Frameworks / ISO 27001:2022 / 5.16 ISO 27001:2022
Organizational controls – ISO 27001:2022
ISO 27001:2022 5.16: Identity management Identities are to be managed throughout their whole life cycle. Purpose (stated in ISO/IEC 27002:2022): enables unique identification of people and systems accessing organizational assets and appropriate assignment of access rights. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 5.16.
Maintained by Gerard Blokdyk · Verified against the published standard 18 August 2026 · Control text last updated 25 September 2026 What else in your programme already covers this This control maps to 116 controls across 29 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
AC-2 Account Management AC-2(1) Automated System Account Management AC-2(13) Disable Accounts for High-Risk Individuals IA-12 Identity Proofing (IA-12) IA-12(2) Identity Proofing | Identity Evidence (IA-12(2)) IA-12(3) Identity Proofing | Identity Evidence Validation and Verification (IA-12(3)) IA-12(5) Identity Proofing | Address Confirmation (IA-12(5)) IA-2 Identification and Authentication (Organizational Users) IA-2(12) Acceptance of PIV Credentials IA-4 Identifier Management IA-4(4) Identifier Management | Identify User Status (IA-4(4)) IA-5 Authenticator Management IA-8 Identification and Authentication (Non-Organizational Users) IA-8(1) Identification and Authentication (Non-organizational Users) | Acceptance of PIV Credentials from Other Agencies (IA-8(1)) IA-8(2) Identification and Authentication (Non-organizational Users) | Acceptance of External Authenticators (IA-8(2)) IA-8(4) Identification and Authentication (Non-organizational Users) | Use of Defined Profiles (IA-8(4)) AC-2 Account Management AC-2(1) Automated System Account Management AC-2(13) Disable Accounts for High-Risk Individuals IA-12 Identity Proofing (IA-12) IA-12(2) Identity Proofing | Identity Evidence (IA-12(2)) IA-12(3) Identity Proofing | Identity Evidence Validation and Verification (IA-12(3)) IA-12(5) Identity Proofing | Address Confirmation (IA-12(5)) IA-2 Identification and Authentication (Organizational Users) IA-2(12) Acceptance of PIV Credentials IA-4 Identifier Management IA-4(4) Identifier Management | Identify User Status (IA-4(4)) IA-5 Authenticator Management IA-8 Identification and Authentication (Non-Organizational Users) IA-8(1) Identification and Authentication (Non-organizational Users) | Acceptance of PIV Credentials from Other Agencies (IA-8(1)) IA-8(2) Identification and Authentication (Non-organizational Users) | Acceptance of External Authenticators (IA-8(2)) IA-8(4) Identification and Authentication (Non-organizational Users) | Use of Defined Profiles (IA-8(4)) 10.2.1.5 10.2.1.5 Logs capture changes to identification and authentication credentials 2.2.2 2.2.2 Vendor default accounts managed 8.2.1 8.2.1 Unique ID assigned to every user 8.2.2 8.2.2 Shared and generic IDs only by exception 8.2.3 8.2.3 Service provider unique factors per customer 8.2.4 8.2.4 User ID lifecycle changes authorized 8.2.6 8.2.6 Inactive accounts removed within 90 days 8.3.11 8.3.11 Tokens, smart cards and certificates individually assigned 8.3.3 8.3.3 Identity verified before factor changes 8.5.1 8.5.1 MFA system resistant to replay and bypass 9.2.3 9.2.3 Physical protection of network hardware and lines 9.3.1 9.3.1 Personnel physical access procedures for the CDE 7.2.4 7.2.4 User accounts and privileges reviewed every six months 7.2.5 7.2.5 Application and system accounts least privilege 7.2.6 7.2.6 Query access to stored cardholder data restricted CIS-12.5 Centralize Network Authentication, Authorization, and Auditing (AAA) CIS-16.11 Leverage Vetted Modules or Services for Application Security Components CIS-4.7 Manage Default Accounts on Enterprise Assets and Software CIS-5.1 Establish and Maintain an Inventory of Accounts CIS-5.3 Disable Dormant Accounts CIS-5.5 Establish and Maintain an Inventory of Service Accounts CIS-5.6 Centralize Account Management CIS-6.1 Establish an Access Granting Process CIS-6.7 Centralize Access Control ASBv3-IM-5 Use single sign-on (SSO) for application access IM-1 Use centralized identity and authentication system IM-3 Manage application identities securely and automatically PA-3 Manage lifecycle of identities and entitlements NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization NIST-CSF-PR.AA-02 Identities are proofed and bound to credentials based on the context of interactions NIST-CSF-PR.AA-03 Users, services, and hardware are authenticated NIST-CSF-PR.AA-04 Identity assertions are protected, conveyed, and verified ANSSI-HYG-05 Maintain an Exhaustive Inventory of Privileged Accounts ANSSI-HYG-06 Organise Joiner, Leaver and Role Change Procedures ANSSI-HYG-08 Identify Each Person by Name and Separate User and Administrator Roles SOC2-CC6.1 CC6.1 Logical access security over protected information assets SOC2-CC6.2 CC6.2 Registering and authorising users before issuing credentials SOC2-CC6.3 CC6.3 Role-based access, least privilege and segregation of duties CE-AC.1 User Account Approval Process CE-AC.2 Authenticate Users Before Granting Access CE-AC.3 Remove or Disable Accounts When No Longer Required MYHR-REG-11 Ensuring required information is given to the System Operator MYHR-SEC-2 Access controls and user account management C5-IDM-02 Granting and change of user accounts and access rights C5-IDM-03 Locking and withdrawal of user accounts in the event of inactivity or multiple failed logins E8-ADMIN-ML1 Restrict Administrative Privileges (ML1) AUCDR-IS-1 Limit risk of unauthorised access to the CDR data environment AESCSF-IAM-1 Identity management DSS05.04 DSS05.04 Manage user identity and logical access A.9.2.1 User registration and de-registration 6.6.2 User access management Art.21.2.i Human resources security, access control policies and asset management Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in Organizational controls – ISO 27001:2022 You are reading one control. How much of ISO 27001:2022 have you already done? ISO 27001:2022 5.16 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27001:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27001:2022 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 170 were rejected on the NIST SP 800-53 Rev 5 pair alone.
Query this from an agent The graph holds this control, the 116 it maps to, and the evidence behind each claim, over MCP and REST.