Awdurdod annibynnol y Deyrnas Unedig a sefydlwyd i gynnal hawliau gwybodaeth er budd y cyhoedd, annog cyrff cyhoeddus i fod yn agored a hybu preifatrwydd data i unigolion.

Information asset register

You have an asset register that records assets, systems and applications used for processing or storing personal data across the organisation.

Ways to meet our expectations:

  • Your organisation has an asset register which holds details of all information assets (software and hardware) including:
  • asset owners;
    • asset location;
    • retention periods; and
    • security measures deployed.
  • You review the register periodically to make sure it remains up to date and accurate.
  • You periodically risk-assess assets within the register and you have physical checks to make sure that the hardware asset inventory remains accurate.

Can you answer yes to the following questions?

  • Is the register accurate – could you use it to find equipment around your office?
  • If we selected a sample of software, could you demonstrate that the details in the register are correct?