM implementation roadmap that covers this unified compliance approach is in ITAM Implementation Roadmap: Getting Started in 90 Days.

How WorkVerge Satisfies ISO 27001 Asset Management Controls

WorkVerge's unified ITAM platform is designed to satisfy ISO 27001 asset management requirements as an operational outcome rather than a compliance activity — the inventory is current because discovery is continuous, ownership is assigned because provisioning workflows capture it at enrollment, and return documentation is generated because offboarding workflows execute it systematically.

  • A.5.9 — Complete, Current Inventory with Named Owners: WorkVerge maintains a live asset graph covering hardware (via agent-based endpoint discovery), cloud resources (via AWS, Azure, GCP API queries), and SaaS applications (via identity provider sync). Every asset has a named owner field — captured at provisioning through HRIS integration, updated when role changes occur, flagged when the owner leaves the organization. The inventory is current because it is updated by operational events, not by periodic manual audit. Generating the A.5.9 evidence report is a filtered export — not a data assembly project. For the full discovery architecture, see How to Automate Asset Discovery: Save 20 Hours/Month.
  • A.5.9 — Asset Classification: WorkVerge's asset records include classification fields — Public, Internal, Confidential, Restricted — configurable to match the organization's information classification scheme. Classification is applied at enrollment and can be updated systematically as classification policies evolve. Assets approaching end-of-life or carrying outdated classification labels surface as alerts, enabling proactive classification governance rather than reactive audit remediation.
  • A.5.10 — Acceptable Use Enforcement: WorkVerge's software access visibility connects acceptable use policies to actual access records — identifying SaaS applications that employees are using outside approved policy scope (shadow IT), or applications where access rights exceed the role definition. Access review workflows built on this visibility provide the A.5.10 enforcement evidence that auditors require beyond the policy document itself.
  • A.5.11 — Return of Assets at Termination: The WorkVerge offboarding workflow, triggered by HRIS termination records, generates an asset return checklist for every assigned device, revokes SaaS access across connected applications, and logs each action with timestamp in the execution audit trail. The A.5.11 evidence for any terminated employee is the workflow execution log — complete, timestamped, and linked to the HRIS event that triggered it. No manual assembly required at audit time. The broader offboarding framework that A.5.11 connects to is covered in Employee Onboarding and Offboarding: Complete Workflow Guide.

Conclusion: A.5.9 Is Not a Documentation Exercise

ISO 27001 asset management controls are often framed as documentation requirements — create an inventory, write a policy, document a process. That framing misses the operational intent. The controls exist because security programs that do not know what assets they have consistently fail to protect the data those assets contain. The inventory is not evidence for an auditor. It is the operational foundation on which every other control depends.

Organizations that treat A.5.9 as a documentation exercise typically find their inventories accurate at the moment of creation and degrading continuously thereafter. Organizations that build ITAM programs around continuous automated discovery and workflow-driven ownership assignment find their inventories accurate as a steady state, not as a periodic achievement. The difference in audit experience between these two approaches is significant — but the more important difference is in the security posture they produce in the periods between audits, when no auditor is looking.