Blog
Practical guidance on NIS2, ISO 27001, and IT asset management for European IT and compliance teams.
Subscribe via RSS- GDPR and the IT asset register: it cuts both ways
Your asset register contains personal data and produces GDPR evidence at once: what to record, what to leave out, and where it carries Articles 30 and 32.
2026-07-18
- ISO 27001 A.5.9: the asset inventory, control by control
What Annex A control A.5.9 actually requires, how it maps to the old 2013 A.8 controls, what certification auditors sample, and a free register template.
2026-07-18
- Snipe-IT alternatives: seven options compared for 2026
Seven Snipe-IT alternatives compared by an IT team that ran Snipe-IT itself: cloud ITAM platforms, discovery tools, and the honest case for staying put.
2026-07-18
- SOC 2 offboarding: proving the assets came back
Disabling the account is only half of SOC 2 offboarding. Auditors sample leavers for device return, wipe records, and revocation timestamps too.
2026-07-16
- SOC 2 Type II evidence: built during the window, not after
A Type II auditor samples the whole observation window. Records reconstructed at audit season fail; records that accumulate as you operate pass.
2026-07-16
- SOC 2 asset inventory: what auditors actually ask for
SOC 2 names the asset inventory in CC6.1's points of focus. Here is the evidence request behind it: ownership, reconciliation, and offboarding proof.
2026-07-02
- NIS2 asset management evidence: what the law requires
NIS2 names asset management in Article 21(2)(i), and Implementing Regulation 2024/2690 spells out the inventory evidence auditors expect. Here's what to keep.
2026-06-20