3.2 Organizational Controls: Asset Management & Information Classification (A.5.9–A.5.14)

Key Takeaways

  • Control A.5.9 mandates an inventory of information and other associated assets, explicitly assigning asset owners who are accountable for asset protection throughout their lifecycle.
  • Control A.5.12 (Classification of Information) categorizes data assets based on legal requirements, business value, criticality, and sensitivity to unauthorized disclosure.
  • Control A.5.13 (Labelling of Information) requires a comprehensive labeling scheme covering physical documents, electronic files, and data in transit.
  • Control A.5.14 (Information Transfer) mandates formal policies, technical protocols, and transfer agreements to safeguard data across internal and external networks.
  • Asset Owners hold ultimate accountability for classification and access approval, while Asset Custodians carry operational responsibility for executing day-to-day technical safeguards.
Last updated: July 2026

3.2 Organizational Controls: Asset Management & Information Classification (A.5.9–A.5.14)

Information and its supporting technical infrastructure represent the lifeblood of modern enterprise operations. Controls A.5.9 through A.5.14 provide the governance and operational framework required to discover, inventory, classify, label, handle, and securely transfer information assets throughout their lifecycle.


Overview of Asset Management Controls (A.5.9 – A.5.14)

Control IDControl NameCore Implementation RequirementLead Implementer Evidence
A.5.9Inventory of information and other associated assetsIdentify, record, and assign accountable owners to all information assets.Centralized Asset Register with designated Asset Owners
A.5.10Acceptable use of information and other associated assetsDefine and enforce clear rules for the acceptable handling of assets.Signed Acceptable Use Policy (AUP) & employee training records
A.5.11Return of assetsEnsure all physical and logical assets are returned upon termination or contract end.Offboarding HR Checklist & Asset Return Sign-off Forms
A.5.12Classification of informationCategorize information according to business sensitivity, value, and legal exposure.Information Classification Scheme & Data Asset Inventory
A.5.13Labelling of informationImplement standardized labeling controls matching assigned classification levels.Visual document labels, DLP metadata tags & banner headers
A.5.14Information transferProtect information during transit across internal and external networks or media.Secure Transfer Policy, TLS 1.3/SFTP standards & ITAs

Asset Inventory & Ownership Lifecycle (A.5.9)

An effective Information Security Management System (ISMS) cannot safeguard assets that are unknown or unmanaged. Control A.5.9 mandates the creation and continuous maintenance of an accurate Asset Inventory. Assets within an ISMS scope fall into five core taxonomy categories:

  1. Information Assets: Databases, customer PII, intellectual property, financial ledgers, system documentation, trade secrets.
  2. Software Assets: Enterprise applications, operating systems, cloud SaaS instances, custom code repositories.
  3. Physical Assets: Servers, networking hardware, laptops, mobile devices, backup tapes, physical paper archives.
  4. Service Assets: Cloud utilities, internet service providers (ISPs), power grid connections, SaaS platform services.
  5. People Assets: Personnel, specialized technical contractors, researchers holding institutional knowledge.

Asset Owner vs. Asset Custodian

A critical distinction rigorously tested on the PECB Lead Implementer exam is the boundary between Ownership (Accountability) and Custody (Operational Execution):

+-------------------------------------------------------------------------+
| ASSET OWNER (Accountability)                                            |
| - Typically a Business Unit Executive, Vice President, or Data Trustee. |
| - Accountable for establishing the asset's classification level.        |
| - Approves access permission requests and defines security requirements. |
| - Conducts periodic access recertifications and accepts residual risks. |
+-------------------------------------------------------------------------+
                                   |
                                   v Delegates technical management
+-------------------------------------------------------------------------+
| ASSET CUSTODIAN (Operational Execution)                                 |
| - Typically IT Operations, Database Administrators, Cloud Engineers.     |
| - Implements technical safeguards (encryption, backups, patching).      |
| - Manages physical storage, network routing, and daily maintenance.      |
+-------------------------------------------------------------------------+

