Asset Management Policy template (SOC 2)

Requires an accurate inventory of devices, cloud resources, software and data, with a named owner and a managed lifecycle for each.

Policy P05 of 22 · Owner: IT/Operations Lead · 3 criteria in the crosswalk · Apache-2.0

What this policy is for

The Asset Management Policy is one of the 22 governance policies in the Policyseed set. It is owned by the IT/Operations Lead, approved by the executive you name in the intake, and reviewed on the cadence you choose. Like every policy in the set it has nine numbered sections: purpose, scope, roles, policy statements, procedures, exceptions, enforcement, review cadence and a revision history table. Sections 4 and 5 carry the substance; those are the sections the Audit Kit rewrites for your named tools.

SOC 2 criteria this policy addresses

The Policyseed crosswalk maps 3 criteria to this policy. Each row names the section an auditor would read for that criterion; the criterion pages explain what it asks in plain words and list evidence examples.

CriterionWhat it coversWhere in this policy
CC2.1Quality informationSection 4 (Policy Statements)
CC6.5Disposal of physical assetsSection 5 (Procedures)
C1.2Disposing of confidential informationSection 5 (Procedures)

Evidence auditors typically ask for

A policy is tested against artifacts. These are examples from the crosswalk for the criteria above, written for a small SaaS company; the Audit Kit ships the full list as an evidence checklist with an owner per row.

  • Asset inventory export (MDM device list plus cloud resource inventory) with owner and classification columns
  • Log retention configuration screenshot from the logging tool showing retention of at least 12 months for security logs
  • Risk register spreadsheet with last-updated date and Security Owner sign-off
  • MDM remote-wipe confirmation for laptops returned by leavers in the period
  • Asset inventory entries marked disposed with the wipe date and method
  • Certificate of destruction from the recycling or ITAD vendor, where used
  • Customer offboarding or deletion request records with completion dates
  • Database or object storage lifecycle policy screenshot enforcing the retention schedule

Full text: the Asset Management Policy rendered for Northwind Cloud Inc

Below is the complete template as the generator renders it for Northwind Cloud Inc, a fictional 11-50-person remote company running Northwind on AWS, Vercel, GitHub and Okta. Every name, tool and date comes from that sample intake; your answers replace them. Section headings carry anchors so the criterion pages can link straight to the section they cite.

Sample document

Northwind Cloud Inc Asset Management Policy

1. Purpose

Northwind Cloud Inc cannot protect what it does not know it has. This policy requires that every laptop, phone, cloud resource, software subscription and significant dataset used to build and run Northwind is recorded, has a named owner, and is managed from acquisition to disposal. An accurate inventory is what makes access reviews, vulnerability management, offboarding and incident response possible, and it is one of the first things an examiner asks to see.

2. Scope

This policy applies to all personnel of Northwind Cloud Inc and to the following asset classes:

  • Hardware: company-owned laptops, desktops, phones, tablets, security keys, external drives and office network equipment.
  • Cloud resources: every account, project, subscription, virtual machine, container service, function, database, storage bucket, queue, DNS zone and network component in AWS and Vercel.
  • Software and services: operating systems, installed applications, browser extensions, the libraries Northwind depends on, and SaaS subscriptions including Supabase, Stripe, Datadog and Slack.
  • Data assets: the datasets, backups and logs described in the Data Classification and Handling Policy, and the systems that hold them.
  • Personally owned devices approved for work use under the Acceptable Use Policy.

The cloud platforms in scope for the inventory are:

  • AWS
  • Vercel

3. Roles and Responsibilities

  • Executive Management (Priya Natarajan, CEO) approves this policy and funds the equipment, tooling and subscriptions needed to maintain a managed fleet.
  • Security Owner (Dana Whitfield, CTO) owns this policy jointly with the IT/Operations Lead, uses the inventory as the basis for access reviews and vulnerability management, and verifies that reconciliations happen on schedule.
  • Engineering owns the cloud resource inventory for AWS and Vercel, enforces tagging and ownership conventions, decommissions unused resources, and maintains the software bill of materials for Northwind.
  • People Operations triggers device assignment at hire and device return at departure, and confirms returns are complete before contract close-out.
  • All Personnel use only assets recorded in the inventory, take reasonable care of company equipment, report loss, theft or damage immediately to security@northwindcloud.example, and return everything when their engagement ends.

