Security
ISO 27001 Asset Management Controls: A Practical Checklist
A6.5–A6.7 (Annex A) translated into concrete actions your team can complete this quarter, with evidence templates.
The 2022 revision of ISO 27001 moved asset management into theme A6 (People) and theme A7 (Physical). For an auditor, four controls dominate.
A6.5 Inventory of information and other associated assets
Maintain a living inventory with an owner per asset. Evidence: a CSV export of every asset, owner, and classification, dated within the audit window.
A6.6 Acceptable use of information and associated assets
A signed acknowledgement on issue. Evidence: per-asset assignment record with timestamp and user.
A6.7 Return of assets
Documented offboarding with asset retrieval. Evidence: check-in record on the day of termination plus a secure wipe certificate.
A7.10 Storage media
Disposal procedure for storage media. Evidence: certificate of destruction or wipe.
AssetMon's immutable audit log captures every check-out, check-in, status change and assignment — exactly the trail ISO auditors want to see.