1. Purpose
The Intellectual Property Register provides a centralized record of the organization’s intellectual property (IP), ownership, classification, location, access, licensing, contractual restrictions, and protection requirements.
The register helps the organization:
- Identify important intellectual property
- Establish ownership
- Record customer and third-party IP
- Track software and licensing rights
- Identify IP-related risks
- Define appropriate protection measures
- Support employee and contractor IP controls
- Support software license compliance
- Manage IP during onboarding and offboarding
- Support incident investigations
- Provide evidence for audits and assessments
Core Principle
Identify → Record → Establish Ownership → Classify → Protect → Monitor → Review → Revoke/Return → Retain Evidence
2. When to Use
Maintain the register where the organization owns, develops, receives, licenses, stores, or otherwise manages important intellectual property.
This may include:
- Source code
- Software products
- Applications
- APIs
- Algorithms
- Technical architecture
- Databases
- Documentation
- Designs
- Product specifications
- Business processes
- Trademarks
- Logos
- Domain names
- Copyrighted material
- Trade secrets
- Research and development
- Proprietary methodologies
- Customer-owned material
- Licensed third-party material
- Open-source components
- AI prompts, models, datasets, or generated materials where relevant
The register should be proportionate to the organization’s size, complexity, and risk.
3. Register Information
| Field | Details |
|---|---|
| Register Name | Intellectual Property Register |
| Organization | |
| Register Owner | |
| Security Owner | |
| Legal/Compliance Owner | |
| Version | |
| Effective Date | |
| Last Review Date | |
| Next Review Date | |
| Approved By |
4. Intellectual Property Register
Use one record for each significant IP asset or IP group.
| IP ID | IP Name | IP Type | Description | Owner | Custodian | Classification | Location | Status |
|---|---|---|---|---|---|---|---|---|
| IP-001 | ||||||||
| IP-002 | ||||||||
| IP-003 |
Recommended Status
- Active
- Under Development
- Licensed
- Customer-Owned
- Third-Party
- Restricted Use
- Archived
- Retired
- Disposed
5. IP Identification
Identify the intellectual property managed by the organization.
Software and Technology
☐ Source code
☐ Application software
☐ APIs
☐ Scripts
☐ Infrastructure-as-Code
☐ Automation
☐ Algorithms
☐ Technical architecture
☐ Databases
☐ Configuration
☐ Security tooling
☐ CI/CD pipelines
☐ Proprietary technology
Business and Commercial IP
☐ Business methodology
☐ Proprietary processes
☐ Pricing models
☐ Product strategy
☐ Business plans
☐ Customer lists
☐ Sales materials
☐ Internal frameworks
☐ Research
Creative IP
☐ Documentation
☐ Training material
☐ Graphics
☐ Website content
☐ Videos
☐ Presentations
☐ Reports
☐ Marketing material
Legal/Brand IP
☐ Trademarks
☐ Logos
☐ Domain names
☐ Copyrighted works
☐ Registered designs
☐ Patents
☐ Trade secrets
External IP
☐ Customer IP
☐ Supplier IP
☐ Licensed software
☐ Open-source software
☐ Third-party documentation
☐ Third-party datasets
☐ Third-party models
☐ AI-generated material where applicable
6. IP Classification
Assign an appropriate classification to each IP asset.
| Classification | Typical Meaning |
|---|---|
| Public | Information intentionally made publicly available |
| Internal | Organization-owned information not intended for public disclosure |
| Confidential | Sensitive business or technical information requiring controlled access |
| Restricted | Highly sensitive IP where unauthorized disclosure, modification, or use could cause significant impact |
IP Classification
IP ID: __________________
Classification: __________________
Reason: __________________
7. Ownership
For every significant IP asset, identify the ownership position.
| IP ID | Ownership Type | Legal Owner | Supporting Agreement | Evidence |
|---|---|---|---|---|
| Organization-Owned | ||||
| Employee/Contractor Assignment | ||||
| Customer-Owned | ||||
| Licensed | ||||
| Third-Party | ||||
| Joint Ownership |
Ownership Verification
☐ Ownership established
☐ Contract reviewed
☐ IP assignment completed where applicable
☐ License agreement reviewed
☐ Customer ownership requirements reviewed
☐ Third-party rights reviewed
☐ Evidence retained
8. IP Custodian
The IP Owner is accountable for the business/legal ownership or responsibility for the IP.
