Skip to content
OnTrackio

Free template

ISO 27001 asset register template

The A.5.9 inventory as a ready-to-use XLSX: information, hardware, software, and service assets in one register with named owners, a classification guide, and the review log that proves "maintained". Correct 2022 numbering with the 2013 mapping included. Direct download, no email gate.

Want to know when this template changes? Regulations and criteria move. Email sales@ontrackio.com and we will send the new version. Nothing else, no newsletter.

What is inside

Four sheets. The How to use sheet carries the control text, the 2013-to-2022 mapping, and the four rules that survive an audit; the other three are the working record:

  • Asset register. Twelve columns across all four asset categories the control expects: information, hardware, software and services, and outsourced services. Four worked example rows, one per category.
  • Classification guide. A four-level example scheme (Public, Internal, Confidential, Restricted) with handling expectations. Replace it with your own scheme if one exists; the register only asks that levels be consistent.
  • Review log. Dated review passes with scope and reviewer. Your own policy sets the cadence; this sheet is what proves the cadence happened.

Running NIS2 or SOC 2 as well? The same spine carries all three: the NIS2 register template adds the Implementing Regulation's field list, and the SOC 2 inventory template splits by asset class for the CC6 sampling style.

Frequently asked questions

Which ISO 27001 control does this template serve?

Annex A control A.5.9 of the 2022 edition: an inventory of information and other associated assets, including owners. If you still run 2013 numbering, that is the successor to A.8.1.1 and A.8.1.2; the acceptable-use reference column bridges A.5.10 and the return-required flag bridges A.5.11.

Why does the register include information assets, not just devices?

Because the control puts information first, and a hardware-only register covers half of it. The template's category column keeps the customer database, the contract repository, the fleet, the SaaS estate, and outsourced processing in one auditable place with one ownership discipline.

Is the template free, and does it certify anything?

Free, direct download, no email gate, and it certifies nothing. Certification is an accredited auditor's judgment of your whole ISMS. This file gives one control family, the asset controls, a defensible working record.

How do auditors test the register?

By sampling: pick a row and interview its owner, pick a real device and find it in the register, check the review log against your own stated cadence, and trace a system from the risk assessment into the register. The columns exist to survive exactly those probes, and the companion guide walks through each one.

The register that stays maintained

OnTrackio keeps the same register agent-reconciled with owners, classification, and a change history, exported in ISO, NIS2, or SOC 2 vocabulary. Public pricing, 30-minute demo.