IT - Asset
Classification and
Control Policy
REVISION HISTORY
Version Author Date of Sections Affected
Number Revision
1 XXXX All
AUTHORIZATION
Approved by Date
Executive Management:
Reviewed By
Process Owner:
<Other Reviewers as necessary>
Table of Contents:
1 SCOPE........................................................................................................................1
2 POLICY STATEMENT............................................................................................1
2.1 INFORMATION SYSTEMS ASSET INVENTORY..............................1
2.2 ASSET CLASSIFICATION ROLES AND RESPONSIBILITIES.......1
2.3 ASSET CLASSIFICATION CRITERIA.................................................1
2.4 CONSISTENT CLASSIFICATION........................................................1
2.5 ACCEPTABLE USE OF ASSETS...........................................................2
2.6 E-WASTE MANAGEMENT....................................................................2
3 COMPLIANCE WITH THE POLICY...................................................................2
4 VIOLATION OF THE POLICY..............................................................................2
4.1 CONSEQUENCES OF VIOLATION OF THE POLICY..............................2
5 CONTACT ROLE FOR CLARIFICATIONS REGARDING THE POLICY....2
Scope
This policy applies to all users of information assets including COMPANY
employees, employees of temporary employment agencies, vendors, business
partners, and contractor personnel and functional units regardless of geographic
location.
Policy Statement
The purpose of this policy is to ensure that the organizations information assets are
accorded protection commensurate to their business value.
1.1 Information Systems Asset Inventory
Companys information assets must be listed in an Information Asset Inventory.
Each Asset must be clearly identified individually and (if appropriate)
collectively in combination with other Assets to form an identifiable
Information System.
The Information Asset Inventory must contain the following information as a
minimum:
o Asset identification
o Asset description
o Asset location
o Asset Owner/Custodian
o Asset classification
o Validity of the classification
1.2 Asset Classification Roles and Responsibilities
Each Information Asset must have a designated Owner. The Information
Owner is the person who has either created the information himself, or is in-
charge of the team producing the information.
Each Information Asset should also have a nominated Custodian (who may be
separate from the Owner of the Information Asset).
The Owner of the Information Asset is responsible for periodically reviewing
the access control polices and classification set on the asset.
1.3 Asset Classification Criteria
All Information Systems / Assets must be classified according to this policy.
All information should be handled according to the classification levels to
ensure security of the information resource.
Risk classification will enable COMPANY to focus asset protection
mechanisms on those Assets that are most susceptible to specific risks.
Consistent Classification
The information can be classified, on sensitivity, into the following categories:
o Public
o Restricted
o Confidential
o Highly Confidential
1
Information which is classified as Confidential must be labelled accordingly,
from the time it is created until the time it is destroyed or re-labelled. Such
markings must appear on all media of the information (hard copies, floppy
disks, CD-ROMs, etc).
Information can be classified, on criticality, into the following categories:
o Critical
o Non Critical
Critical information are that are mandatory for the regular performance of an
information system.
1.4 Acceptable use of Assets
COMPANY must ensure that there are rules defined for the acceptable use of
all the information assets of the organization.
COMPANY must ensure that the employees, contractors and third parties
follow the policy for the acceptable use of all the information assets.
1.5 E-Waste Management
The company considers computer and related hardware items which either
dont meet the business requirements or no longer useful as E-Wastes. These e-
wastes are disposed in the following way:
o Donating Computers to educational institutions which dont meet the
business requirement but still can be used for educational purpose.
o Hand over / selling to Govt. authorized e-waste recycling agents that are no
longer useful.
o SCRAP
Compliance with the Policy
Compliance with the Asset Classification and Control Policy is mandatory.
COMPANY Department Heads shall ensure continuous compliance monitoring within
their Department. Compliance with the Asset Classification and Control Policy shall
be a matter for periodic review by Head IT.
Violation of the Policy
Any employee who discovers a breach of this policy shall notify the Head IT.
Violations of the policies of COMPANY shall result in disciplinary action by
management.
2 Consequences of violation of the Policy
Disciplinary action shall be consistent with the severity of the incident, as
determined by an investigation, and may include, but not be limited to:
Loss of access privileges to information assets, and
Other actions as deemed appropriate by Management, Human Resources, and
the Legal Department.