ISO/IEC 27001

⌘K
  1. Home
  2. Docs
  3. ISO/IEC 27001
  4. Other Doc
  5. Intellectual Property Register

Intellectual Property Register

1. Purpose

The Intellectual Property Register provides a centralized record of the organization’s intellectual property (IP), ownership, classification, location, access, licensing, contractual restrictions, and protection requirements.

The register helps the organization:

  • Identify important intellectual property
  • Establish ownership
  • Record customer and third-party IP
  • Track software and licensing rights
  • Identify IP-related risks
  • Define appropriate protection measures
  • Support employee and contractor IP controls
  • Support software license compliance
  • Manage IP during onboarding and offboarding
  • Support incident investigations
  • Provide evidence for audits and assessments

Core Principle

Identify → Record → Establish Ownership → Classify → Protect → Monitor → Review → Revoke/Return → Retain Evidence


2. When to Use

Maintain the register where the organization owns, develops, receives, licenses, stores, or otherwise manages important intellectual property.

This may include:

  • Source code
  • Software products
  • Applications
  • APIs
  • Algorithms
  • Technical architecture
  • Databases
  • Documentation
  • Designs
  • Product specifications
  • Business processes
  • Trademarks
  • Logos
  • Domain names
  • Copyrighted material
  • Trade secrets
  • Research and development
  • Proprietary methodologies
  • Customer-owned material
  • Licensed third-party material
  • Open-source components
  • AI prompts, models, datasets, or generated materials where relevant

The register should be proportionate to the organization’s size, complexity, and risk.


3. Register Information

FieldDetails
Register NameIntellectual Property Register
Organization
Register Owner
Security Owner
Legal/Compliance Owner
Version
Effective Date
Last Review Date
Next Review Date
Approved By

4. Intellectual Property Register

Use one record for each significant IP asset or IP group.

IP IDIP NameIP TypeDescriptionOwnerCustodianClassificationLocationStatus
IP-001
IP-002
IP-003
  • Active
  • Under Development
  • Licensed
  • Customer-Owned
  • Third-Party
  • Restricted Use
  • Archived
  • Retired
  • Disposed

5. IP Identification

Identify the intellectual property managed by the organization.

Software and Technology

☐ Source code
☐ Application software
☐ APIs
☐ Scripts
☐ Infrastructure-as-Code
☐ Automation
☐ Algorithms
☐ Technical architecture
☐ Databases
☐ Configuration
☐ Security tooling
☐ CI/CD pipelines
☐ Proprietary technology

Business and Commercial IP

☐ Business methodology
☐ Proprietary processes
☐ Pricing models
☐ Product strategy
☐ Business plans
☐ Customer lists
☐ Sales materials
☐ Internal frameworks
☐ Research

Creative IP

☐ Documentation
☐ Training material
☐ Graphics
☐ Website content
☐ Videos
☐ Presentations
☐ Reports
☐ Marketing material

☐ Trademarks
☐ Logos
☐ Domain names
☐ Copyrighted works
☐ Registered designs
☐ Patents
☐ Trade secrets

External IP

☐ Customer IP
☐ Supplier IP
☐ Licensed software
☐ Open-source software
☐ Third-party documentation
☐ Third-party datasets
☐ Third-party models
☐ AI-generated material where applicable


6. IP Classification

Assign an appropriate classification to each IP asset.

ClassificationTypical Meaning
PublicInformation intentionally made publicly available
InternalOrganization-owned information not intended for public disclosure
ConfidentialSensitive business or technical information requiring controlled access
RestrictedHighly sensitive IP where unauthorized disclosure, modification, or use could cause significant impact

IP Classification

IP ID: __________________

Classification: __________________

Reason: __________________


7. Ownership

For every significant IP asset, identify the ownership position.

