Expert Advice Community

Guest

Asset register

  Quote
Guest
Guest user Created:   May 20, 2017 Last commented:   May 20, 2017

Asset register

I am working on my Information Asset Register and I have a few questions:
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal May 20, 2017

1 - We as an organisation have a LinkedIn account, which have a number of contacts on so would we need to put this on the register?

Answer: If your organization uses this account to help support the business you should include it as an asset, because it contains information that should be properly protected (the business contacts). To help you define this need you can ask yourself "what if I do not have access to information from this account any more?"

2 - What about our email folders and actual emails, do they have to be recorded on the register?

Answer: Also yes if these emails contain information the business needs to be performed and the loss of these will affect the organization capacity to do business. But you do not need to refer to the e-mail folders and e-mails themselves in the register. You can included only the relevant e-mail account (e.g., CEO email account) or e-mail service (if you are using a cloud service like Gmail).

3 - Some of the girls in the office record information on Notebooks and store them in locked draws when they are not in use, again would these need to be recorded on the register?

Answer: Again you have to think about what would happen to the business if the information on these notebooks was lost (in case of a robbery or damage of the notebooks, at least you would have a financial loss regarding the equipment). If the impact is relevant to the organization it should be considered in the asset register.

This article will provide you further explanation about asset registry:
- How to handle Asset register (Asset inventory) according to ISO 27001 https://advisera.com/27001academy/knowledgebase/how-to-handle-asset-register-asset-inventory-according-to-iso-27001/

These materials will also help you regarding asset registry:
- Book Secure & Simple: A Small-Business Guide to Implementing ISO 27001 On Your Own https://advisera.com/books/secure-and-simple-a-small-business-guide-to-implementing-iso-27001-on-your-own/
- Free online training ISO 27001 Foundations Course https://advisera.com/training/iso-27001-foundations-course/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

May 20, 2017

May 20, 2017

Suggested Topics