Asset Management Policy
Governs how Finaisse identifies, owns, and handles its information and system assets. Subordinate to the Information Security Policy.
| Policy owner | Security & Infrastructure Owner (Sekhar) |
| Applies to | Information assets, systems, services, and endpoints |
| Effective | 2026-08-27 (v0.1 draft) |
| Review cadence | Annual + on major architecture change |
| Classification | Internal-confidential |
| ISO | A.5.9–5.11 · SOC 2 CC6.1 |
1. Purpose
Ensure information assets are identified, have an accountable owner, and are handled and retired securely.
2. Asset inventory
🎯 Target — maintain an inventory of information assets and the services/data stores that process them, with an owner per asset. Today the platform's services are enumerated in Architecture and the service registry; this policy formalises ownership and inventory as the team grows.
3. Ownership & acceptable handling
- Every significant asset has an owner accountable for its classification and protection.
- Assets are handled per the Data Classification & Retention Policy; Restricted-data assets receive the strongest controls.
- Use of assets follows the Acceptable Use Policy.
4. Return & secure disposal
- On personnel offboarding, company assets and access are returned/revoked (HR Security & Awareness Policy).
- Data is disposed of per its retention schedule using secure deletion (Data Classification & Retention Policy).
5. Review
Reviewed annually and on major architecture change.
Revision history
| Version | Date | Author | Change |
|---|---|---|---|
| 0.1 | 2026-08-27 | Security & Infrastructure Owner | Initial draft |