Information Asset, Data and Record
In ISO/IEC 27001 and the fundamental principles of an Information Security Management System (ISMS), it is important to distinguish between information assets, data and records, because each shapes how auditors assess scope, risk and evidence. INFORMATION ASSET: An asset is anything that has value … In ISO/IEC 27001 and the fundamental principles of an Information Security Management System (ISMS), it is important to distinguish between information assets, data and records, because each shapes how auditors assess scope, risk and evidence. INFORMATION ASSET: An asset is anything that has value to the organization. An information asset is knowledge or data that has value to the organization and therefore needs protection. Examples include customer databases, intellectual property, contracts, strategic plans and employee files. Assets associated with information, such as hardware, software, networks, people and facilities, are also considered because they store, process or transmit information. ISO/IEC 27001 Annex A control 5.9 requires an inventory of information and other associated assets, including owners. Control 5.12 requires information to be classified according to its confidentiality, integrity and availability requirements. Information assets are central to risk assessment, since risks are identified by considering threats and vulnerabilities affecting them. DATA: ISO/IEC 27000 defines data as a collection of values assigned to base measures, derived measures and/or indicators. More generally, data are raw facts, figures or symbols, such as numbers, text, images or signals, that have little meaning until they are processed, organized or interpreted. Once data are given context and meaning, they become information. Data may be structured, such as database fields, or unstructured, such as emails. Protecting data throughout its lifecycle of creation, storage, use, transmission and deletion is a core ISMS concern, reflected in controls such as 8.10 information deletion, 8.11 data masking and 8.12 data leakage prevention. RECORD: A record is a document stating results achieved or providing evidence of activities performed. Records are a form of documented information that is retained, not revised, to show what happened. Examples include audit reports, training logs, incident reports, access reviews and management review minutes. Control 5.33 requires records to be protected from loss, destruction, falsification and unauthorized access. For a Lead Auditor, records are vital objective evidence for verifying conformity with ISO/IEC 27001 requirements.
Information Asset, Data and Record: ISMS Fundamental Concepts for the ISO 27001 Lead Auditor
Introduction
Every Information Security Management System (ISMS) exists for one purpose: to protect information. Before an organization can protect information, and before an auditor can judge whether it is protected, both must agree on what is being protected. The concepts of information asset, data and record provide that shared vocabulary. They appear throughout ISO/IEC 27000, ISO/IEC 27001 and ISO/IEC 27002, and they are tested heavily in Lead Auditor exams because they underpin scoping, risk assessment, asset inventories, classification and audit evidence.
1. Why These Concepts Are Important
Scope and risk assessment depend on them. Clause 6.1.2 of ISO/IEC 27001 requires risks to the confidentiality, integrity and availability of information within the ISMS scope to be identified. You cannot identify those risks without first knowing which information, and which associated assets, are in scope.
Annex A controls are built around them. Many controls refer directly to assets, information or records, including:
- 5.9 Inventory of information and other associated assets
- 5.10 Acceptable use of information and other associated assets
- 5.11 Return of assets
- 5.12 Classification of information
- 5.13 Labelling of information
- 5.33 Protection of records
- 5.34 Privacy and protection of PII
- 8.10 Information deletion
- 8.11 Data masking
- 8.12 Data leakage prevention
Records are the auditor's evidence. Auditors rely on records to verify that activities were actually performed. If you cannot tell a record from a document, you cannot properly assess Clause 7.5 (Documented information) or gather objective evidence.
Accountability. Assets must have owners. Ownership drives classification, access decisions and risk treatment. Without a clear concept of an asset, accountability breaks down.
2. What They Are: Key Definitions
Data
Data are raw facts, figures, symbols or values with no context or interpretation attached. Examples are a string of numbers, a sensor reading or a database field. In measurement terms, ISO/IEC 27000 describes data as a collection of values assigned to base measures, derived measures and/or indicators. In general use, data is the raw material from which information is produced.
