ISO 27001:2022
Organizational controls – ISO 27001:2022

ISO 27001:2022 5.16: Identity management

Identities are to be managed throughout their whole life cycle. Purpose (stated in ISO/IEC 27002:2022): enables unique identification of people and systems accessing organizational assets and appropriate assignment of access rights. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 5.16.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 116 controls across 29 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

FedRAMP High · 16 controls

  • AC-2 Account Management
  • AC-2(1) Automated System Account Management
  • AC-2(13) Disable Accounts for High-Risk Individuals
  • IA-12 Identity Proofing (IA-12)
  • IA-12(2) Identity Proofing | Identity Evidence (IA-12(2))
  • IA-12(3) Identity Proofing | Identity Evidence Validation and Verification (IA-12(3))
  • IA-12(5) Identity Proofing | Address Confirmation (IA-12(5))
  • IA-2 Identification and Authentication (Organizational Users)
  • IA-2(12) Acceptance of PIV Credentials
  • IA-4 Identifier Management
  • IA-4(4) Identifier Management | Identify User Status (IA-4(4))
  • IA-5 Authenticator Management
  • IA-8 Identification and Authentication (Non-Organizational Users)
  • IA-8(1) Identification and Authentication (Non-organizational Users) | Acceptance of PIV Credentials from Other Agencies (IA-8(1))
  • IA-8(2) Identification and Authentication (Non-organizational Users) | Acceptance of External Authenticators (IA-8(2))
  • IA-8(4) Identification and Authentication (Non-organizational Users) | Use of Defined Profiles (IA-8(4))

FedRAMP Moderate · 16 controls

  • AC-2 Account Management
  • AC-2(1) Automated System Account Management
  • AC-2(13) Disable Accounts for High-Risk Individuals
  • IA-12 Identity Proofing (IA-12)
  • IA-12(2) Identity Proofing | Identity Evidence (IA-12(2))
  • IA-12(3) Identity Proofing | Identity Evidence Validation and Verification (IA-12(3))
  • IA-12(5) Identity Proofing | Address Confirmation (IA-12(5))
  • IA-2 Identification and Authentication (Organizational Users)
  • IA-2(12) Acceptance of PIV Credentials
  • IA-4 Identifier Management
  • IA-4(4) Identifier Management | Identify User Status (IA-4(4))
  • IA-5 Authenticator Management
  • IA-8 Identification and Authentication (Non-Organizational Users)
  • IA-8(1) Identification and Authentication (Non-organizational Users) | Acceptance of PIV Credentials from Other Agencies (IA-8(1))
  • IA-8(2) Identification and Authentication (Non-organizational Users) | Acceptance of External Authenticators (IA-8(2))
  • IA-8(4) Identification and Authentication (Non-organizational Users) | Use of Defined Profiles (IA-8(4))

PCI DSS 4.0 · 15 controls

  • 10.2.1.5 10.2.1.5 Logs capture changes to identification and authentication credentials
  • 2.2.2 2.2.2 Vendor default accounts managed
  • 8.2.1 8.2.1 Unique ID assigned to every user
  • 8.2.2 8.2.2 Shared and generic IDs only by exception
  • 8.2.3 8.2.3 Service provider unique factors per customer
  • 8.2.4 8.2.4 User ID lifecycle changes authorized
  • 8.2.6 8.2.6 Inactive accounts removed within 90 days
  • 8.3.11 8.3.11 Tokens, smart cards and certificates individually assigned
  • 8.3.3 8.3.3 Identity verified before factor changes
  • 8.5.1 8.5.1 MFA system resistant to replay and bypass
  • 9.2.3 9.2.3 Physical protection of network hardware and lines
  • 9.3.1 9.3.1 Personnel physical access procedures for the CDE
  • 7.2.4 7.2.4 User accounts and privileges reviewed every six months
  • 7.2.5 7.2.5 Application and system accounts least privilege
  • 7.2.6 7.2.6 Query access to stored cardholder data restricted

CIS Controls v8 · 9 controls

  • CIS-12.5 Centralize Network Authentication, Authorization, and Auditing (AAA)
  • CIS-16.11 Leverage Vetted Modules or Services for Application Security Components
  • CIS-4.7 Manage Default Accounts on Enterprise Assets and Software
  • CIS-5.1 Establish and Maintain an Inventory of Accounts
  • CIS-5.3 Disable Dormant Accounts
  • CIS-5.5 Establish and Maintain an Inventory of Service Accounts
  • CIS-5.6 Centralize Account Management
  • CIS-6.1 Establish an Access Granting Process
  • CIS-6.7 Centralize Access Control

NIST SP 800-53 Rev 5 · 9 controls

  • ASBv3-IM-5 Use single sign-on (SSO) for application access
  • IM-1 Use centralized identity and authentication system
  • IM-3 Manage application identities securely and automatically
  • PA-3 Manage lifecycle of identities and entitlements

CMMC 2.0 · 4 controls

  • NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization
  • NIST-CSF-PR.AA-02 Identities are proofed and bound to credentials based on the context of interactions
  • NIST-CSF-PR.AA-03 Users, services, and hardware are authenticated
  • NIST-CSF-PR.AA-04 Identity assertions are protected, conveyed, and verified

NIST SP 800-171 Rev 3 · 4 controls

  • ANSSI-HYG-05 Maintain an Exhaustive Inventory of Privileged Accounts
  • ANSSI-HYG-06 Organise Joiner, Leaver and Role Change Procedures
  • ANSSI-HYG-08 Identify Each Person by Name and Separate User and Administrator Roles

HIPAA Security Rule · 3 controls

NIST SP 800-66 Rev 2 · 3 controls

SOC 2 · 3 controls

  • SOC2-CC6.1 CC6.1 Logical access security over protected information assets
  • SOC2-CC6.2 CC6.2 Registering and authorising users before issuing credentials
  • SOC2-CC6.3 CC6.3 Role-based access, least privilege and segregation of duties

UK Cyber Essentials · 3 controls

  • CE-AC.1 User Account Approval Process
  • CE-AC.2 Authenticate Users Before Granting Access
  • CE-AC.3 Remove or Disable Accounts When No Longer Required
  • MYHR-REG-11 Ensuring required information is given to the System Operator
  • MYHR-SEC-2 Access controls and user account management

C5 (Germany) · 2 controls

  • C5-IDM-02 Granting and change of user accounts and access rights
  • C5-IDM-03 Locking and withdrawal of user accounts in the event of inactivity or multiple failed logins
  • E8-ADMIN-ML1 Restrict Administrative Privileges (ML1)
  • AUCDR-IS-1 Limit risk of unauthorised access to the CDR data environment
  • AESCSF-IAM-1 Identity management

COBIT 2019 · 1 control

  • DSS05.04 DSS05.04 Manage user identity and logical access

DORA · 1 control

ISO 27001:2013 · 1 control

  • A.9.2.1 User registration and de-registration

ISO 27002:2022 · 1 control

  • 5.16 Identity management

ISO 27701:2019 · 1 control

  • 6.6.2 User access management

NIS2 Directive · 1 control

  • Art.21.2.i Human resources security, access control policies and asset management

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Organizational controls – ISO 27001:2022

You are reading one control. How much of ISO 27001:2022 have you already done?

ISO 27001:2022 5.16 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27001:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27001:2022 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 170 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 116 it maps to, and the evidence behind each claim, over MCP and REST.