4. Policy Statements

  • 4.1 Northwind Cloud Inc maintains an asset register covering hardware, cloud resources, software and services, and data assets. Every entry records the asset identifier, type, owner, assigned user where applicable, location or hosting platform, classification of the data it holds, and status. Kandji is the authoritative source for endpoint records and the register is reconciled against it.
  • 4.2 Every asset has a named owner accountable for its security, lifecycle and retirement. Ownership passes explicitly when a person changes role or leaves, and assets are not moved, lent, reassigned or removed from an office without the register being updated. Company equipment is never sold, gifted or discarded by individuals.
  • 4.3 Company devices are procured through the IT/Operations Lead, configured to the baseline in the Endpoint and Workstation Security Policy before handover, enrolled in Kandji so that encryption, screen lock, update and inventory policies apply automatically, and recorded in the register with the assigned user on the day they are issued.
  • 4.4 Production, source code and customer data are accessed only from devices in the register that meet the security baseline. Devices not enrolled in Kandji are denied access to those systems.
  • 4.5 Every resource in AWS and Vercel is created through infrastructure-as-code or a documented change and carries tags for owner, environment, service and data classification. Untagged resources are treated as unowned and removed under 5.4. Cloud accounts, projects and subscriptions are themselves recorded in the register with their purpose and administrative owner.
  • 4.6 Engineering maintains a software bill of materials for Northwind listing the languages, frameworks, libraries and container base images in use and their versions, generated automatically from GitHub and GitHub Actions wherever possible, so that vulnerability notices can be matched to what is actually deployed. Open-source components are used within their licence terms, and the IT/Operations Lead keeps licence and subscription records.
  • 4.7 SaaS subscriptions and services are approved under the Acceptable Use Policy before purchase, recorded in the register with their owner, the data classification they hold and their renewal date, and provisioned through Okta where supported. Services paid for on personal cards or expensed without approval are not permitted.
  • 4.8 Storage media, including laptop drives, phones, external drives and decommissioned cloud volumes and snapshots, are sanitised before reuse or disposal by cryptographic erase, full secure wipe or physical destruction under the Data Retention and Disposal Policy. The method and date are recorded, and third-party disposal is accompanied by a certificate of destruction.
  • 4.9 Removable media is not used for company or customer data except with written approval from the Security Owner; approved media is encrypted, recorded in the register and wiped after use.
  • 4.10 Loss, theft or unexplained absence of any asset is reported to security@northwindcloud.example immediately and handled under the Incident Response Policy, including remote wipe through Kandji and credential rotation for endpoints.
  • 4.11 Because Availability is within the scope of the SOC 2 examination, Engineering monitors the capacity and utilisation of production resources in AWS and Vercel, alerts on thresholds that would affect the availability of Northwind, and reviews capacity forecasts at least quarterly.

