Search in ISMS Guides

Google
 

Monday, July 23, 2007

Information security policies

From Wikipedia, the free encyclopedia

Information security policies are a special type of documented business rule for protecting information and the systems which store and process the information. Information security policies are usually documented in one or more information security policy documents. Within an organization, these written policy documents provide a high-level description of the various controls the organization will use to protect information.

Written information security policy documents are also a formal declaration of management's intent to protect information, and are required for compliance with various security and privacy regulations. Organizations that require audits of their internal systems for compliance with various regulations will often use information security policies as the reference for the audit.


Developing Information Security Policies

Proper development of information security policies requires careful planning. While information security policies are usually developed by one group, such as the information security department, policy development requires the input of all major business units within the organization. The policy development process has five major steps:

1. Assemble the policy development team - The team can include both primary and secondary members. Primary members will be the persons who write the policies, and should include at least one information security specialist and ideally a technical writer to help produce documents that are easy to read and understand. Secondary team members will help build requirements, review and approve documents. Ideal secondary team members include representatives from legal, human resources (HR), information technology (IT) and various business units.
2. Gather Requirements - Decide which topics will be covered within your policy documents. Use the results of your organizational risk assessment to determine which parts of the organization are at greatest risk.
3. Write Draft Policy Documents - Create draft policy documents for each major policy topic you will address. Be sure to use consistent style and formatting between documents.
4. Review and approve draft policy documents - Send each document for review to members of the review team. Ideally, team members should commit to reviewing each document within a definted time period.
5. Formally publish written documents - Once each document has been formally approved, they can be published to the organization. Official publication of these documents should be sanctioned with the support of a high-level executive within the organization, preferable the CEO or CIO.


Resources

The following resources will help in development and deployment of information security policies:
The SANS Security Policy Project provides a set of sample information security policy documents.
Information Security Policies the complete RUsecure security policy definition document.
Information Security Roles and Responsibilities Made Easy by Charles Cresson Wood provides advice for building a proper information security organization, including sample security-related job descriptions.

Security policy

From Wikipedia, the free encyclopedia

A security policy is a definition of what it means to be secure for a system, organization or other entity. For an organization, it addresses the constraints on behavior of its members as well as constraints imposed on adversaries by mechanisms such as doors, locks, keys and walls. For systems, the security policy addresses constraints on functions and flow among them, constraints on access by external systems and adversaries including programs and access to data by people.

Because the security policy is a high level definition of secure behavior, it is meaningless to claim an entity is "secure" without knowing what "secure" means. It is also foolish to make any significant effort to address security without tracing the effort to a security policy.

Significance

If it is important to be secure, then it is important to be sure all of the security policy is enforced by mechanisms that are strong enough. There are organized methodologies and risk assessment strategies to assure completeness of security policies and assure that they are completely enforced. In complex systems, such as information systems, policies can be decomposed into sub-policies to facilitate the allocation of security mechanisms to enforce sub-policies. However, this practice has pitfalls. It is too easy to simply go directly to the sub-policies, which are essentially the rules of operation and dispense with the top level policy. That gives the false sense that the rules of operation address some overall definition of security when they do not. Because it is so difficult to think clearly with completeness about security, rules of operation stated as "sub-policies" with no "super-policy" usually turn out to be rambling ad-hoc rules that fail to enforce anything with completeness. Consequently, a top level security policy is essential to any serious security scheme and sub-policies and rules of operation are meaningless

ISO/IEC 27002

From Wikipedia, the free encyclopedia

ISO/IEC 27002 is an information security standard published by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC) as ISO/IEC 17799:2005 and subsequently renumbered ISO/IEC 27002:2005 in July 2007, bringing it into line with the other ISO/IEC 27000-series standards. It is entitled Information technology - Security techniques - Code of practice for information security management. The current standard is a revision of the version first published by ISO/IEC in 2000, which was a word-for-word copy of the British Standard (BS) 7799-1:1999.

ISO/IEC 27002 provides best practice recommendations on information security management for use by those who are responsible for initiating, implementing or maintaining Information Security Management Systems (ISMS). Information security is defined within the standard in the context of the C-I-A triad:

the preservation of confidentiality (ensuring that information is accessible only to those authorised to have access), integrity (safeguarding the accuracy and completeness of information and processing methods) and availability (ensuring that authorised users have access to information and associated assets when required).