The IP Custodian is responsible for managing and protecting the IP in practice.
| IP ID | Owner | Custodian | Department | Contact |
|---|---|---|---|---|
9. IP Location
Record where the IP is stored or maintained.
| IP ID | Repository/System | Environment | Location | Backup Location |
|---|---|---|---|---|
Examples:
- GitHub/GitLab repository
- AWS S3
- Amazon RDS
- AWS Secrets Manager
- Corporate file storage
- SaaS platform
- Document management system
- Physical records
- Employee workstation
Do not record passwords, API keys, private keys, or other secrets in this register.
10. Source Code Register
Where software is developed internally, record important repositories.
| Repository ID | Application | Repository | Owner | Classification | Production Related | Criticality |
|---|---|---|---|---|---|---|
| SRC-001 | ||||||
| SRC-002 |
Source Code Controls
☐ Access restricted
☐ MFA enabled
☐ Named accounts
☐ Branch protection
☐ Code review
☐ Repository backup
☐ Secrets scanning
☐ Dependency scanning
☐ Logging enabled
☐ Offboarding process defined
11. Software Product Register
| Product ID | Product Name | Version | Owner | Repository | Deployment | IP Owner |
|---|---|---|---|---|---|---|
Record significant changes where required.
12. Trademark Register
| Trademark ID | Name/Mark | Type | Jurisdiction | Registration No. | Owner | Status | Renewal |
|---|---|---|---|---|---|---|---|
| TM-001 | |||||||
| TM-002 |
Examples:
- Company name
- Product name
- Brand
- Logo
- Service mark
13. Domain Name Register
| Domain ID | Domain | Purpose | Registrar | Owner | Renewal Date | Status |
|---|---|---|---|---|---|---|
| DOM-001 | ||||||
| DOM-002 |
Domain Controls
☐ Administrative access protected
☐ MFA enabled
☐ Renewal monitoring
☐ Ownership verified
☐ Recovery contact maintained
☐ Registrar access restricted
14. Copyright Register
Record significant copyrighted material.
| Copyright ID | Work | Type | Author/Creator | Owner | Location | Status |
|---|---|---|---|---|---|---|
| CR-001 | ||||||
| CR-002 |
Examples:
- Software
- Documentation
- Training material
- Website content
- Graphics
- Videos
- Reports
- Marketing content
15. Trade Secret Register
Where appropriate, identify important trade secrets.
| Trade Secret ID | Description | Owner | Classification | Access Group | Storage | Review |
|---|---|---|---|---|---|---|
| TS-001 | Restricted | |||||
| TS-002 | Restricted |
Avoid recording the actual secret itself in the register.
The register should identify where the protected information exists and how it is controlled, rather than unnecessarily reproducing the secret.
16. Patent and Invention Register
Where applicable:
| Patent ID | Invention | Inventor | Owner | Jurisdiction | Application No. | Status |
|---|---|---|---|---|---|---|
| PAT-001 | ||||||
| PAT-002 |
17. Customer-Owned IP
Customer IP must be clearly distinguished from organization-owned IP.
| Customer IP ID | Customer | IP Description | Ownership | Permitted Use | Storage | Access | Return/Delete Requirement |
|---|---|---|---|---|---|---|---|
| CIP-001 | Customer | ||||||
| CIP-002 | Customer |
Customer IP Controls
☐ Customer ownership verified
☐ Contract reviewed
☐ Permitted use documented
☐ Access restricted
☐ Classification assigned
☐ Retention defined
☐ Return/deletion requirement defined
☐ Offboarding requirement defined
18. Third-Party Licensed IP
Record important third-party intellectual property used by the organization.
| License ID | Software/IP | Provider | License Type | Permitted Use | Restrictions | Renewal | Owner |
|---|---|---|---|---|---|---|---|
| LIC-001 | |||||||
| LIC-002 |
Examples:
- Commercial software
- Stock images
- Fonts
- Datasets
- APIs
- SaaS software
- Development frameworks
- Commercial libraries
- AI services
19. Open-Source Software Register
Where relevant, maintain a separate software dependency inventory or integrate the information into the IP register.
