Asset identification and classification is the step where you find out what information your organisation actually holds, who owns each piece, and how sensitive it is. Everything else in security depends on it. You cannot protect data you have not listed, and you cannot decide how hard to protect it until you know what it is worth.
Most teams underestimate this step. They list servers and laptops, call it an inventory, and move on. Proper asset identification and classification goes further than that. It goes wider: the customer database, the contract folder on someone's desktop, the spreadsheet a manager keeps offline, the supplier portal login, and the person who is the only one who knows how a system works.
Asset identification and classification produces a living register with owners and sensitivity labels attached. That register drives access rules, retention periods, backup priorities, and control choices. This page covers what counts as an asset, how to run identification properly, how to set classification levels that people follow, and how to keep it current. It sits at the start of any information security management system build.
What Counts as an Information Asset
An asset is anything holding or supporting information you would not want lost, changed, or exposed. Five groups cover almost everything.

Information itself. Databases, documents, records, contracts, source code, backups, and archives. This is the actual asset. Everything else exists to hold or move it.
Software. Applications, operating systems, development tools, and cloud services.
Hardware. Servers, laptops, mobile devices, network equipment, storage media, and printers.
Services and infrastructure. Internet connectivity, power, hosting, and communication services.
People and knowledge. Skills and knowledge held by individuals, especially where only one person understands a process or system.
That last group is the most often skipped and frequently the highest exposure. A single administrator holding undocumented knowledge is a real availability risk, and no scanning tool will report it.
How to Run Asset Identification
Identification works best from the business process inward, not from the IT inventory outward. Asking "what information does this process create, use, and store?" finds things an inventory tool never sees.
Start With Processes, Not Systems
Walk through each significant process with the people who run it. Payroll, onboarding, quoting, delivery. At each step, ask what information appears, where it goes, and who touches it. This surfaces shadow assets: local spreadsheets, personal drives, and unapproved cloud folders.
Combine Several Discovery Sources
No single source is complete. Use network and endpoint discovery for technical assets, the software licence list, the supplier and contract register, finance records for what was purchased, and staff interviews for everything else. Where sources disagree, treat the gap as a finding rather than an error to smooth over.
Record the Fields That Matter
Keep entries short or nobody maintains them. A workable record holds the asset name and description, its type, the owner, the custodian who runs it day to day, its location or hosting, the classification level, any linked legal or contractual requirement, and the review date.
The distinction between owner and custodian matters. The owner decides who may access the asset and accepts the risk. The custodian operates it. IT is usually the custodian, rarely the owner. Confusing the two leaves nobody making access decisions.
Try Effivity for Free and see how an asset register connects to the risks and controls that protect each entry.
Setting Classification Levels
Classification assigns a sensitivity level so people know how to handle each asset. Three or four levels work. More than four and staff stop applying them correctly.

A common set: Public for anything freely shareable, Internal for routine business information, Confidential for data that would cause harm if disclosed, and Restricted for the small volume of highly sensitive material such as regulated personal data, financial records, or credentials.
Classify on Impact, Not Feeling
Base the level on what happens if the asset is exposed, altered, or unavailable. Consider financial loss, legal exposure, operational disruption, and reputational damage. Score against confidentiality, integrity, and availability separately, because they rarely match. A public price list has low confidentiality needs but high integrity needs, since a wrong figure causes real damage.
Watch the Over-Classification Trap
When in doubt, people mark everything Confidential. The result is a system where the label carries no meaning and genuinely sensitive material gets the same treatment as a meeting agenda. If more than a third of your assets sit in the top two levels, the criteria need tightening, not the labels.
Define Handling Rules Per Level
A label without handling rules changes nothing. For each level, state how the asset may be stored, shared, transmitted, printed, retained, and disposed of. Staff need to know what the label requires of them, not just what it is called.
Linking Classification to Controls
Classification is only useful when it drives decisions. Higher levels should trigger stronger access control requirements, encryption in transit and at rest, tighter retention and disposal, more frequent backup, and closer monitoring.
Done well, this saves money. Applying maximum controls everywhere is expensive and slows work down. Classification lets you spend where exposure is highest and leave routine information alone.
The register also feeds directly into risk work. Each asset carries its own set of threats and vulnerabilities, and the classification level sets the impact side of the score. Without the register, information security risk management has no anchor.
Keeping the Register Current
An asset register decays fast. Systems get added, staff leave, suppliers change, and projects create data nobody logs.
Set a review cycle, quarterly for most organisations, with owners confirming their own entries rather than a central team guessing. Add trigger-based updates for new systems, new suppliers, office moves, and role changes.
Build asset checks into existing processes rather than creating new ones. Procurement approval adds the asset, and the leaver checklist reassigns ownership. Registers maintained through daily processes stay accurate; registers maintained by annual campaigns do not.
Reclassification deserves its own note. Sensitivity changes over time. Draft financial results are Restricted before publication and Public afterwards. Record when a level should change rather than leaving it fixed forever.
Common Mistakes Worth Avoiding
Listing hardware only. A laptop inventory is not an asset register. The information on the laptop is the asset.
No named owner. Entries owned by a department are owned by nobody. Access decisions then default to IT, who lack the business context to make them.
Classifying without handling rules. Labels alone change no behaviour.
One-off exercise. A register built for certification and left alone is worse than none, because it looks maintained.
Ignoring supplier-held data. Information processed by a third party is still yours, and it belongs in the register with the supplier named. Your vendor management records are the quickest place to find them.
How Software Keeps It Manageable
Spreadsheets hold up to roughly a hundred assets and two maintainers. Past that, versions diverge and reviews stop happening.
A structured platform holds each asset with its owner, classification, and location, links it to the risks and controls covering it, and prompts owners when reviews fall due. Effivity's information security management software does this through its Information Assets module, where classification levels connect to Annex A controls and to the risk register, so raising an asset's level shows immediately which controls and risks are affected.
Auditors during an ISO 27001 audit usually start with the asset register and trace outward from it. Having ownership, classification, and treatment in one linked record turns that from a search into a screen.
Get a Free Personalized Demo to see how your current inventory would map into a working asset register.
Frequently Asked Questions
It is the process of listing every information asset you hold, assigning an owner to each, and labelling it by sensitivity. The labels then decide how each asset is protected.
Information itself, software, hardware, services and infrastructure, and people or knowledge. The last group is the most commonly missed in asset registers.
Three or four works for most organisations, such as Public, Internal, Confidential, and Restricted. More levels lead to inconsistent labelling by staff.
A named business person who decides access and accepts the risk, not a department. IT is usually the custodian who operates the asset, not its owner.
Quarterly suits most organisations, with owners confirming their own entries. Add updates whenever systems, suppliers, offices, or roles change.