After the introductory sections, the standard contains the following twelve main sections:

* 1: Risk assessment and treatment - analysis of the organization's information security risks
* 2: Security policy - management direction
* 3: Organization of information security - governance of information security
* 4: Asset management - inventory and classification of information assets
* 5: Human resources security - security aspects for employees joining, moving and leaving an organization
* 6: Physical and environmental security - protection of the computer facilities
* 7: Communications and operations management - management of technical security controls in systems and networks
* 8: Access control - restriction of access rights to networks, systems, applications, functions and data
* 9: Information systems acquisition, development and maintenance - building security into applications
* 10: Information security incident management - anticipating and responding appropriately to information security breaches
* 11: Business continuity management - protecting, maintaining and recovering business-critical processes and systems
* 12: Compliance - ensuring conformance with information security policies, standards, laws and regulations

Within each section, information security controls and their objectives are specified and outlined. The information security controls are generally regarded as best practice means of achieving those objectives. For each of the controls, implementation guidance is provided. Specific controls are not mandated since:

1. Each organization is expected to undertake a structured information security risk assessment process to determine its specific requirements before selecting controls that are appropriate to its particular circumstances. (The introduction section outlines a risk assessment process although there are more specific standards covering this area such as ISO Technical Report TR 13335 GMITS Part 3 - Guidelines for the management of IT security - Security Techniques, and BS 7799 Part 3.)
2. It is practically impossible to list all conceivable controls in a general purpose standard. (Industry-specific implementation guidance for ISO/IEC 27001 and 27002 are anticipated to give advice tailored to organizations in the telecomms, financial services, healthcare, lotteries and other industries).

ISO/IEC 27002 has directly equivalent national standards in countries such as Australia and New Zealand (AS/NZS ISO/IEC 17799:2006), the Netherlands (NEN-ISO/IEC 17799:2002 nl, 2005 version in translation), Denmark (DS484:2005), Sweden (SS 627799), Japan (JIS Q 27002), UNE 71501 (Spain), the United Kingdom (BS ISO/IEC 17799:2005) and Uruguay (UNIT/ISO 17799:2005). Translation and local publication often results in several months' delay after the main ISO/IEC standard is revised and released but the national standard bodies go to great lengths to ensure that the translated content accurately and completely reflects ISO/IEC 27002.

Saturday, July 21, 2007

Information Lifecycle Management

From Wikipedia, the free encyclopedia

Information Lifecycle Management refers to a wide-ranging set of strategies for administering storage systems on computing devices. Specifically, four categories of storage strategies may be considered under the auspices of ILM

Policy

ILM Policy consists of the overarching storage and information policies that drive management processes. Policies are dictated by business goals and drivers. Therefore, policies generally tie into a framework of overall IT governance and management; change control processes; requirements for system availability and recovery times; and service level agreements (SLA)

Management

Information Management consists of the practices that facilitate operational storage management. These include the principles that guide ILM; the storage management tools and practices; database management practices; system performance and monitoring; system configuration; capacity planning; and business controls. Business controls generally include chargeback, costing and P&L-related metrics..

Operational

Operational aspects of ILM include backup and data protection; disaster recovery, restore, and restart; archiving and long-term retention; data replication; and day-to-day processes and procedures necessary to manage a storage architecture.

Infrastructure

Infrastructure facets of ILM include the logical and physical architectures; the applications dependent upon the storage platforms; security of storage; and data center constraints. Within the application realm, the relationship between applications and the production, test, and development requirements are generally most relevant for ILM.

Definition

In the year 2004, attempts have been made by the Information Technology and Information Storage industries (SNIA association) to assign a new definition to Information Lifecycle Management (ILM).

* Information Lifecycle Management comprises the policies, processes, practices, and tools used to align the business value of information with the most appropriate and cost effective IT infrastructure from the time information is conceived through its final disposition. Information is aligned with business processes through management policies and service levels associated with applications, metadata, information, and data.

This is based on the desire to move information to less expensive means of storage and management based on its usage rather than evaluating its value to an organization and managing it accordingly. While there is a need to find a means to more effectively manage the vast quantities of information being generated electronically by organizations, the proposed IT practice is NOT by any means ILM, as it is classically known. ILM is as well part of the overall approach of ECM Enterprise content management.

