Evidence
The asset inventory everything else depends on
It is unglamorous, it is the foundation of the risk assessment, and it is the artefact most likely to be out of date by the audit.
Facts checked — 2026-09-11
How do you keep an asset inventory accurate?
An inventory needs an owner per asset, a classification, and enough detail to support a risk decision. What it does not need is exhaustive depth — an inventory of every laptop screw is a document nobody maintains, and an unmaintained inventory is worse than a coarse one.
Wherever possible, derive it rather than type it: cloud resources from the provider’s API, endpoints from the device management tool, repositories from the source host. A derived inventory is current by construction; a typed one is current on the day it was typed.
The bottom line
Derive what you can, own what you cannot, and keep it coarse enough that somebody will actually maintain it.
Related services
ISO/IEC 27001 — Information Security Management
Build an information security management system that survives Stage 2 — and the three years of surveillance that follow.
Related insights
Evidence
Running an internal audit that is worth the day it costs
Its job is to find things before the external auditor does, not to pass.
Evidence
Corrective action is not the same as fixing it
A fix addresses the instance. Corrective action addresses why it happened.
Evidence
Evidence that collects itself
If producing evidence is a separate task, it will be skipped in a busy quarter.