# Asset management policy

Source: https://aestech.com.au/policy-templates/#asset-management-policy
Markdown URL: https://aestech.com.au/policy-templates/asset-management-policy.md

Use for ISO 27001 A.5.9, A.5.10, A.5.11, A.7.9 to A.7.14, SOC 2 Security, and PCI DSS asset inventory expectations.

Frameworks: ISO 27001, SOC 2, PCI DSS

Use this as a starting point only. Adapt it to your real scope, systems, legal obligations, customer commitments and operating process.

```text
1. Purpose
This policy defines how information and the assets that support it are identified, recorded, owned, handled, returned and disposed of, so that the company knows what it has, who is responsible for it, and that assets are protected throughout their life cycle.

2. Scope
This policy applies to all assets associated with information and information processing, including hardware such as laptops, mobile devices, servers and removable media, software and SaaS subscriptions, cloud resources, information assets such as databases and repositories, and supporting services. It applies to all employees and contractors who are issued or handle company assets.

3. Policy statements
- An inventory of assets must be maintained and kept accurate, recording at minimum the asset, its owner, its location or hosting, its classification and its status.
- Every asset in the inventory must have a named owner responsible for its protection, appropriate handling and life cycle decisions.
- Assets must be handled in accordance with the classification of the information they store or process, as defined in the information classification policy.
- Company equipment must not be modified, lent or used in ways that compromise its security controls, and must be physically protected when off premises.
- Removable media may be used only where approved, must be encrypted when carrying confidential data, and must be tracked while in use.
- All company assets, including devices, media, access cards and documentation, must be returned on termination of employment or engagement, or when no longer required for the role.
- Equipment and media containing company data must be securely sanitised or physically destroyed before disposal, resale, return to a lessor or reuse, using methods that prevent data recovery.
- Disposal of assets must be recorded, and bulk or third-party destruction must be supported by a certificate of destruction.
- Unaccounted-for assets must be investigated, and lost assets containing company data must be reported as security events.

4. Roles and responsibilities
- The [IT Manager] maintains the asset inventory and manages issue, return and disposal of equipment.
- Asset owners approve access to and handling of their assets and confirm inventory accuracy.
- [HR] triggers asset return at offboarding and confirms completion with IT.
- All staff take reasonable care of assigned assets and report loss, theft or damage immediately.

5. Procedures
- Record new assets in the inventory at procurement or creation, and assign an owner.
- Issue equipment to staff against a signed record of receipt.
- Reconcile the inventory at least [annually] against device management and procurement records.
- At offboarding, collect all assets, confirm return against the issue record and wipe or reassign devices.
- Sanitise storage using secure erase, cryptographic erasure or physical destruction, and record the method, date and person responsible.

6. Evidence and records
Keep the asset inventory, issue and return records, reconciliation results, sanitisation and disposal logs, certificates of destruction, lost asset incident tickets and exception approvals.

7. Review cadence
This policy is reviewed at least annually and after significant changes to equipment, hosting or ways of working.

Owner: [role]
Version: [x.y]   Approved by: [name/role]   Date: [date]
```

Full template pack: https://aestech.com.au/policy-templates/policy-pack.md