IP IDOwnership TypeLegal OwnerSupporting AgreementEvidence
Organization-Owned
Employee/Contractor Assignment
Customer-Owned
Licensed
Third-Party
Joint Ownership

Ownership Verification

☐ Ownership established
☐ Contract reviewed
☐ IP assignment completed where applicable
☐ License agreement reviewed
☐ Customer ownership requirements reviewed
☐ Third-party rights reviewed
☐ Evidence retained


8. IP Custodian

The IP Owner is accountable for the business/legal ownership or responsibility for the IP.

The IP Custodian is responsible for managing and protecting the IP in practice.

IP IDOwnerCustodianDepartmentContact

9. IP Location

Record where the IP is stored or maintained.

IP IDRepository/SystemEnvironmentLocationBackup Location

Examples:

  • GitHub/GitLab repository
  • AWS S3
  • Amazon RDS
  • AWS Secrets Manager
  • Corporate file storage
  • SaaS platform
  • Document management system
  • Physical records
  • Employee workstation

Do not record passwords, API keys, private keys, or other secrets in this register.


10. Source Code Register

Where software is developed internally, record important repositories.

Repository IDApplicationRepositoryOwnerClassificationProduction RelatedCriticality
SRC-001
SRC-002

Source Code Controls

☐ Access restricted
☐ MFA enabled
☐ Named accounts
☐ Branch protection
☐ Code review
☐ Repository backup
☐ Secrets scanning
☐ Dependency scanning
☐ Logging enabled
☐ Offboarding process defined


11. Software Product Register

Product IDProduct NameVersionOwnerRepositoryDeploymentIP Owner

Record significant changes where required.


12. Trademark Register

Trademark IDName/MarkTypeJurisdictionRegistration No.OwnerStatusRenewal
TM-001
TM-002

Examples:

  • Company name
  • Product name
  • Brand
  • Logo
  • Service mark

13. Domain Name Register

Domain IDDomainPurposeRegistrarOwnerRenewal DateStatus
DOM-001
DOM-002

Domain Controls

☐ Administrative access protected
☐ MFA enabled
☐ Renewal monitoring
☐ Ownership verified
☐ Recovery contact maintained
☐ Registrar access restricted


14. Copyright Register

Record significant copyrighted material.

Copyright IDWorkTypeAuthor/CreatorOwnerLocationStatus
CR-001
CR-002

Examples:

  • Software
  • Documentation
  • Training material
  • Website content
  • Graphics
  • Videos
  • Reports
  • Marketing content

15. Trade Secret Register

Where appropriate, identify important trade secrets.

Trade Secret IDDescriptionOwnerClassificationAccess GroupStorageReview
TS-001Restricted
TS-002Restricted

Avoid recording the actual secret itself in the register.

The register should identify where the protected information exists and how it is controlled, rather than unnecessarily reproducing the secret.


16. Patent and Invention Register

Where applicable:

Patent IDInventionInventorOwnerJurisdictionApplication No.Status
PAT-001
PAT-002

17. Customer-Owned IP

Customer IP must be clearly distinguished from organization-owned IP.

Customer IP IDCustomerIP DescriptionOwnershipPermitted UseStorageAccessReturn/Delete Requirement
CIP-001Customer
CIP-002Customer

Customer IP Controls

☐ Customer ownership verified
☐ Contract reviewed
☐ Permitted use documented
☐ Access restricted
☐ Classification assigned
☐ Retention defined
☐ Return/deletion requirement defined
☐ Offboarding requirement defined


18. Third-Party Licensed IP

Record important third-party intellectual property used by the organization.

License IDSoftware/IPProviderLicense TypePermitted UseRestrictionsRenewalOwner
LIC-001
LIC-002

Examples:

  • Commercial software
  • Stock images
  • Fonts
  • Datasets
  • APIs
  • SaaS software
  • Development frameworks
  • Commercial libraries
  • AI services

19. Open-Source Software Register

Where relevant, maintain a separate software dependency inventory or integrate the information into the IP register.

