HLD Group
Asset management policy
Inventory and lifecycle of information assets.
Last updated: 24 July 2026
Version 1.0 · Review cycle: 365 days · View all frameworks
1. Purpose
This policy defines how HLD Group identifies, records, classifies, and manages information assets throughout their lifecycle. You cannot protect what you do not know you have; an accurate asset inventory is the foundation of every other security control.
2. Scope
This policy applies to all information assets owned, leased, or processed by HLD Group, including hardware, software, cloud resources, data, and the identities and services that act on them.
3. Definitions
- Information asset — any data, system, service, or device that stores, processes, or transmits information
- Asset owner — the person accountable for an asset’s protection and appropriate use
- Configuration item — an asset tracked for change and configuration management
- Sanitisation — rendering data on media unrecoverable before disposal or reuse
4. Asset inventory
- A maintained inventory of hardware, software, cloud resources, and data stores
- Automated discovery used to keep the inventory current and detect unauthorised assets
- Each asset has an identified owner and a classification
- Cloud and ephemeral resources are tagged for ownership, environment, and data sensitivity
5. Ownership and acceptable use
Every asset has a named owner responsible for its classification, protection, and appropriate use. Acceptable use of assets is governed by the Acceptable Use Policy, and handling is governed by the classification assigned under the Data Classification Policy.
6. Lifecycle management
- Assets are acquired through approved channels and hardened before use
- Assets are maintained, patched, and monitored while in service
- Assets are tracked through reassignment, and access is updated accordingly
- Assets are securely decommissioned at end of life
7. Secure disposal and media sanitisation
- Media is sanitised using approved methods before disposal or reuse
- Cryptographic erasure is used where data was encrypted, and physical destruction where required
- Disposal of assets holding sensitive data is recorded with evidence retained
- Third-party disposal vendors are assessed and provide certificates of destruction
8. Framework alignment
- ISO/IEC 27001:2022 Annex A controls 5.9 (inventory of information and other associated assets), 5.10 (acceptable use), 5.11 (return of assets), and 7.14 (secure disposal or reuse of equipment)
- NIST SP 800-53 Rev. 5 control family CM (Configuration Management) and MP (Media Protection)
- SOC 2 Trust Services Criteria CC6.1 and CC6.5
9. Roles, exceptions, and review
Asset owners are accountable for their assets; IT maintains the inventory under the CISO. Exceptions require documented CISO approval with compensating controls and an expiry date. This policy is reviewed at least annually.
Related frameworks
For contractual attestations or audit packs, contact [email protected].