Information Lifecycle Management (sometimes abbreviated ILM) is the practice of applying certain policies to the effective management of information throughout its useful life. This practice has been used by Records and Information Management (RIM) Professionals for over three decades and had its basis in the management of information in paper or other physical forms (microfilm, negatives, photographs, audio or video recordings and other assets).

ILM includes every phase of a "record" from its beginning to its end. And while it is generally applied to information that rises to the classic definition of a record (Records management), it applies to any and all informational assets. During its existence, information can become a record by being identified as documenting a business transaction or as satisfying a business need. And while most records are thought of as having a relationship to business, not all do. Much recorded information may not serve a business need of any sort, but still serves to document a critical point in history or to document an event. Examples of these are birth, death, medical/health and educational records.

Functionality

For the purposes of business records, there are five phases identified as being part of the lifecycle continuum. These are:

* Creation and Receipt
* Distribution
* Use
* Maintenance
* Disposition

Creation and Receipt deals with records from their point of origination. This could include their creation by a member of an organization at varying levels or receipt of information from an external source. It includes correspondence, forms, reports, drawings, computer input/output, or other sources.

Distribution is the process of managing the information once it has been created or received. This includes both internal and external distribution, as information that leaves an organization becomes a record of a transaction with others.

Use takes place after information is distributed internally, and can generate business decisions, document further actions, or serve other purposes.

Maintenance is the management of information. This can include processes such as filing, retrieval and transfers. While the connotation of 'filing' presumes the placing of information in a prescribed container and leaving it there, there is much more involved. Filing is actually the process of arranging information in a predetermined sequence and creating a system to manage it for its useful existence within an organization. Failure to establish a sound method for filing information makes its retrieval and use nearly impossible. Transferring information refers to the process of responding to requests, retrieval from files and providing access to users authorized by the organization to have access to the information. While removed from the files, the information is tracked by the use of various processes to ensure it is returned and/or available to others who may need access to it.

Disposition is the practice of handling information that is less frequently accessed or has met its assigned retention periods. Less frequently accessed records may be considered for relocation to an 'inactive records facility' until they have met their assigned retention period. Retention periods are based on the creation of an organization-specific retention schedule, based on research of the regulatory, statutory and legal requirements for management of information for the industry in which the organization operates. Additional items to consider when establishing a retention period are any business needs that may exceed those requirements and consideration of the potential historic, intrinsic or enduring value of the information. If the information has met all of these needs and is no longer considered to be valuable, it should be disposed of by means appropriate for the content. This may include ensuring that others cannot obtain access to outdated or obsolete information as well as measures for protection privacy and confidentiality.

Long-term records are those that are identified to have a continuing value to an organization. Based on the period assigned in the retention schedule, these may be held for periods of 25 years or longer, or may even be assigned a retention period of "indefinite" or "permanent". The term "permanent" is used much less frequently outside of the Federal Government, as it is impossible to establish a requirement for such a retention period. There is a need to ensure records of a continuing value are managed using methods that ensure they remain persistently accessible for length of the time they are retained. While this is relatively easy to accomplishing with paper or microfilm based records by providing appropriate environmental conditions and adequate protection from potential hazards, it is less simple for electronic format records. There are unique concerns related to ensuring the format they are generated/captured in remains viable and the media they are stored on remains accessible. Media is subject to both degradation and obsolescence over its lifespan, and therefore, policies and procedures must be established for the periodic conversion and migration of information stored electronically to ensure it remains accessible for its required retention periods.

Information Lifecycle Management

IT asset management

From Wikipedia, the free encyclopedia
Jump to: navigation, search

IT asset management (ITAM) is the set of business practices that join financial, contractual and inventory functions to support life cycle management and strategic decision making for the IT environment. Assets include all elements of software and hardware that are found in the business environment.

Software asset management

Software Asset Management applies to the business practices specific to software management, including software license management, configuration management, standardization of images and compliance to regulatory and legal restrictions—such as copyright law, Sarbanes Oxley and software publisher contractual compliance. Legal software use in an organization is enforced by such compliance companies as Business Software Alliance, SIIA and FAST.

Software is referred to as entitlements so that SAM programs confirm the right to use, or entitlement to that software by the user. Automation is used to facilitate this management. Microsoft maintains a list of SAM providers to help customers manage their software.

[edit] Hardware asset management

Hardware asset management entails the management of the physical components of computers and computer networks, from acquisition through disposal. Common business practices include request and approval process, procurement management, life cycle management, redeployment and disposal management.