ComponentVersionLicenseApplicationSourceOwnerLicense Review

Review

☐ License identified
☐ License obligations understood
☐ Permitted use verified
☐ Attribution requirement identified
☐ Distribution requirement identified
☐ Copyleft implications considered
☐ Security vulnerabilities reviewed
☐ Approval completed where required


20. AI-Related Intellectual Property

Where AI is used in development or business operations, identify relevant IP.

AI IP IDAssetTypeProvider/ModelOwnerData UsedPermitted UseRisk
AI-001Prompt
AI-002Dataset
AI-003Model

Consider:

  • AI-generated content
  • Prompts
  • Proprietary datasets
  • Training data
  • Fine-tuned models
  • Model configurations
  • Evaluation datasets
  • AI-generated source code
  • Customer information used with AI
  • Third-party model licensing

AI use should comply with applicable contracts, licensing restrictions, confidentiality requirements, and organizational policy.


21. Employee and Contractor IP

Record IP created by employees or contractors where ownership documentation is relevant.

Person/RoleIPEngagement TypeAssignment RequiredAssignment CompletedEvidence
Employee
Contractor

Verification

☐ Employment agreement reviewed
☐ Contractor agreement reviewed
☐ IP assignment included where required
☐ Confidentiality obligations established
☐ Pre-existing IP identified
☐ Evidence retained


22. Pre-Existing IP

Identify IP brought into the organization or project before employment/engagement.

IP IDDescriptionOwnerPersonPre-Existing DatePermitted Organizational Use

This helps distinguish organizational IP from an employee’s or contractor’s pre-existing intellectual property.


23. IP Access Register

For sensitive IP, record who or which role has access.

IP IDUser/RoleAccess TypeBusiness NeedApprovalStart DateExpiry/Review
Read
Write
Admin

Apply least privilege.


24. IP Sharing

Record significant external sharing.

IP IDRecipientPurposeContract/NDAInformation SharedApproved ByDate

External sharing should be based on:

  • Business need
  • Ownership
  • Contractual rights
  • Classification
  • Confidentiality requirements
  • Security requirements
  • Approved transfer mechanisms

25. IP Risk Assessment

Important IP should be assessed for risks such as:

  • Unauthorized disclosure
  • Unauthorized modification
  • Theft
  • Misuse
  • Loss of ownership
  • License violation
  • Customer contractual violation
  • Unauthorized copying
  • Source-code exposure
  • Repository compromise
  • Employee/contractor departure
  • Supplier compromise
  • AI-related misuse
  • Counterfeit or unauthorized use
  • Accidental public disclosure
IP IDThreatVulnerabilityImpactLikelihoodRiskTreatment

26. IP Protection Requirements

Define controls according to risk.

IP IDProtection RequirementControlOwnerEvidence
Encryption
MFA
Access restriction
Backup
Monitoring
Contractual protection

27. IP Lifecycle

Each important IP asset should have an identifiable lifecycle.

Lifecycle

Create → Identify → Establish Ownership → Classify → Store → Protect → Use → Share → Review → Archive/Retire → Return/Delete

Record important lifecycle events where appropriate.

IP IDLifecycle StageDateActionOwnerEvidence
Created
Updated
Archived
Retired

28. IP Changes

Significant changes should be recorded.

Change IDIP IDChangeReasonRisk ImpactApproved ByDate

Examples:

  • New owner
  • New repository
  • New license
  • New customer
  • New jurisdiction
  • New access group
  • New technology
  • Acquisition
  • Product change
  • Major software release

29. IP Incident Record

If an IP-related security event or incident occurs, record the relationship to the relevant IP.

Incident IDIP IDIncident TypeDateImpactStatusResponse Record
Unauthorized access
Data/IP disclosure
License issue

Examples:

  • Source-code exposure
  • Unauthorized repository access
  • Customer IP disclosure
  • License violation
  • Lost device containing IP
  • Unauthorized copying
  • Trademark misuse
  • Trade-secret disclosure

30. Offboarding

When employees, contractors, suppliers, or other parties leave the relationship, review their access to IP.

