Skip to main content

operationsVersion 1SOC2ISO27001NIST800-171

Asset Management Policy

How information assets are inventoried, owned, classified, and lifecycled.

Download PDFSHA-256 0d7cae89c245c747…

Asset Management Policy

1. Purpose

Establishes how Rex Black inventories, classifies, and governs its information assets, hardware, software, cloud resources, data stores, and accounts, so that every asset has a named owner and a known lifecycle.

2. Scope

All assets that process, store, or transmit Rex Black or client data, including:

  • Employee devices (Rex Black-issued and BYOD).
  • AWS accounts, IAM roles, and cloud resources.
  • SaaS accounts (Google Workspace, GitHub, Stripe, etc.).
  • DynamoDB tables, S3 buckets, SSM parameters, KMS keys.
  • Source code repositories and build artifacts.

3. Policy statements

3.1 Inventory

  1. An authoritative inventory of assets is maintained in the Rex Black Admin under /admin/compliance/assets and reviewed quarterly.
  2. Every asset has an owner (named Rex Black person or team), a classification (see 009-data-classification-and-handling-policy.md), and a criticality (low/medium/high/critical).
  3. Hardware assets (laptops) are additionally tracked by serial number, assigned user, and MDM enrollment status.

3.2 Classification

  1. Every asset is classified at creation and re-classified on material change.
  2. Data stored on an asset inherits the highest classification of any data it contains.

3.3 Lifecycle

  1. Acquisition: provisioning follows the approved hardware and software lists maintained by the Security Officer. Exceptions require written approval.
  2. Operation: every asset runs a supported, patched version of its operating system and software. End-of-life components are removed from service within 90 days of vendor EOL.
  3. Decommissioning: before an asset leaves Rex Black control, storage media are wiped per NIST SP 800-88 (cryptographic erase for SEDs, minimum single-pass overwrite otherwise) and the action is logged in the asset inventory.

3.4 Cloud resources

  1. Every AWS resource is tagged with Owner, Environment, Classification, and CostCenter. Untagged resources are flagged weekly and removed if unclaimed within 14 days.
  2. Stateful resources (DynamoDB, S3, Secrets Manager, KMS) cannot be deleted without Security Officer approval, enforced by AWS SCP (forceDestroy: false on IaC-managed buckets).

3.5 Recovery from loss or theft

Lost or stolen devices trigger the Incident Response Plan (012-incident-response-plan.md). MDM remote-wipe is initiated immediately; all credentials on the device are rotated; the incident is recorded.

4. Roles & responsibilities

Role Responsibility
Security Officer Owns the asset inventory, quarterly review.
Asset owner Keeps their asset's metadata current.
All personnel Report lost/stolen assets immediately to security@.

5. Enforcement & exceptions

Untagged or unowned assets are reclaimed. Exceptions require Security Officer approval with a 30-day time-box.

6. References

  • 009-data-classification-and-handling-policy.md
  • 012-incident-response-plan.md
  • 025-endpoint-security-policy.md

7. Revision history

Version Date Author Approver Change
1.0 2026-04-17 S.O. CEO Initial policy

Approval

This policy has been reviewed and is hereby approved for the named version and effective date above.

Approved by Myles Bai
Title Chief Executive Officer, Rex Black LLC
Email myles@rexblack.com
Approval date 2026-04-17
Effective date 2026-04-17
Next review due 2027-04-17

Digital signature of record: the CEO's electronic approval is captured in the platform audit log (event kind admin.policy.approved) with hash-chained integrity under the M-C1 control. The hash-chained audit log entry for this document is the canonical signature of record; this printed block exists for print/review convenience.

← Back to the trust center