Assets, data and classification
The inventory, the classification scheme and the handling rules: what the organisation holds, how sensitive it is, how it moves, how long it is kept and how it is destroyed.
Policy types in this family
7- Asset management policy policy
What is held, who owns it, how it is recorded through its life and what the owner must do with it. Required by ISO 27001, NIS2; owner the head of IT operations. - Data governance policy policy
Who owns each data set, the quality it must meet, where it comes from and how it may be used, including as training data. Required by ISO 27001, ISO 42001; owner the AI governance lead (CTO, CDO or head of data science). - Information classification and handling policy policy
The classification scheme, the criteria for each level, the label each carries and the handling rules for each level in each medium. Required by ISO 27001, ISO 27701; owner the information security lead (CISO or ISMS manager). - Information transfer policy policy
How information moves between people, systems and organisations, by which channels, with which protections, and under which agreements. Required by ISO 27001, ISO 27701; owner the information security lead (CISO or ISMS manager). - Media handling and disposal policy policy
How storage media and equipment are used, moved, wiped and destroyed, and the record of destruction. Required by ISO 27001, ISO 27701; owner the head of IT operations. - Records retention schedule record
How long each class of record is kept, on what basis, where, and how it is destroyed when the period ends. Required by ISO 27001, ISO 27701, GDPR; owner legal or the compliance officer. - Software asset management policy policy
Which software may be installed, by whom, under which licences, and how the installed estate is inventoried. Required by ISO 27001; owner the head of IT operations.
What reaches this family
| ISO 27001 | Expects: asset management policy, information classification and handling policy, information transfer policy, media handling and disposal policy, records retention schedule. Requires, by clause: ISO 27001 5.9, ISO 27001 5.11, ISO 27001 5.12, ISO 27001 5.13, ISO 27001 5.14, ISO 27001 7.10, ISO 27001 7.14, ISO 27001 8.10, ISO 27001 5.33, ISO 27001 8.19. |
|---|---|
| ISO 27701 | Expects: records retention schedule. Requires, by clause: ISO 27701 A.3.5, ISO 27701 A.3.6, ISO 27701 A.3.7, ISO 27701 A.3.20, ISO 27701 A.3.21, ISO 27701 A.1.4.9, ISO 27701 A.1.4.8. |
| ISO 42001 | Expects: data governance policy. Requires, by clause: ISO 42001 A.7.2, ISO 42001 A.7.4, ISO 42001 A.7.5. |
| NIS2 | Expects: asset management policy. Requires, by clause: NIS2 Art. 21(2)(i). |
| GDPR | Expects: records retention schedule. Requires, by clause: GDPR Art. 5. |
Register the documents in this family
Paste the list; every document in this family is placed in its type, given its owner and cadence against the clauses, and the ones the regimes expect and the list does not carry are named. Eight documents free, no account.
Build a register