| Component | Version | License | Application | Source | Owner | License Review |
|---|---|---|---|---|---|---|
Review
☐ License identified
☐ License obligations understood
☐ Permitted use verified
☐ Attribution requirement identified
☐ Distribution requirement identified
☐ Copyleft implications considered
☐ Security vulnerabilities reviewed
☐ Approval completed where required
20. AI-Related Intellectual Property
Where AI is used in development or business operations, identify relevant IP.
| AI IP ID | Asset | Type | Provider/Model | Owner | Data Used | Permitted Use | Risk |
|---|---|---|---|---|---|---|---|
| AI-001 | Prompt | ||||||
| AI-002 | Dataset | ||||||
| AI-003 | Model |
Consider:
- AI-generated content
- Prompts
- Proprietary datasets
- Training data
- Fine-tuned models
- Model configurations
- Evaluation datasets
- AI-generated source code
- Customer information used with AI
- Third-party model licensing
AI use should comply with applicable contracts, licensing restrictions, confidentiality requirements, and organizational policy.
21. Employee and Contractor IP
Record IP created by employees or contractors where ownership documentation is relevant.
| Person/Role | IP | Engagement Type | Assignment Required | Assignment Completed | Evidence |
|---|---|---|---|---|---|
| Employee | |||||
| Contractor |
Verification
☐ Employment agreement reviewed
☐ Contractor agreement reviewed
☐ IP assignment included where required
☐ Confidentiality obligations established
☐ Pre-existing IP identified
☐ Evidence retained
22. Pre-Existing IP
Identify IP brought into the organization or project before employment/engagement.
| IP ID | Description | Owner | Person | Pre-Existing Date | Permitted Organizational Use |
|---|---|---|---|---|---|
This helps distinguish organizational IP from an employee’s or contractor’s pre-existing intellectual property.
23. IP Access Register
For sensitive IP, record who or which role has access.
| IP ID | User/Role | Access Type | Business Need | Approval | Start Date | Expiry/Review |
|---|---|---|---|---|---|---|
| Read | ||||||
| Write | ||||||
| Admin |
Apply least privilege.
24. IP Sharing
Record significant external sharing.
| IP ID | Recipient | Purpose | Contract/NDA | Information Shared | Approved By | Date |
|---|---|---|---|---|---|---|
External sharing should be based on:
- Business need
- Ownership
- Contractual rights
- Classification
- Confidentiality requirements
- Security requirements
- Approved transfer mechanisms
25. IP Risk Assessment
Important IP should be assessed for risks such as:
- Unauthorized disclosure
- Unauthorized modification
- Theft
- Misuse
- Loss of ownership
- License violation
- Customer contractual violation
- Unauthorized copying
- Source-code exposure
- Repository compromise
- Employee/contractor departure
- Supplier compromise
- AI-related misuse
- Counterfeit or unauthorized use
- Accidental public disclosure
| IP ID | Threat | Vulnerability | Impact | Likelihood | Risk | Treatment |
|---|---|---|---|---|---|---|
26. IP Protection Requirements
Define controls according to risk.
| IP ID | Protection Requirement | Control | Owner | Evidence |
|---|---|---|---|---|
| Encryption | ||||
| MFA | ||||
| Access restriction | ||||
| Backup | ||||
| Monitoring | ||||
| Contractual protection |
27. IP Lifecycle
Each important IP asset should have an identifiable lifecycle.
Lifecycle
Create → Identify → Establish Ownership → Classify → Store → Protect → Use → Share → Review → Archive/Retire → Return/Delete
Record important lifecycle events where appropriate.
| IP ID | Lifecycle Stage | Date | Action | Owner | Evidence |
|---|---|---|---|---|---|
| Created | |||||
| Updated | |||||
| Archived | |||||
| Retired |
28. IP Changes
Significant changes should be recorded.
| Change ID | IP ID | Change | Reason | Risk Impact | Approved By | Date |
|---|---|---|---|---|---|---|
Examples:
- New owner
- New repository
- New license
- New customer
- New jurisdiction
- New access group
- New technology
- Acquisition
- Product change
- Major software release
29. IP Incident Record
If an IP-related security event or incident occurs, record the relationship to the relevant IP.
| Incident ID | IP ID | Incident Type | Date | Impact | Status | Response Record |
|---|---|---|---|---|---|---|
| Unauthorized access | ||||||
| Data/IP disclosure | ||||||
| License issue |
Examples:
- Source-code exposure
- Unauthorized repository access
- Customer IP disclosure
- License violation
- Lost device containing IP
- Unauthorized copying
- Trademark misuse
- Trade-secret disclosure
30. Offboarding
When employees, contractors, suppliers, or other parties leave the relationship, review their access to IP.