[edit] Role of IT asset management in an organization

The IT Asset Management function is the primary point of accountability for the life-cycle management of information technology assets throughout the organization.

Included in this responsibility are development and maintenance of policies, standards, processes, systems and measurements that enable the organization to manage the IT Asset Portfolio with respect to risk, cost, control, IT Governance, compliance and business performance objectives as established by the business.

IT Asset Management integrates the physical, technological, contractual and financial aspects of information technology assets to enable a holistic and proactive approach to achieving the objectives.

[edit] Goals of ITAM

ITAM business practices have a common set of goals:

* Uncover savings through process improvement and support for strategic decision making
* Gain control of the inventory
* Increase accountability to insure compliance
* Enhance performance of assets and the life cycle management
* Risk reduction through standardization, proper documentation, loss detection

[edit] Process

ITAM business practices are process-driven and matured through iterative and focused improvements. Most successful ITAM programs are invasive to the organization, involving everyone at some level, such as end users (educating on compliance), budget managers (redeployment as a choice), IT service departments (providing information on warranties), and finance (invoice reconciliation, updates for fixed asset inventories).

IT asset management generally uses automation to manage the discovery of assets, so inventory can be compared to ownership information. Full business management of IT assets requires a repository of multiple types of information about the asset, as well as integration with other systems such as supply chain, help desk, procurement and HR systems.

Friday, July 20, 2007

The Management System for ISO 17799

Introduction

The publication of the standard ISO 17799 provides an international basis for a common understanding of management of information security. ISO 17799 was developed as a standard containing codes of practice for information security management to ensure that appropriate action is taken to secure data storage and transfer - whether data is provided in paper or in electronic form.

ISO 17799 "Code of Practice for Information Security Management" refers to ten control for these actions:
- Security Policy
- Security Organisation
- Asset Classification and Control
- Personnel Security
- Physical and Environmental Security
- Communications and Operations Management
- Access Control
- Systems Development and Maintenance
- Business Continuity Management
- Compliance.

After the framework for managing information security is given this way a question arises about the management system which shall perform the management of information security. How does such a management system look like?

The Information Security Management System

Overview

The PCDA (Plan-Do-Check-Act) model used as basis for the revision of BS 7799-2 was not only selected to conform to other management standards such as ISO 9000 or ISO 14000. It even more emphasises a strict process thinking to use this model which has its root in quality management.
The phases or activities of the PDCA cycle are:
- PLAN: Establishing the ISMS
- DO: Operating the ISMS
- CHECK: Monitoring and reviewing the ISMS
- ACT: Improving the ISMS.

PLAN

The PLAN phase is concerned with establishing the ISMS. The first step is to determine the scope of the ISMS, i.e. responding to what shall be controlled by the ISMS. An ISMS policy has to be defined that includes objectives, legal or regulatory requirements, contractual obligations, strategic organisational and risk management context and risk assessment criteria.

There has to be a systematic approach to risk management. The definition of such an approach can be assisted by the very famous standard AS/NZS 4360:1999 from Australia and New Zealand or a standard published in the UK: AIRMIC, ALARM, IRM:2000.

Note: This standard is jointly developed by The Institute of Risk Management (IRM), The Association of Insurance and Risk Managers (AIRMIC) and ALARM The National Forum for Risk Management in the Public Sector.

Risk Identification
This step identifies the assets becoming subject to risk assessment and threats to those assets. Further vulnerabilities that might be exploited by the threats and potential losses have to be identified.

Risk Assessment
Risk assessment means to look at typically two parameters: probability of occurrence of risk and impact in case of occurrence of risk.
The FMEA (Failure Mode and effects Analysis) provides a third very interesting parameter: the probability of detection. This is the probability that the occurrence of a threat is detected by using detection actions before any major impact has happened. An example for detection actions are virus scans or intrusion detection.

Action Identification and Assessment
There are several options of how to respond to a risk, including:
- taking actions
- accepting risks
- avoiding risks
- transferring risks to other parties.

Controlling Risk Actions
ISO 17799 includes several controls without claiming these to be complete. These controls shall be selected and justified on basis of the results of risk assessment.

Statement of Applicability
The Statement of Applicability documents the controls.

Management Approval
Management has to approve the implementation of the ISMS. The responsibility of management is a key success factor for the ISMS (please cf. below).