Information Classification Schemes (A.5.12)

Control A.5.12 requires information to be classified to ensure that security controls are applied proportionately according to business value, legal requirements, and sensitivity to harm. A standard commercial four-tier classification scheme includes:

Classification LevelImpact & Sensitivity DefinitionTypical Data ExamplesRequired Baseline Security Safeguards
Confidential / SecretSevere financial loss, legal penalties, or catastrophic reputational damage if disclosed.Trade secrets, acquisition plans, cryptographic keys, root credentials.Mandatory AES-256 encryption at rest/transit, strict RBAC, DLP blocking, NDA required.
Restricted / PrivateModerate to high impact. Contains sensitive operational data or regulated privacy data.Customer PII, health records (ePHI), financial statements, employee HR files.Encrypted in transit & at rest, access strictly restricted to need-to-know, audit logging.
Internal / StandardMinor impact if disclosed outside the entity. Standard business operating data.Internal wikis, organizational charts, policy documents, internal announcements.User authentication required; default baseline security for corporate staff.
PublicZero business impact if disclosed. Explicitly cleared for public distribution.Marketing press releases, public website pages, published product documentation.Integrity controls to prevent unauthorized web alteration; no confidentiality rules.

Labelling & Media Handling (A.5.13)

Control A.5.13 ensures that classification levels are clearly communicated through standardized labeling across all media formats:

  • Physical Document Labelling: Header/footer classification stamps, color-coded binder covers, and secure handling marks on printed documents and physical storage boxes.
  • Digital Document Labelling: Automated Data Loss Prevention (DLP) metadata tags embedded into Microsoft Office and PDF files, visual header banners in documents, and subject line prefixes in email messages (e.g., [RESTRICTED-PII]).
  • Removable Media & Sanitization: Removable storage media (USB drives, external SSDs, backup tapes) containing classified data must be labeled. Physical media disposal must follow strict sanitization standards (e.g., NIST SP 800-88, degaussing, or physical shredding to DIN 66399 Level P-4 or higher) with signed destruction certificates.

Information Transfer Controls (A.5.14)

Control A.5.14 protects data in transit across internal networks, public internet connections, and physical transit. Lead Implementers must enforce:

  1. Acceptable Transfer Channels: Prohibiting the transmission of classified corporate data over unencrypted commercial messaging tools or personal email accounts.
  2. Technical Encryption Safeguards: Mandating modern cryptographic protocols—such as TLS 1.3 for web API endpoints, SSH/SFTP for server file transfers, and end-to-end payload encryption for sensitive email attachments.
  3. Information Transfer Agreements (ITAs): Formal legal agreements signed prior to exchanging data with external business partners. ITAs define data protection duties, permitted usage, mandatory encryption mechanisms, incident notification SLAs, and data return/destruction obligations upon contract completion.

Real-World Implementation Scenario:
A healthcare technology provider processes electronic health records (ePHI). The Lead Implementer designates the Chief Medical Officer as the Asset Owner (A.5.9) for patient data. The asset owner classifies patient data as Confidential - ePHI (A.5.12). Under Control A.5.13, automated DLP rules tag all outgoing patient files. Under Control A.5.14, external transfers to medical research partners require mutual TLS (mTLS) 1.3 encryption and mandatory execution of a formal Information Transfer Agreement alongside a HIPAA Business Associate Agreement (BAA).

Test Your Knowledge

An enterprise defines operational roles for its customer database. The Head of Sales determines who may access customer accounts and sets the data sensitivity level, while the Senior Database Administrator executes daily backup jobs, applies encryption keys, and patches the database server. What role is the Database Administrator fulfilling under Control A.5.9?

A
B
C
D
Test Your Knowledge

What is the PRIMARY objective of Control A.5.12 (Classification of information) within an ISO/IEC 27001 Information Security Management System?

A
B
C
D
Test Your Knowledge

When establishing an Information Transfer Policy under Control A.5.14 to govern data exchanges with external third parties, which requirement MUST be formally incorporated?

A
B
C
D