☐ IP access identified
☐ Repository access removed
☐ Cloud access removed
☐ SaaS access removed
☐ VPN access removed
☐ Credentials revoked
☐ Tokens revoked
☐ Customer IP access removed
☐ Assets returned
☐ Confidential information returned/deleted where required
☐ IP assignment obligations verified
☐ Exit evidence retained
31. IP Return and Deletion
For customer-owned or third-party IP:
| IP ID | Owner | Return/Delete Requirement | Action | Verification | Date |
|---|---|---|---|---|---|
Where deletion is required, retain appropriate evidence without retaining unnecessary copies of the protected information.
32. IP Review
The register should be reviewed periodically and following significant changes.
Review:
☐ New IP
☐ Retired IP
☐ Ownership changes
☐ New employees/contractors
☐ Offboarding
☐ New customers
☐ New suppliers
☐ New software licenses
☐ Open-source changes
☐ New AI services
☐ Repository changes
☐ Classification changes
☐ Access changes
☐ IP incidents
☐ Contract changes
☐ Legal/regulatory changes
33. Review Frequency
The organization should define review frequency based on risk.
Example:
| IP Risk | Suggested Review Approach |
|---|---|
| Low | Periodic review |
| Medium | At least annual review |
| High | More frequent review |
| Critical | Continuous/change-triggered review |
These are examples and should be aligned with the organization’s risk methodology.
34. IP Register Summary
| Category | Total Assets | High Risk | Restricted | Customer-Owned | Third-Party | Under Review |
|---|---|---|---|---|---|---|
| Software | ||||||
| Source Code | ||||||
| Trademarks | ||||||
| Copyright | ||||||
| Trade Secrets | ||||||
| Customer IP | ||||||
| Licensed IP | ||||||
| Open Source | ||||||
| AI IP | ||||||
| Other |
35. Outstanding Actions
| Action ID | IP ID | Issue | Risk | Action | Owner | Due Date | Status |
|---|---|---|---|---|---|---|---|
36. Exceptions
Any exception to IP protection requirements should be documented.
| Exception ID | IP ID | Requirement | Reason | Risk | Compensating Control | Approver | Expiry |
|---|---|---|---|---|---|---|---|
Exceptions should be:
- Justified
- Risk assessed
- Approved by an authorized person
- Time limited where practical
- Reviewed periodically
37. AWS SaaS Startup Example
A SaaS startup operates a customer-facing application hosted on AWS.
Important IP may include:
Source Code
IP ID: IP-001
Asset: SaaS Application Source Code
Owner: CTO
Classification: Restricted
Repository: Corporate Git repository
Access: Development and approved DevOps personnel
Controls: MFA, branch protection, code review, logging, secrets scanning
Technical Architecture
IP ID: IP-002
Asset: AWS Architecture and Infrastructure-as-Code
Owner: Engineering
Classification: Confidential
Storage: Code repository and approved documentation platform
Controls: Access control, repository protection, backup
Customer Deliverables
IP ID: IP-003
Asset: Customer-specific implementation documentation
Owner: Customer
Classification: Confidential
Use: Contractually permitted customer support
Controls: Restricted access and contractual confidentiality
Proprietary Methodology
IP ID: IP-004
Asset: Internal SaaS security assessment methodology
Owner: Organization
Classification: Restricted
Access: Security team
Controls: Restricted repository access and confidentiality requirements
Open-Source Dependencies
IP ID: IP-005
Asset: Software dependencies
Owner: Third-party authors/licensors
Classification: Third-party licensed
Controls: Dependency inventory, license review, vulnerability monitoring
38. Startup-Friendly Implementation
A startup does not need to create hundreds of individual records on day one.
Start with the IP that creates the greatest business or security exposure.