DO

The DO phase implements the steps as planned in the previous phase. Activities as known from project management are employed to build the ISMS. These include:
- Management of implementation
- Resource Management
- Schedule Management
- Training Management

CHECK

In the CHECK phase the ISMS is monitored and reviewed.

Monitoring
Monitoring the operation of the ISMS includes detecting errors in the results of processing, identifying security breaches, auditing performance, identifying actions taken to resolve a security breach, following up actions in case of security breaches.

Review
Reviews ensure the effectiveness of the ISMS; they are conducted in a regular manner. Reviews include:
- Security Policy and Objectives
- Audits
- Observations
- Suggestions for Improvement
- Feedback.

Residual risk
Residual and acceptable risk has to be reviewed regularly with regard to impact on organisation, technology, business objectives and processes, identified threats and external effects such as legal or regulatory environment and changes in social climate.

ACT

The ACT phase is the phase of improvement. In this phase improvements are implemented, corrective and preventive actions taken, results communicated with all interested parties and improvement actions monitored.

The Management Control System

The management control system comprises:
- Document Control
- Audit
- Review
- Responsibility of Management
- Corrective and Preventive Actions
- Continual Improvement

Document Control

Document Control of ISMS is the same as of quality management. Hence, all organisations having implemented a document control system conforming to ISO 9000: 2000 will meet the requirements of BS 7799-2 with regard to the procedures needed for document control. The single steps are:
- Approval of documents for adequacy prior to issue
- Review and update of documents as necessary and reapprove
- Identification of changes and current document revision status
- Availability of relevant versions of documents at points of use
- Legible and readily identifiable documents
- Identification and controlled distribution of external documents
- Controlled distribution of documents
- Prevention of unintended use of obsolete documents
- Suitable identification to obsolete documents if they are retained.

BS 7799-2 lists documents to be included into the ISMS:
- Statements of security policy and control objectives
- Scope, procedures and controls of the ISMS
- Risk assessment report
- Risk treatment plan
- Procedures to ensure effective planning, operation and control of its IS processes
- Records (cf. below)
- Statement of Applicability

Control of Records
Records have to be made and maintained as evidence of conformance to the standard and to demonstrate the effective operation of the ISMS. Again, the requirements are the same as for quality management.

The procedure to control records has to be documented and comprises:
- Identification
- Storage
- Protection
- Retrieval
- Retention
- Disposition

The internal Audit

The internal audit plays a core role in the effort of maintaining information security and improvement. Audits shall ensure that all elements of the ISMS conform to the requirements of the standard and identified information security requirements, are effectively implemented and maintained and perform as expected. The results of audits are:
- Actual, detected concerns (cf. below: Corrective Actions)
- Potential concerns (cf. below: Preventive Actions)
- Opportunities for improvement (cf. below: continual improvement)

Audit activities comprise:
- Definition of audit objectives
- Examine the documents
- Audit planning
- Auditing
- Audit results report
- Completion of audit plan
- Follow-up audits as needed
Organisations running a quality management system easily can combine the audit function of the ISMS with the one of quality management.

Management Review

Management has to conduct a management review of the ISMS; this again is known from quality management. The management review shall confirm the continuing suitability, adequacy and effectiveness of the ISMS.

Review input includes audit and review results, corrective and preventive actions, recommendations for improvement and new technologies and procedures.

The results of a review are corrections and improvements to the ISMS and provision of resources as needed.

Management Responsibility

A very important, though often neglected element of the management control system is management responsibility. It covers three items:
- Management commitment
- Resource management
- Training, awareness and competency.

Management Commitment
Management commitment is like in other management systems a critical success factor. In particular, management has to care about:
- Establishing the information security policy
- Ensuring that information security objectives and plans are established
- Assigning roles and responsibilities
- Communication of importance of information security
- Providing sufficient resources for the ISMS (cf. below)
- Deciding about acceptable level of risk
- Conducting management reviews.

Resource Management
Management is responsible to provide sufficient resources to:
- Establish, implement, operate and maintain the ISMS
- Ensure that ISMS procedures support the business requirements
- Ensure that legal/regulatory requirements and contractual obligations are addressed
- Ensure adequate security by applying implemented controls
- Carry our reviews and taking appropriate actions
- Improve effectiveness of ISMS

Training, Awareness and competency
Management is responsible that all personal of the ISMS is sufficiently trained. In detail:
- Determining necessary competency
- Providing training
- Evaluating effectiveness of training
- Maintaining training records on experience, skills and qualifications.