Information
Information is data that has been processed, organized or given context so that it has meaning. For example, 37.5 is data. Patient X's temperature is 37.5 degrees Celsius is information. Information can exist in many forms:
- Printed or written on paper
- Stored electronically
- Transmitted by post or electronic means
- Shown on film or displayed on screens
- Spoken in conversation
- Held as knowledge in people's minds
Whatever form it takes, information should be appropriately protected. This is a classic exam point.
Asset
An asset is anything that has value to the organization. ISO/IEC 27002:2022 distinguishes two types:
- Primary assets: information itself, and business processes and activities.
- Supporting (associated) assets: hardware, software, networks, people, sites and facilities, organizational structures, and services such as cloud or outsourced services, on which the primary assets depend.
Information Asset
An information asset is information that has value to the organization and therefore needs protection. Typical examples include customer databases, contracts, intellectual property, financial reports, HR files, system configurations, policies and procedures, and backup data. ISO/IEC 27001:2022 uses the phrase information and other associated assets to cover both the information and the things that store, process or transmit it.
Record
A record is information created, received and maintained as evidence and as an asset by an organization or person, in pursuit of legal obligations or in the transaction of business (ISO/IEC 27002, aligned with ISO 15489-1). Put simply, a record states results achieved or provides evidence of activities performed. Examples include audit reports, access logs, training attendance sheets, incident reports, management review minutes, risk assessment results and signed contracts.
Documented Information
ISO/IEC 27000 defines documented information as information required to be controlled and maintained by an organization and the medium on which it is contained. It covers two types:
- Documented information to be maintained. These were formerly called documents, such as policies, procedures and the Statement of Applicability. They describe what should be done and can be revised.
- Documented information to be retained. These were formerly called records. They show what was done and should not be altered.
3. How It Works in Practice
The Data, Information, Knowledge Hierarchy
Data is collected. It is processed and contextualized into information. Information is interpreted and applied as knowledge, which supports decisions. Security controls must protect every stage. For example, raw data may be masked (8.11), information may be classified (5.12), and knowledge held by staff may be protected through NDAs and awareness (6.6, 6.3).
The Asset Management Lifecycle
1. Identify: build and maintain an inventory of information and associated assets (5.9).
2. Assign ownership: every asset has an owner who is accountable for its protection.
3. Classify: classify according to confidentiality, integrity, availability and legal requirements (5.12).
4. Label and handle: apply labels and handling procedures (5.13).
5. Use acceptably: define rules for acceptable use (5.10).
6. Transfer securely: protect information in transit (5.14).
7. Return or dispose: recover assets on termination (5.11) and delete information securely (8.10, 7.14).
The Information Lifecycle
Information is created or received, then stored, processed, transmitted and shared, archived, and finally destroyed. Risks change at each stage, and controls should follow the information throughout its life.
Records Management
Control 5.33 requires records to be protected from loss, destruction, falsification, unauthorized access and unauthorized release. In practice this means:
- Defining retention periods based on legal, regulatory, contractual and business needs
- Ensuring integrity, so that records cannot be altered without detection
- Ensuring authenticity, reliability and usability over time, including readability of storage media and formats
- Controlling storage, retrieval and disposal
Clause 7.5.3 also requires control of distribution, access, retrieval, use, storage, preservation, legibility, change control, retention and disposition.
How the Auditor Uses These Concepts
- Checks that the asset inventory is complete, accurate, current and consistent with the scope.
- Verifies that owners are assigned and aware of their responsibilities.
- Samples assets to confirm that classification and labelling match policy.
- Uses records as objective evidence that controls operate effectively. A procedure shows intent. A record proves performance.
- Checks that records are protected, retained for the defined period and disposed of properly.
4. Worked Examples
Example 1: A server log file shows failed login attempts. The individual log entries are data. The log as a whole, interpreted, is information. Because it serves as evidence of activity, it is also a record. It must be protected from tampering (8.15 Logging, 5.33).