5. Procedures

  • 5.1 Device issue. The IT/Operations Lead procures the device, records its serial number and model, applies the baseline configuration through Kandji enrolment, assigns it to the user in the register, and obtains the user's signed acknowledgement of receipt. Devices are shipped only to addresses confirmed by People Operations.
  • 5.2 Register updates. Any change to an asset's owner, user, location or status is recorded within two business days. The IT/Operations Lead edits the register for hardware and services; Engineering edits it for cloud resources and the software bill of materials.
  • 5.3 Quarterly reconciliation. Within the first month of each quarter the IT/Operations Lead reconciles the hardware register against the device list in Kandji and the active user list from Okta, and Engineering reconciles the cloud register against a fresh resource export from AWS and Vercel. Discrepancies are investigated and recorded, and the signed-off reconciliation is retained as evidence.
  • 5.4 Unowned cloud resources. Engineering runs a monthly report of resources in AWS and Vercel lacking the required tags, attempts to identify the owner from deployment history in GitHub and GitHub Actions, and after ten business days snapshots any still-unowned resource that holds data, removes it, and records the removal in a ticket.
  • 5.5 SaaS review. Each quarter the IT/Operations Lead compares the services register against the application catalogue in Okta and expense and card records, adds any service in use without an entry, refers it to the Security Owner for approval or termination, and flags renewals due next quarter so that unused subscriptions are cancelled rather than auto-renewed.
  • 5.6 Software bill of materials. GitHub Actions generates the dependency manifest for Northwind on each production build. Engineering stores the latest manifest with the release record, and the Vulnerability and Patch Management Policy uses it to match advisories to deployed components.
  • 5.7 Return and disposal. People Operations includes device return in the offboarding checklist and provides a prepaid shipping label for remote staff. The IT/Operations Lead confirms receipt, records the date, wipes the device through Kandji, and marks it available or retired. Unreturned devices are escalated to the Security Owner after five business days and treated as lost. End-of-life devices are wiped as in 4.8 and recycled through a vendor that provides a certificate of destruction; cloud volumes, snapshots and buckets are deleted through a reviewed change.
  • 5.8 Lost or stolen assets. The user reports to security@northwindcloud.example immediately. The Security Owner initiates a remote lock and wipe through Kandji, revokes the user's sessions, rotates any credentials that were on the device, marks the asset lost in the register, and records the event under the Incident Response Policy. Police reports are filed where theft is suspected.

6. Exceptions

Exceptions, such as a temporary personally owned device while a company device is in transit, or a research environment that cannot be tagged conventionally, are approved in writing by the Security Owner, recorded in the exception register with compensating controls and an expiry date no later than twelve months out, and reviewed at each annual review. No exception permits access to customer data from a device not recorded in the register.

7. Enforcement

Assets discovered outside the register are brought under management or removed, and the circumstances are investigated. Personnel who use unrecorded devices for company data, dispose of equipment or media without sanitisation, or fail to return assets at departure are subject to the disciplinary process in the Acceptable Use Policy and may be held responsible for unreturned equipment. Engineering leads are accountable for untagged or unowned cloud resources in their areas.

8. Review Cadence

The IT/Operations Lead and the Security Owner review this policy at the annual policy review, after any incident involving a lost, stolen or unknown asset, and whenever Northwind Cloud Inc adopts a new cloud platform, device type or management tool. Revisions are approved by Priya Natarajan, CEO and recorded in section 9.

9. Revision History

VersionDateDescriptionApproved by
1.02026-09-02Initial releasePriya Natarajan, CEO

Frequently asked questions

Who should own the Asset Management Policy?
In the Policyseed template the IT/Operations Lead owns the Asset Management Policy: they maintain the text, run the procedures in section 5 and hold the evidence those procedures produce. The approver you name in the intake signs it, and section 8 sets the review cadence you choose (annual, semi-annual or quarterly).
Which SOC 2 criteria does the Asset Management Policy address?
3 criteria in the Policyseed crosswalk: CC2.1 (Quality information), CC6.5 (Disposal of physical assets) and C1.2 (Disposing of confidential information). Each mapping points at a numbered section of this policy, and the Audit Kit exports the same mapping as an Excel crosswalk with an evidence checklist.
Is the Asset Management Policy template free to use?
Yes. The template is Apache-2.0 licensed and the generator renders it in your browser with your company, stack and owner names filled in; nothing is stored server-side. The Audit Kit ($39 one-time) rewrites sections 4 and 5 for your named tools with Claude and adds Word documents, the crosswalk spreadsheet, acknowledgment forms and a review calendar. Refunds are available within 14 days on request. Policyseed provides governance policy templates, not legal advice; the CPA firm performs the examination.

Policyseed provides governance policy templates and AI tailoring. It is not legal advice and not a compliance guarantee. Management adopts the policies; the CPA firm performs the SOC 2 examination.