Resources / Free policy templates
Free Asset Management and Information Classification Policy Template (Word)
The complete template is below — read every word before you download. Editable Word version, no email required. Satisfies: ISO/IEC 27001:2022, ISO/IEC 27001:2022 Annex A 5.9, 5.10, 5.11, 5.12, 5.13, 7.10, 7.14, 8.10.
Download the Word template (.docx) — free
Get new templates and guides by email
An occasional email when we publish a new free template, guide, or dataset. Unsubscribe any time.
[Organization Name]
Asset Management and Information Classification Policy
ISO/IEC 27001:2022 — ISO/IEC 27001:2022 Annex A 5.9, 5.10, 5.11, 5.12, 5.13, 7.10, 7.14, 8.10
This template is a complete, adoptable asset management and information classification policy aligned to ISO/IEC 27001:2022. It covers asset inventory, ownership, acceptable handling, a four-tier classification scheme, labelling, return of assets, and secure disposal. Every [bracketed placeholder] must be replaced with your organization's own names, systems, tiers, and timeframes before the policy is approved and issued.
1. Purpose
This policy establishes how [Organization Name] identifies, owns, classifies, labels, handles, returns, and disposes of information and other associated assets, so that every asset in scope of the information security management system (ISMS) has a named owner and a known sensitivity level and receives protection proportionate to the impact of its loss, disclosure, or modification. It supports ISO/IEC 27001:2022 Annex A controls 5.9 (inventory of information and other associated assets), 5.10 (acceptable use of information and other associated assets), 5.11 (return of assets), 5.12 (classification of information), and 5.13 (labelling of information). The disposal and media provisions in Section 9 additionally support 7.10 (storage media), 7.14 (secure disposal or re-use of equipment), and 8.10 (information deletion).
2. Scope
This policy applies to all information and other associated assets controlled by [Organization Name], in any format and at any lifecycle stage: end-user devices, servers and network equipment, storage media, licensed software and source code, cloud services and SaaS subscriptions, databases and information held in any system, and physical records. It applies to all employees, contractors, temporary staff, and third parties granted access to them.
3. Roles and Asset Ownership
Every asset in the inventory has a named owner, normally the manager of the function that relies on it. The owner classifies the asset, approves who may access it, confirms that handling rules are applied, and authorizes transfer, return, or disposal. [IT Manager] maintains the inventory and its supporting tooling, [Information Security Manager] maintains this policy and the classification scheme, and [Department Managers] confirm that recorded assets and owners remain accurate.
4. Asset Inventory
[Organization Name] maintains an inventory of information and other associated assets in [Asset Register/Asset Management System]. Each record captures an identifier, description and type, owner, location or hosting arrangement, classification, business criticality, and lifecycle status; cloud service and SaaS records also capture the provider, service purpose, and contract owner. Records are created at acquisition or provisioning, updated whenever ownership, location, or classification changes, and reviewed by the asset owner at least [quarterly].
5. Acceptable Handling and Use
Assets may be used only for authorized business purposes, in line with the [Acceptable Use Policy]. Users must not disable security controls, install unapproved software, connect unapproved storage media, or move information to personal accounts, personal devices, or unapproved cloud services. Portable devices and removable media must be encrypted to [Encryption Standard] and must not be left unattended in unsecured locations. Loss, theft, or suspected compromise of an asset must be reported to [Reporting Channel].
6. Information Classification Scheme
The asset owner classifies information by the impact that unauthorized disclosure, modification, or loss would have on [Organization Name], its customers, and its legal obligations. The scheme has four tiers: [Public], approved for release outside the organization; [Internal], routine business information for staff and authorized third parties; [Confidential], sensitive business, customer, or personal data limited to defined roles; and [Restricted], information whose compromise would cause severe harm to the organization, its customers, or individuals, of the kinds listed in [Restricted Data Examples]. Unclassified information is treated as [Internal], and classification is reviewed when information changes purpose or sensitivity.
7. Labelling and Handling Rules by Tier
Information classified above [Public] is labelled consistently in document headers or footers, email subject lines or message classification tags, repository and database metadata, and on media and printed records. [Public] information requires approval from [Communications Owner] before release and carries no confidentiality restrictions once released, but remains subject to the integrity and availability controls that apply to all [Organization Name] information. [Internal] information may be shared internally, and externally under a confidentiality agreement, and is stored only in [Approved Systems]. [Confidential] information also requires need-to-know access, encryption in transit and at rest, and owner approval before external sharing. [Restricted] information also requires multi-factor authentication, logged access, storage only in [Approved Restricted Systems], and no transfer outside [Approved Transfer Channels].
8. Return of Assets
On termination of employment, expiry or termination of a contract, or a role change that removes the need for an asset, all assets issued by [Organization Name] are returned on or before the last working day or the effective date of the change. [Line Manager] initiates the [Offboarding Checklist], and each return is recorded in the inventory within [5 business days], covering devices, storage media, access tokens and keys, and physical records. Where a personally owned device was used under [BYOD Policy], organizational information is removed and the removal is confirmed in writing. Access to systems, cloud services, and premises is revoked in parallel and the inventory record updated.
9. Secure Disposal, Exceptions, and Review
Assets at end of life are disposed of according to the highest classification of information they have held. Media holding [Confidential] or [Restricted] information is sanitized using [Approved Sanitization Method] or physically destroyed before the equipment leaves [Organization Name]'s control, and information held in cloud services is deleted in line with the provider's documented deletion process and the [Data Retention Schedule]. Where [Disposal Vendor] performs disposal, a certificate of destruction is obtained and retained, and the inventory record is closed with the disposal date and method.
Exceptions must be requested in writing, assessed for risk, approved by [Information Security Manager], recorded in the [Exception Register], and given an expiry date. Failure to comply may result in disciplinary action under [Organization Name]'s disciplinary procedure and, for third parties, action under the applicable contract.
This policy is reviewed at least [annually] and after any significant change to the organization, its systems, or applicable legal and contractual obligations. Approved by [Approver Name/Title], version [1.0], effective [Effective Date].
How to customize this template
- Replace every [bracketed placeholder] — [Organization Name], [IT Manager], [Information Security Manager], [Asset Register/Asset Management System], review cadences, and the version and effective date — with your organization's actual names and values.
- Adjust the four-tier scheme in Section 6 to the tier names you already use; if you use three tiers, delete one tier and remove its rules from Section 7 so the two sections stay consistent.
- Confirm the handling rules in Section 7 describe controls you actually operate today (encryption, multi-factor authentication, approved systems) and remove any rule you cannot currently enforce rather than stating it aspirationally.
- Set the return timeframe in Section 8 to match your real offboarding process, and reference your existing offboarding checklist and BYOD policy by their actual document names.
- Populate the asset inventory itself before issuing the policy — including cloud services and SaaS subscriptions — and assign a named owner to every record so Section 3 reflects reality.
- Have the policy approved by the named approver, record the version and effective date, distribute it to staff and relevant third parties, and re-review it on the stated cycle.
One honest caveat, as with everything we publish: no template, free or paid, makes an organization certified or compliant on its own. The document describes the practice; you still operate it.
This is one document — the toolkit is the whole set
This free template is drafted to the same standard as our paid toolkits. If you need the complete, cross-referenced documentation set rather than one policy:
- ISO 27001 Policy Pack — Core —
$59$29.50 - ISO 27001 Complete Toolkit —
$99$49.50 - NIST CSF 2.0 Complete Toolkit —
$79$39.50