Corrective and Preventive Actions

Internal audits and other internal and external source provide evidence about the effectiveness of the ISMS. Actions are initiated to eliminate any concern and prevent the re-occurrence of such concern. With regard to the management system there are two important types of actions: corrective actions and preventive actions.

Corrective actions are actions taken after the occurrence of a risk or a concern to prevent re-occurrence in the future.

Preventive actions are used to anticipate potential risks or concerns and to prevent any potential future damage before any occurrence is detected.

Continual Improvement of the ISMS

Both ISO 9000:2000 and BS 7799-2 list next to the just mentioned corrective and preventive actions the continual improvement. Whereas corrective and preventive actions focus on detected or potential concerns actions also can be taken to further improve a system in terms of effectiveness and efficiency that is free of any concern.

The continual striving for improvement without being based on any problem or concern is very important for any successful management system. It is the step from a re-active to a pro-active management.

The steps of continual improvement are:
- Identification of possible improvement area s
- Analysis and justification of needed action
- Determining availability of resources
- Deciding to implement improvements
- Implementing improvements
- Measuring impact on organisation
- Considering results at management review
- Continually looking for improvements.

Conclusion

BS 7799-2 provides an information security management system to realise information security as determined in ISO 17799. The neighbourhood to ISO 9000 is obvious and an important issue to efficiently setup the system.

BS 7799-2 is a fundamental add-on to ISO 17799 as it allows to integrate information security actions in a management system. Such a management is the basis any success in information security.

BS 7799-2 provides organisations with the opportunity register the ISMS and communicate the own commitment. ISO 17799 does not serve this.

By Andreas E. Fiedler

Published

© 2003 Northwest Controlling Corporation Ltd.
Internet: http://www.noweco.com/
Email: info@noweco.com.

Asset Management Journal Guide

Diligently managed assets of a business organization can make a lot of difference in its profit percentages. Judicious control over all tangible and intangible assets of a company makes sure that there are no leaking funds in the organization and all assets are utilized at maximum capacity. An inefficient management of resources and incorrect information about the objects in a commercial establishment may lead to drainage of finances and in turn adversely affect company’s performance.

Realizing the importance of asset management in any company’s performance has led to newer advanced strategies in this field of trade. Entire business management consists of host of issues comprising of cost management, capital budgeting, expense accounting, financial planning and reporting and many other similar topics. Asset management constitutes a large percentage of managing concerns in an organization. Apart from administering tangible goods, raw materials, finished products, vehicles, buildings and many other such items modern businesses also need to manage their intellectual assets.

Asset management is a comprehensive term and usually requires professional handling of the situation. There are many commercial asset-managing firms that offer services for administering various resources of the company. Many software are presently available in market that enable efficient managing of a companies assets. Traditional asset management meant dealing mostly with fixed assets in their every stage of life cycle. Entire infrastructure related to factory establishment comes under asset management.

Monitoring the whereabouts of assets, ensuring the availability of all resources required in an industry whether easily available or scarce is an integral part of managing assets for that company. Finalizing purchasing requests, valuation, depreciation, asset receipts, maintenance, warranties, user data and other related physical attributes of an asset form a major role of an asset manager.

Optimal judgment about methodology applied for managing assets of different enterprises differs according to their unique characteristics. No one procedure that has been successful for one concern can guarantee similar affluent results for another enterprise with different objectives.

Professional asset managers are also required to fix emergency problems arising due to unanticipated reduction in production capacity or a major break down in plants machinery, etc. the training received by them during their learning and skills learnt through experience facilitates a asset manager to handle every job diligently. Regular maintenance of assets ensures an adequate potential of asset manager while, recovering quickly from unpredicted adverse situation test the actual capability of asset management in a company.

The asset manager is liable to provide information about vast enquires related to it. The actual cost at procurement, vendor’s details, the department and the particular team that is using it, the physical location, depreciation and any other data related should always be available at any point of time. All this helps in efficient running of a business enterprise. Decisions as when new machinery needs to be purchased or the firm could carry on with just repairing old machinery and judgment about whether the concern should buy an asset or should lease it depends on information provided by the asset manger of the company.


About the Author:

Mansi aggarwal writes about asset management journal news. Learn more http://www.assetmanagementjournal.com .