When I audit information security, an asset inventory is the foundation - what information you hold, who owns it and how it is protected. This matrix captures that in one view, so the controls have something to sit on.
This form template is supplied in fully editable MS Word format and can be easily customised and edited. The document uses pre-defined style formatting throughout, with all text in Calibri font for improved readability.
The following document labelling is included in the footer:
- Form number and title
- Information-classification
- Version
- Page number / total pages
alphaZ documents - beautifully designed, tried and tested form templates. No junk, jargon or unnecessary fields. Simple and usable form templates
developed over 25 years through practical use in the real world. No AI generated nonsense here!
Further guidance on information assets and security controls:
Download this form template with your company name and logo already added!
Document Preparation available with all document toolkits.
To get access to this file please click on Add to Cart to purchase for immediate download. If you have an alphaZ Subscription just click on Download Files to view all the files available to download. This form is also included in the ISO 27001 Toolkit and every alphaZ ISO toolkit that covers information security, so the toolkit route gives you this file plus everything else you need in one download.
If you'd like hands-on help mapping your information assets and controls, or your wider information security management system, our remote support services provide direct expert input from our team, by the day, by project, or on an ongoing basis.
An information assets matrix for recording the information your organisation holds and how it is protected - a description of each asset with its context and boundaries, the owner, the protection and controls currently in place, and any comments or actions required. It gives you a single view of your information assets.
ISO 27001 is built on knowing and protecting your information assets, and an asset inventory is where a risk assessment starts. This matrix gives you that inventory and supports the asset management and risk requirements of an information security management system aligned with ISO 27001.
Any organisation that holds information worth protecting benefits from an asset inventory. It suits any business working towards or maintaining ISO 27001, or simply wanting to understand what information it holds and how it is secured.