Phase 1 — Identify
Create records for:
- Source code
- Production architecture
- Customer IP
- Important business IP
- Trademarks/domains
- Critical licensed software
Phase 2 — Establish Ownership
Confirm:
- Who owns it
- Who created it
- What contract applies
- Whether assignment exists
- Whether third-party rights exist
Phase 3 — Protect
Apply:
- Classification
- Least privilege
- MFA
- Encryption where appropriate
- Repository controls
- Backup
- Logging
- Contractual protection
Phase 4 — Review
Review:
- Access
- Ownership
- Licenses
- Customer restrictions
- New AI usage
- New suppliers
- Offboarding
- IP incidents
39. Common Mistakes
Avoid:
- Treating source code as the only IP.
- Failing to identify customer-owned IP.
- Assuming everything created by a contractor automatically belongs to the organization.
- Failing to document pre-existing IP.
- Ignoring open-source licenses.
- Ignoring third-party content and datasets.
- Keeping IP in personal repositories.
- Granting excessive repository access.
- Sharing confidential architecture without authorization.
- Forgetting domain-name ownership.
- Failing to track license renewal.
- Using customer information in AI tools without reviewing contractual restrictions.
- Failing to update the register after major product changes.
- Keeping the actual secret or credential inside the IP register.
40. Relationship With Other ISMS Documents
| Document | Relationship |
|---|---|
| Intellectual Property Protection Policy | Defines IP protection requirements |
| Information Classification Policy | Defines classification |
| Asset Register | Identifies systems and information assets |
| Information Asset Ownership Register | Defines asset ownership |
| Access Control Policy | Controls access to IP |
| Supplier Security Requirements | Protects IP shared with suppliers |
| Customer Contract Security Review | Identifies customer IP obligations |
| Open Source Software Policy | Controls open-source use |
| Software License Compliance Procedure | Manages software licensing |
| Employee Onboarding | Establishes IP responsibilities |
| Employee Offboarding | Revokes access and returns IP |
| Incident Management | Handles IP-related incidents |
| Risk Register | Tracks significant IP risks |
| Legal & Regulatory Requirements Register | Tracks applicable legal obligations |
| Contractual Security Requirements Register | Tracks contractual IP commitments |
41. ISO/IEC 27001 Connection
The Intellectual Property Register supports the organization’s risk-based management of information and related assets.
It can provide evidence for areas including:
- Information classification
- Asset ownership
- Access control
- Information transfer
- Supplier security
- Intellectual property protection
- Protection of records
- Secure development
- Cloud security
- Logging and monitoring
- Information deletion
- Offboarding
The register itself is not a universally mandatory ISO/IEC 27001 form.
The organization should determine what IP records are necessary based on:
- Information-security risks
- Business requirements
- Legal requirements
- Contractual obligations
- Customer requirements
- Technology environment
- Risk treatment decisions
Relevant controls should be reflected in the organization’s applicable Statement of Applicability and supporting evidence.
42. Audit Evidence
Examples of evidence that may support the register include:
- Completed IP Register
- Employment agreements
- Contractor agreements
- IP assignment agreements
- NDA/confidentiality agreements
- Customer contracts
- License agreements
- Trademark records
- Domain registration records
- Copyright records
- Software repository records
- Access-control records
- Repository permissions
- Open-source inventories
- SBOM
- License review records
- AI usage assessments
- IP risk assessments
- IP incident records
- Offboarding records
- Return/deletion evidence
- Periodic review records
Do not store passwords, API keys, private keys, authentication tokens, or other secrets in the IP Register.
43. Final IP Audit Trail
For each important IP asset, the organization should be able to demonstrate:
What IP do we have?
Who owns it?
Who created it?
Is it ours, customer-owned, licensed, or third-party?
Where is it stored?
How is it classified?
Who can access it?
Why do they need access?
What contractual or licensing restrictions apply?
How is it protected?
What risks have been identified?
Has the IP been shared externally?
What happens when someone leaves?
What happens when the IP is retired?
What evidence proves that the controls are operating?
44. Final Principle
Identify the IP → Establish Ownership → Classify It → Record Its Location → Control Access → Protect It → Manage Licensing → Monitor Use → Review Changes → Revoke Access → Return/Delete When Required → Preserve Evidence
The Intellectual Property Register should not become a static inventory maintained only for an audit. It should be a working record connecting ownership, classification, access, licensing, security controls, contractual obligations, risk, and lifecycle management.
