Asset Management Policy
Purpose
You cannot protect what you cannot see. This policy makes sure that every asset supporting our company or customer services is known, owned, classified, and controlled through its full life, from the day it is commissioned to the day it is disposed of.
Asset classes
The following are treated as assets under this policy:
- Devices — laptops and removable media
- Infrastructure — servers, cloud resources, storage, and network components
- Software and data — applications, code repositories, and databases
- Accounts and services — service accounts, third-party services, and licences
- Information — documents and records
Inventory requirements
Every asset is recorded in the inventory with:
- Owner
- Custodian
- Purpose
- Classification
- Environment
- Location or provider
- Users and administrators
- Criticality
- Creation date
- Review date
- Decommission status
Commissioning
Before an asset goes into production or is used for customer work, it is approved, assigned an owner, configured securely, documented, and entered into the inventory. An asset in use but not in the inventory is treated as an exception to be corrected, not an accepted state.
Review
Inventories are reviewed periodically and again after any major system change. Anything unused, duplicated, or unrecognised is investigated and retired where appropriate.
Decommissioning and disposal
Assets are taken out of service through a defined sequence:
- Securely delete the data held on them
- Revoke associated access
- Review backup and retention obligations before removal
- Release or reassign any licences
- Update the asset's status in the inventory
Evidence maintained
- Asset inventory
- Ownership records
- Configuration checklists
- Access lists
- Disposal records
- Review evidence