ISO 27001:2022
Organizational controls – ISO 27001:2022

ISO 27001:2022 5.18: Access rights

Access rights to information and associated assets are to be granted, reviewed, changed and withdrawn in line with the access control rules and policy the organization has set. Purpose (stated in ISO/IEC 27002:2022): keeps access to information and assets defined and approved against what the business needs. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 5.18.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 103 controls across 30 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

PCI DSS 4.0 · 13 controls

  • 3.5.1.2 3.5.1.2 Disk or partition encryption only on removable media
  • 3.6.1.3 3.6.1.3 Cleartext key component access limited to minimum custodians
  • 7.2.2 7.2.2 User access assigned by job function and least privilege
  • 7.2.3 7.2.3 Privileges approved by authorized personnel
  • 7.2.5.1 7.2.5.1 Application and system account access reviewed periodically
  • 8.2.4 8.2.4 User ID lifecycle changes authorized
  • 8.2.5 8.2.5 Terminated users' access revoked immediately
  • 8.2.6 8.2.6 Inactive accounts removed within 90 days
  • 9.4.1 9.4.1 Physical security of all media
  • 3.6.1 3.6.1 Procedures protect keys against disclosure and misuse
  • 7.2.4 7.2.4 User accounts and privileges reviewed every six months
  • 7.2.5 7.2.5 Application and system accounts least privilege
  • 7.2.6 7.2.6 Query access to stored cardholder data restricted

CIS Controls v8 · 9 controls

  • CIS-12.5 Centralize Network Authentication, Authorization, and Auditing (AAA)
  • CIS-5.1 Establish and Maintain an Inventory of Accounts
  • CIS-5.3 Disable Dormant Accounts
  • CIS-5.5 Establish and Maintain an Inventory of Service Accounts
  • CIS-5.6 Centralize Account Management
  • CIS-6.1 Establish an Access Granting Process
  • CIS-6.2 Establish an Access Revoking Process
  • CIS-6.7 Centralize Access Control
  • CIS-6.8 Define and Maintain Role-Based Access Control

FedRAMP High · 8 controls

  • AC-2 Account Management
  • AC-2(13) Disable Accounts for High-Risk Individuals
  • AC-2(3) Disable Accounts
  • AC-2(7) Privileged User Accounts
  • AC-22 Publicly Accessible Content
  • AC-6 Least Privilege
  • AC-6(7) Review of User Privileges
  • PS-5 Personnel Transfer

FedRAMP Moderate · 8 controls

  • AC-2 Account Management
  • AC-2(13) Disable Accounts for High-Risk Individuals
  • AC-2(3) Disable Accounts
  • AC-2(7) Privileged User Accounts
  • AC-22 Publicly Accessible Content
  • AC-6 Least Privilege
  • AC-6(7) Review of User Privileges
  • PS-5 Personnel Transfer

NIST SP 800-53 Rev 5 · 7 controls

HIPAA Security Rule · 5 controls

NIST SP 800-66 Rev 2 · 5 controls

SOC 2 · 4 controls

  • SOC2-CC6.1 CC6.1 Logical access security over protected information assets
  • SOC2-CC6.2 CC6.2 Registering and authorising users before issuing credentials
  • SOC2-CC6.3 CC6.3 Role-based access, least privilege and segregation of duties
  • SOC2-P5.1 P5.1 Data subject access

UK Cyber Essentials · 4 controls

  • CE-AC.1 User Account Approval Process
  • CE-AC.3 Remove or Disable Accounts When No Longer Required
  • CE-AC.4 Privileged Account Approval and Tracking
  • CE-AC.6 Periodic Review of Privileged Access
  • ANSSI-HYG-05 Maintain an Exhaustive Inventory of Privileged Accounts
  • ANSSI-HYG-06 Organise Joiner, Leaver and Role Change Procedures
  • ANSSI-HYG-09 Assign the Correct Rights on Sensitive Resources
  • ASBv3-PA-4 Review and reconcile user access regularly
  • PA-2 Avoid standing access for user accounts and permissions
  • PA-3 Manage lifecycle of identities and entitlements

C5 (Germany) · 3 controls

  • C5-IDM-02 Granting and change of user accounts and access rights
  • C5-IDM-04 Withdraw or adjust access rights as the task area changes
  • C5-IDM-05 Regular review of access rights

CMMC 2.0 · 3 controls

ISO 27001:2013 · 3 controls

  • A.9.2.2 User access provisioning
  • A.9.2.5 Review of user access rights
  • A.9.2.6 Removal or adjustment of access rights
  • NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization
  • NIST-CSF-PR.AA-04 Identity assertions are protected, conveyed, and verified
  • NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties

NIST SP 800-171 Rev 3 · 3 controls

  • E8-ADMIN-ML2 Restrict Administrative Privileges (ML2)
  • ASD37-18 Restrict administrative privileges (Essential)
  • AUCDR-IS-1 Limit risk of unauthorised access to the CDR data environment
  • MYHR-SEC-2 Access controls and user account management
  • MBX-2 MBX-2 On departure, warn the employee of the account closure date and then delete the nominative address

COBIT 2019 · 1 control

  • DSS05.04 DSS05.04 Manage user identity and logical access

DORA · 1 control

ISO 27002:2022 · 1 control

ISO 27701:2019 · 1 control

  • 6.6.2 User access management

NIS2 Directive · 1 control

  • Art.21.2.i Human resources security, access control policies and asset management

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Organizational controls – ISO 27001:2022

You are reading one control. How much of ISO 27001:2022 have you already done?

ISO 27001:2022 5.18 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27001:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27001:2022 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 170 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 103 it maps to, and the evidence behind each claim, over MCP and REST.