operationsVersion 1SOC2ISO27001NIST800-171
Asset Management Policy
How information assets are inventoried, owned, classified, and lifecycled.
Asset Management Policy
1. Purpose
Establishes how Rex Black inventories, classifies, and governs its information assets, hardware, software, cloud resources, data stores, and accounts, so that every asset has a named owner and a known lifecycle.
2. Scope
All assets that process, store, or transmit Rex Black or client data, including:
- Employee devices (Rex Black-issued and BYOD).
- AWS accounts, IAM roles, and cloud resources.
- SaaS accounts (Google Workspace, GitHub, Stripe, etc.).
- DynamoDB tables, S3 buckets, SSM parameters, KMS keys.
- Source code repositories and build artifacts.
3. Policy statements
3.1 Inventory
- An authoritative inventory of assets is maintained in the Rex Black
Admin under
/admin/compliance/assetsand reviewed quarterly. - Every asset has an
owner(named Rex Black person or team), aclassification(see009-data-classification-and-handling-policy.md), and acriticality(low/medium/high/critical). - Hardware assets (laptops) are additionally tracked by serial number, assigned user, and MDM enrollment status.
3.2 Classification
- Every asset is classified at creation and re-classified on material change.
- Data stored on an asset inherits the highest classification of any data it contains.
3.3 Lifecycle
- Acquisition: provisioning follows the approved hardware and software lists maintained by the Security Officer. Exceptions require written approval.
- Operation: every asset runs a supported, patched version of its operating system and software. End-of-life components are removed from service within 90 days of vendor EOL.
- Decommissioning: before an asset leaves Rex Black control, storage media are wiped per NIST SP 800-88 (cryptographic erase for SEDs, minimum single-pass overwrite otherwise) and the action is logged in the asset inventory.
3.4 Cloud resources
- Every AWS resource is tagged with
Owner,Environment,Classification, andCostCenter. Untagged resources are flagged weekly and removed if unclaimed within 14 days. - Stateful resources (DynamoDB, S3, Secrets Manager, KMS) cannot be
deleted without Security Officer approval, enforced by AWS SCP
(
forceDestroy: falseon IaC-managed buckets).
3.5 Recovery from loss or theft
Lost or stolen devices trigger the Incident Response Plan
(012-incident-response-plan.md). MDM remote-wipe is initiated
immediately; all credentials on the device are rotated; the incident
is recorded.
4. Roles & responsibilities
| Role | Responsibility |
|---|---|
| Security Officer | Owns the asset inventory, quarterly review. |
| Asset owner | Keeps their asset's metadata current. |
| All personnel | Report lost/stolen assets immediately to security@. |
5. Enforcement & exceptions
Untagged or unowned assets are reclaimed. Exceptions require Security Officer approval with a 30-day time-box.
6. References
009-data-classification-and-handling-policy.md012-incident-response-plan.md025-endpoint-security-policy.md
7. Revision history
| Version | Date | Author | Approver | Change |
|---|---|---|---|---|
| 1.0 | 2026-04-17 | S.O. | CEO | Initial policy |
Approval
This policy has been reviewed and is hereby approved for the named version and effective date above.
| Approved by | Myles Bai |
| Title | Chief Executive Officer, Rex Black LLC |
| myles@rexblack.com | |
| Approval date | 2026-04-17 |
| Effective date | 2026-04-17 |
| Next review due | 2027-04-17 |
Digital signature of record: the CEO's electronic approval is captured
in the platform audit log (event kind admin.policy.approved) with
hash-chained integrity under the M-C1 control. The hash-chained audit
log entry for this document is the canonical signature of record; this
printed block exists for print/review convenience.