Asset Inventory Template

How to develop an asset inventory and operate the corresponding control

Written By Micah

What is the Asset Inventory control?

Strike Graph’s asset inventory control description includes the following language:

An inventory of information assets, including hardware, software, is maintained and updated at least annually. All assets have an assigned asset owner. All assets are classified based on the data classification convention.

Why is this control important?

Assets are anything valuable and necessary for the function of your service (data is also considered an asset, but that should be tracked on a separate register). Knowing which software and hardware assets store, transmit, and process data is beneficial for several reasons: you will know where your data resides so that you can apply appropriate logical and physical access controls, and track who "owns" which products to make decisions about maintenance and invoice approvals.

You must also identify whether the asset touches sensitive or confidential information (based on how you classify your data). Any asset that holds, transmits, or processes sensitive or confidential information should have appropriate security controls applied. For guidance on classifying your organization’s data, please refer to our Data Classification Policy article and corresponding template.

Who's involved with this control?

  • Typical Control Owner: CTO (or equivalent)

  • Typical Parties Involved: Security Manager

When should I perform this control?

The list should be updated and reviewed annually at a minimum, but in most organizations, this inventory is a "living" document.

How do I perform this control?

In smaller organizations, the simplest way to track hardware is to maintain a spreadsheet of assets based on purchasing history. Tools like Asset Tiger can also be used to track hardware assets. If tracking manually, details to include are:

  • Make

  • Model

  • Purchase date

  • Who has been issued the asset

  • Classification - Assign the strictest classification considering the data held or transmitted through the asset.

Remember to consider on-site servers, routers, desktops, and modems.

For software, we find it useful to maintain a spreadsheet of all products utilized from development tools to HR and sales tools. The software asset list should include both purchased and free tools. Include who in the organization makes decisions about the product (typically who will approve the invoice), the team that primarily uses the software, who the superusers or admins are, and what the password settings look like. This way you can ensure that the settings either follow the corporate password policy, or that any exceptions to the policy have been approved.

A video demonstration of how to utilize the Asset Inventory template can be found here.

Tip: On your software inventory, include information on licensing and renewal dates. Then this document becomes both an IT compliance artifact as well as a budgeting or money-saving tool! You can track how many licenses you own, and whether you need to increase or reduce the number of users.

This template includes five different tabs/sheets. Navigate to the tab that is most relevant to your organization.

Commonly associated evidence:

  • Asset Inventory (can also be known as Asset Register)

  • Asset Inventory Procedures

Who needs a control like this?

  • All businesses

How to use the template:

  • Click on the link above to access the template

    • If you are a Google Workplace organization, make a copy by going to File > Make a copy

    • If you are not a Google Workplace organization, download a copy by going to File > Download and selecting your preferred file type (available as DOCX, PDF, and more)

  • Review and then remove instructional text

  • Save in a centralized place

  • Attach to evidence either through Integrations, Automated Collection, or direct upload

If you need help using the template, please let us know.