An information asset register lists what content your organisation holds, where it lives, who owns it, and how sensitive it is. It is the foundation that every other governance decision builds on. Without one, retention, classification, and access reviews are educated guesses.
What an asset register captures
For each information asset, capture at minimum:
- Asset name: a clear, human-readable name (e.g. Employee records, Contracts, Project documentation)
- Description: what the asset contains
- Owner: the person or team accountable for the asset
- Location: where it lives (SharePoint site, library, mailbox, line-of-business system)
- Sensitivity: Public, Internal, Confidential, Highly Confidential
- Personal information: yes or no, and what types
- Retention: how long you must keep it and the authority
- Disposal action: delete, archive, or transfer
- Volume: rough size and growth rate
Where to build it
A SharePoint list works well. Capture each row as an asset, use choice columns for sensitivity and disposal action, and link to the source location via a hyperlink column. The list becomes a living document, not a one-off spreadsheet that ages on a shared drive.
How to populate it
Start with the categories that are easiest to identify:
- Walk through each business function (HR, finance, sales, operations, legal)
- For each function, list the major information assets it produces or holds
- Identify the system or location for each asset
- Capture sensitivity and retention based on existing policy or legal advice
Do not try to capture every document. Capture asset types and the places they live.
Use it to drive decisions
Once the register exists, use it to:
- Prioritise sensitivity labelling (label the highest-sensitivity assets first)
- Design retention policies in Microsoft Purview
- Identify gaps where personal information is stored without controls
- Map data flows for Privacy Act compliance
- Inform access reviews and permission audits
Keep it alive
Review the register at least annually. Add new assets as they are created. Retire assets that no longer exist. A stale register loses trust quickly.
To scope an information asset register engagement, submit a support ticket.
Comments
0 comments
Please sign in to leave a comment.