☐ IP access identified
☐ Repository access removed
☐ Cloud access removed
☐ SaaS access removed
☐ VPN access removed
☐ Credentials revoked
☐ Tokens revoked
☐ Customer IP access removed
☐ Assets returned
☐ Confidential information returned/deleted where required
☐ IP assignment obligations verified
☐ Exit evidence retained


31. IP Return and Deletion

For customer-owned or third-party IP:

IP IDOwnerReturn/Delete RequirementActionVerificationDate

Where deletion is required, retain appropriate evidence without retaining unnecessary copies of the protected information.


32. IP Review

The register should be reviewed periodically and following significant changes.

Review:

☐ New IP
☐ Retired IP
☐ Ownership changes
☐ New employees/contractors
☐ Offboarding
☐ New customers
☐ New suppliers
☐ New software licenses
☐ Open-source changes
☐ New AI services
☐ Repository changes
☐ Classification changes
☐ Access changes
☐ IP incidents
☐ Contract changes
☐ Legal/regulatory changes


33. Review Frequency

The organization should define review frequency based on risk.

Example:

IP RiskSuggested Review Approach
LowPeriodic review
MediumAt least annual review
HighMore frequent review
CriticalContinuous/change-triggered review

These are examples and should be aligned with the organization’s risk methodology.


34. IP Register Summary

CategoryTotal AssetsHigh RiskRestrictedCustomer-OwnedThird-PartyUnder Review
Software
Source Code
Trademarks
Copyright
Trade Secrets
Customer IP
Licensed IP
Open Source
AI IP
Other

35. Outstanding Actions

Action IDIP IDIssueRiskActionOwnerDue DateStatus

36. Exceptions

Any exception to IP protection requirements should be documented.

Exception IDIP IDRequirementReasonRiskCompensating ControlApproverExpiry

Exceptions should be:

  • Justified
  • Risk assessed
  • Approved by an authorized person
  • Time limited where practical
  • Reviewed periodically

37. AWS SaaS Startup Example

A SaaS startup operates a customer-facing application hosted on AWS.

Important IP may include:

Source Code

IP ID: IP-001
Asset: SaaS Application Source Code
Owner: CTO
Classification: Restricted
Repository: Corporate Git repository
Access: Development and approved DevOps personnel
Controls: MFA, branch protection, code review, logging, secrets scanning

Technical Architecture

IP ID: IP-002
Asset: AWS Architecture and Infrastructure-as-Code
Owner: Engineering
Classification: Confidential
Storage: Code repository and approved documentation platform
Controls: Access control, repository protection, backup

Customer Deliverables

IP ID: IP-003
Asset: Customer-specific implementation documentation
Owner: Customer
Classification: Confidential
Use: Contractually permitted customer support
Controls: Restricted access and contractual confidentiality

Proprietary Methodology

IP ID: IP-004
Asset: Internal SaaS security assessment methodology
Owner: Organization
Classification: Restricted
Access: Security team
Controls: Restricted repository access and confidentiality requirements

Open-Source Dependencies

IP ID: IP-005
Asset: Software dependencies
Owner: Third-party authors/licensors
Classification: Third-party licensed
Controls: Dependency inventory, license review, vulnerability monitoring


38. Startup-Friendly Implementation

A startup does not need to create hundreds of individual records on day one.

Start with the IP that creates the greatest business or security exposure.

Phase 1 — Identify

Create records for:

  • Source code
  • Production architecture
  • Customer IP
  • Important business IP
  • Trademarks/domains
  • Critical licensed software

Phase 2 — Establish Ownership

Confirm:

  • Who owns it
  • Who created it
  • What contract applies
  • Whether assignment exists
  • Whether third-party rights exist

Phase 3 — Protect

Apply:

  • Classification
  • Least privilege
  • MFA
  • Encryption where appropriate
  • Repository controls
  • Backup
  • Logging
  • Contractual protection

Phase 4 — Review

Review:

