Security

ISO 27001 Asset Management Controls: A Practical Checklist

A6.5–A6.7 (Annex A) translated into concrete actions your team can complete this quarter, with evidence templates.

JJoel Rivera··7 min read

The 2022 revision of ISO 27001 moved asset management into theme A6 (People) and theme A7 (Physical). For an auditor, four controls dominate.

A6.5 Inventory of information and other associated assets

Maintain a living inventory with an owner per asset. Evidence: a CSV export of every asset, owner, and classification, dated within the audit window.

A6.6 Acceptable use of information and associated assets

A signed acknowledgement on issue. Evidence: per-asset assignment record with timestamp and user.

A6.7 Return of assets

Documented offboarding with asset retrieval. Evidence: check-in record on the day of termination plus a secure wipe certificate.

A7.10 Storage media

Disposal procedure for storage media. Evidence: certificate of destruction or wipe.

AssetMon's immutable audit log captures every check-out, check-in, status change and assignment — exactly the trail ISO auditors want to see.

#ISO 27001#asset management controls#compliance#audit-ready