Example 2: The access control policy is documented information to be maintained, and it can be revised. The completed quarterly access review sign-off is documented information to be retained. It is a record and must not be changed after the fact.
Example 3: A senior engineer holds undocumented knowledge of a critical system. That knowledge is information, and the engineer is a supporting asset (people). The risk of losing it should be treated, for example through documentation, succession planning and confidentiality agreements.
5. Common Misconceptions
- Misconception: information assets are only electronic. Reality: paper, spoken and tacit knowledge all count.
- Misconception: hardware is the asset that matters most. Reality: the information is the primary asset. Hardware is supporting.
- Misconception: records can be updated when errors are found. Reality: records should be protected against modification. Corrections should be traceable, never silent overwrites.
- Misconception: data and information are synonyms. Reality: information is data with meaning and context. Exams may test this distinction.
- Misconception: an asset owner legally owns the asset. Reality: the owner is the individual or entity with management responsibility and accountability. It is not about property rights.
Exam Tips: Answering Questions on Information Asset, Data and Record
1. Anchor on the definition of asset. If a question asks what qualifies as an asset, remember: anything that has value to the organization. People, reputation, processes and services can all be assets.
2. Distinguish primary from supporting assets. Information and business processes are primary. Hardware, software, networks, people, sites and services are supporting. Questions often ask which asset is the true object of protection. The answer is the information.
3. Remember that information exists in all forms. Choose answers that extend protection to paper, verbal and tacit knowledge, not just digital files.
4. Records are evidence and are not revised. When a scenario describes someone editing a completed record, such as changing a training log after an audit, treat it as a potential nonconformity against 7.5.3 and/or 5.33. Documents such as policies and procedures are revised under change control.
5. Map scenarios to controls.
- Missing or outdated inventory: 5.9
- Unclear owner: 5.9
- No classification scheme: 5.12
- Unlabelled media: 5.13
- Records lost or altered: 5.33
- Data not deleted after its retention period: 8.10
- Leaving employee kept a laptop: 5.11
6. Think like an auditor about evidence. In case-study questions, ask which record would prove the control is working. Examples are the asset register, classification records, access review records, disposal certificates and retention schedules. Interviews and observations support findings, but records provide the strongest objective evidence.
7. Watch the wording. Phrases such as to be maintained versus to be retained, data versus information, and owner versus custodian or user are deliberate distractors. Read each option carefully.
8. Link assets to risk. Questions on risk assessment usually expect you to identify assets, their owners and their CIA requirements. A risk exists when a threat exploits a vulnerability of an asset and affects confidentiality, integrity or availability.
9. Write nonconformities clearly. In essay or case-study answers, state the requirement (clause or control), the evidence observed (for example, 3 of 10 sampled laptops were not in the inventory), and why it is a nonconformity. Do not prescribe solutions. Auditors report findings. They do not design fixes.
10. Use precise ISO language. Say information and other associated assets, documented information and objective evidence. Precise terminology signals competence to examiners.
Quick Revision Summary
- Data: raw facts without context.
- Information: data with meaning. It is the primary asset to be protected in every form.
- Asset: anything of value. Assets are primary (information, processes) or supporting (hardware, software, people, sites, services).
- Information asset: valuable information that requires protection, inventoried, owned and classified.
- Record: evidence of results achieved or activities performed. It is retained, protected and not altered.
- Key controls: 5.9 to 5.14, 5.33, 5.34, 7.14, 8.10 to 8.12, and Clause 7.5.
Master these distinctions and you will be able to scope an ISMS, assess risks, evaluate asset management and recognize valid audit evidence. These are core competencies for an ISO/IEC 27001 Lead Auditor.
Unlock Premium Access
ISO/IEC 27001 Lead Auditor
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 3041 Superior-grade ISO/IEC 27001 Lead Auditor practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- ISO 27001 LA: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!