  • Access
  • Ownership
  • Licenses
  • Customer restrictions
  • New AI usage
  • New suppliers
  • Offboarding
  • IP incidents

39. Common Mistakes

Avoid:

  • Treating source code as the only IP.
  • Failing to identify customer-owned IP.
  • Assuming everything created by a contractor automatically belongs to the organization.
  • Failing to document pre-existing IP.
  • Ignoring open-source licenses.
  • Ignoring third-party content and datasets.
  • Keeping IP in personal repositories.
  • Granting excessive repository access.
  • Sharing confidential architecture without authorization.
  • Forgetting domain-name ownership.
  • Failing to track license renewal.
  • Using customer information in AI tools without reviewing contractual restrictions.
  • Failing to update the register after major product changes.
  • Keeping the actual secret or credential inside the IP register.

40. Relationship With Other ISMS Documents

DocumentRelationship
Intellectual Property Protection PolicyDefines IP protection requirements
Information Classification PolicyDefines classification
Asset RegisterIdentifies systems and information assets
Information Asset Ownership RegisterDefines asset ownership
Access Control PolicyControls access to IP
Supplier Security RequirementsProtects IP shared with suppliers
Customer Contract Security ReviewIdentifies customer IP obligations
Open Source Software PolicyControls open-source use
Software License Compliance ProcedureManages software licensing
Employee OnboardingEstablishes IP responsibilities
Employee OffboardingRevokes access and returns IP
Incident ManagementHandles IP-related incidents
Risk RegisterTracks significant IP risks
Legal & Regulatory Requirements RegisterTracks applicable legal obligations
Contractual Security Requirements RegisterTracks contractual IP commitments

41. ISO/IEC 27001 Connection

The Intellectual Property Register supports the organization’s risk-based management of information and related assets.

It can provide evidence for areas including:

  • Information classification
  • Asset ownership
  • Access control
  • Information transfer
  • Supplier security
  • Intellectual property protection
  • Protection of records
  • Secure development
  • Cloud security
  • Logging and monitoring
  • Information deletion
  • Offboarding

The register itself is not a universally mandatory ISO/IEC 27001 form.

The organization should determine what IP records are necessary based on:

  • Information-security risks
  • Business requirements
  • Legal requirements
  • Contractual obligations
  • Customer requirements
  • Technology environment
  • Risk treatment decisions

Relevant controls should be reflected in the organization’s applicable Statement of Applicability and supporting evidence.


42. Audit Evidence

Examples of evidence that may support the register include:

  • Completed IP Register
  • Employment agreements
  • Contractor agreements
  • IP assignment agreements
  • NDA/confidentiality agreements
  • Customer contracts
  • License agreements
  • Trademark records
  • Domain registration records
  • Copyright records
  • Software repository records
  • Access-control records
  • Repository permissions
  • Open-source inventories
  • SBOM
  • License review records
  • AI usage assessments
  • IP risk assessments
  • IP incident records
  • Offboarding records
  • Return/deletion evidence
  • Periodic review records

Do not store passwords, API keys, private keys, authentication tokens, or other secrets in the IP Register.


43. Final IP Audit Trail

For each important IP asset, the organization should be able to demonstrate:

What IP do we have?
Who owns it?
Who created it?
Is it ours, customer-owned, licensed, or third-party?
Where is it stored?
How is it classified?
Who can access it?
Why do they need access?
What contractual or licensing restrictions apply?
How is it protected?
What risks have been identified?
Has the IP been shared externally?
What happens when someone leaves?
What happens when the IP is retired?
What evidence proves that the controls are operating?


44. Final Principle

Identify the IP → Establish Ownership → Classify It → Record Its Location → Control Access → Protect It → Manage Licensing → Monitor Use → Review Changes → Revoke Access → Return/Delete When Required → Preserve Evidence

The Intellectual Property Register should not become a static inventory maintained only for an audit. It should be a working record connecting ownership, classification, access, licensing, security controls, contractual obligations, risk, and lifecycle management.