Asset Inventory Template
How to develop an asset inventory and operate the corresponding control
Written By Micah
What is the Asset Inventory control?
Strike Graph’s asset inventory control description includes the following language:
An inventory of information assets, including hardware, software, is maintained and updated at least annually. All assets have an assigned asset owner. All assets are classified based on the data classification convention.
Why is this control important?
Assets are anything valuable and necessary for the function of your service (data is also considered an asset, but that should be tracked on a separate register). Knowing which software and hardware assets store, transmit, and process data is beneficial for several reasons: you will know where your data resides so that you can apply appropriate logical and physical access controls, and track who "owns" which products to make decisions about maintenance and invoice approvals.
You must also identify whether the asset touches sensitive or confidential information (based on how you classify your data). Any asset that holds, transmits, or processes sensitive or confidential information should have appropriate security controls applied. For guidance on classifying your organization’s data, please refer to our Data Classification Policy article and corresponding template.
Who's involved with this control?
Typical Control Owner: CTO (or equivalent)
Typical Parties Involved: Security Manager
When should I perform this control?
The list should be updated and reviewed annually at a minimum, but in most organizations, this inventory is a "living" document.
How do I perform this control?
In smaller organizations, the simplest way to track hardware is to maintain a spreadsheet of assets based on purchasing history. Tools like Asset Tiger can also be used to track hardware assets. If tracking manually, details to include are:
Make
Model
Purchase date
Who has been issued the asset
Classification - Assign the strictest classification considering the data held or transmitted through the asset.
Remember to consider on-site servers, routers, desktops, and modems.
For software, we find it useful to maintain a spreadsheet of all products utilized from development tools to HR and sales tools. The software asset list should include both purchased and free tools. Include who in the organization makes decisions about the product (typically who will approve the invoice), the team that primarily uses the software, who the superusers or admins are, and what the password settings look like. This way you can ensure that the settings either follow the corporate password policy, or that any exceptions to the policy have been approved.
A video demonstration of how to utilize the Asset Inventory template can be found here.
Tip: On your software inventory, include information on licensing and renewal dates. Then this document becomes both an IT compliance artifact as well as a budgeting or money-saving tool! You can track how many licenses you own, and whether you need to increase or reduce the number of users.
This template includes five different tabs/sheets. Navigate to the tab that is most relevant to your organization.
Commonly associated evidence:
Asset Inventory (can also be known as Asset Register)
Asset Inventory Procedures
Who needs a control like this?
All businesses
How to use the template:
Click on the link above to access the template
If you are a Google Workplace organization, make a copy by going to File > Make a copy
If you are not a Google Workplace organization, download a copy by going to File > Download and selecting your preferred file type (available as DOCX, PDF, and more)
Review and then remove instructional text
Save in a centralized place
Attach to evidence either through Integrations, Automated Collection, or direct upload
If you need help using the template, please let us know.