ISO 27002:2022
Organizational controls – ISO 27002:2022

ISO 27002:2022 5.16: Identity management

Identities are to be managed throughout their whole life cycle. Purpose: make it possible to identify each person and system that accesses the organization's information and assets uniquely, and to assign access rights properly. Guidance: identity processes should ensure that an identity issued to a person is tied to that one person so they can be held accountable; that identities used by several people (shared identities) are allowed only where the business or operations genuinely need them, each with its own approval, and documented; that identities for non-human entities go through appropriately segregated approval and are independently overseen on an ongoing basis; that identities are disabled or removed promptly once no longer needed, for example when the entity is retired or the person leaves or changes role; that within a given domain each entity has only one identity so duplicates are avoided; and that records are kept of all significant events in the use and management of identities and authentication information. A supporting process handles changes to identity information and may include re-checking trusted documents about a person. Where third-party identities are accepted (for example social media logins), the organization confirms they give the trust level required and that the associated risks are understood and treated, including through supplier controls (5.19) and authentication information controls (5.17). Other information: granting or withdrawing access typically involves confirming the business need for an identity, verifying the entity before assigning a logical identity, creating it, configuring and activating it together with its authentication services, and then granting or revoking specific rights based on authorization decisions (5.18).

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 125 controls across 35 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

FedRAMP High · 19 controls

  • AC-2 Account Management
  • AC-2(2) Automated Temporary and Emergency Account Management
  • AC-2(7) Privileged User Accounts
  • IA-1 Policy and Procedures
  • IA-12 Identity Proofing (IA-12)
  • IA-12(2) Identity Proofing | Identity Evidence (IA-12(2))
  • IA-12(3) Identity Proofing | Identity Evidence Validation and Verification (IA-12(3))
  • IA-12(5) Identity Proofing | Address Confirmation (IA-12(5))
  • IA-2 Identification and Authentication (Organizational Users)
  • IA-3 Device Identification and Authentication
  • IA-4 Identifier Management
  • IA-4(4) Identifier Management | Identify User Status (IA-4(4))
  • IA-5 Authenticator Management
  • IA-5(2) Public Key-Based Authentication
  • IA-8 Identification and Authentication (Non-Organizational Users)
  • IA-8(1) Identification and Authentication (Non-organizational Users) | Acceptance of PIV Credentials from Other Agencies (IA-8(1))
  • IA-8(2) Identification and Authentication (Non-organizational Users) | Acceptance of External Authenticators (IA-8(2))
  • IA-8(4) Identification and Authentication (Non-organizational Users) | Use of Defined Profiles (IA-8(4))
  • PS-4 Personnel Termination

FedRAMP Moderate · 19 controls

  • AC-2 Account Management
  • AC-2(2) Automated Temporary and Emergency Account Management
  • AC-2(7) Privileged User Accounts
  • IA-1 Policy and Procedures
  • IA-12 Identity Proofing (IA-12)
  • IA-12(2) Identity Proofing | Identity Evidence (IA-12(2))
  • IA-12(3) Identity Proofing | Identity Evidence Validation and Verification (IA-12(3))
  • IA-12(5) Identity Proofing | Address Confirmation (IA-12(5))
  • IA-2 Identification and Authentication (Organizational Users)
  • IA-3 Device Identification and Authentication
  • IA-4 Identifier Management
  • IA-4(4) Identifier Management | Identify User Status (IA-4(4))
  • IA-5 Authenticator Management
  • IA-5(2) Public Key-Based Authentication
  • IA-8 Identification and Authentication (Non-Organizational Users)
  • IA-8(1) Identification and Authentication (Non-organizational Users) | Acceptance of PIV Credentials from Other Agencies (IA-8(1))
  • IA-8(2) Identification and Authentication (Non-organizational Users) | Acceptance of External Authenticators (IA-8(2))
  • IA-8(4) Identification and Authentication (Non-organizational Users) | Use of Defined Profiles (IA-8(4))
  • PS-4 Personnel Termination

NIST SP 800-53 Rev 5 · 10 controls

PCI DSS 4.0 · 10 controls

  • 8.2.1 8.2.1 Unique ID assigned to every user
  • 8.2.2 8.2.2 Shared and generic IDs only by exception
  • 8.2.3 8.2.3 Service provider unique factors per customer
  • 8.2.4 8.2.4 User ID lifecycle changes authorized
  • 8.2.6 8.2.6 Inactive accounts removed within 90 days
  • 8.3.11 8.3.11 Tokens, smart cards and certificates individually assigned
  • 8.3.3 8.3.3 Identity verified before factor changes
  • 9.4.1 9.4.1 Physical security of all media
  • 7.2.4 7.2.4 User accounts and privileges reviewed every six months
  • 7.2.5 7.2.5 Application and system accounts least privilege

CIS Controls v8 · 7 controls

  • CIS-12.5 Centralize Network Authentication, Authorization, and Auditing (AAA)
  • CIS-5.1 Establish and Maintain an Inventory of Accounts
  • CIS-5.3 Disable Dormant Accounts
  • CIS-5.5 Establish and Maintain an Inventory of Service Accounts
  • CIS-5.6 Centralize Account Management
  • CIS-6.5 Require MFA for Administrative Access
  • CIS-6.6 Establish and Maintain an Inventory of Authentication and Authorization Systems
  • ASBv3-LT-2 Enable threat detection for identity and access management
  • ASBv3-PA-5 Set up emergency access
  • IM-1 Use centralized identity and authentication system
  • IM-3 Manage application identities securely and automatically
  • PA-3 Manage lifecycle of identities and entitlements

CMMC 2.0 · 4 controls

MTCS (Singapore) · 4 controls

  • 22.14 Service and application accounts
  • 23.10 Self-service portal creation and management of user accounts
  • 23.2 User access registration
  • 23.9 Change of cloud user's administrator details notification
  • NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization
  • NIST-CSF-PR.AA-02 Identities are proofed and bound to credentials based on the context of interactions
  • NIST-CSF-PR.AA-03 Users, services, and hardware are authenticated
  • NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties

SOC 2 · 4 controls

  • SOC2-CC6.1 CC6.1 Logical access security over protected information assets
  • SOC2-CC6.2 CC6.2 Registering and authorising users before issuing credentials
  • SOC2-CC6.3 CC6.3 Role-based access, least privilege and segregation of duties
  • SOC2-P5.1 P5.1 Data subject access
  • ISM-0407 Secure record of user access authorisations
  • ISM-0414 Unique identification of system users
  • ISM-0415 Controlling shared user accounts

NIST SP 800-171 Rev 3 · 3 controls

UK Cyber Essentials · 3 controls

  • CE-AC.1 User Account Approval Process
  • CE-AC.2 Authenticate Users Before Granting Access
  • CE-AC.3 Remove or Disable Accounts When No Longer Required
  • ANSSI-HYG-06 Organise Joiner, Leaver and Role Change Procedures
  • ANSSI-HYG-08 Identify Each Person by Name and Separate User and Administrator Roles
  • MYHR-REG-11 Ensuring required information is given to the System Operator
  • MYHR-SEC-2 Access controls and user account management

C5 (Germany) · 2 controls

  • C5-IDM-01 Policy for user accounts and access rights
  • C5-IDM-02 Granting and change of user accounts and access rights

HIPAA Security Rule · 2 controls

NIST SP 800-207 · 2 controls

NIST SP 800-66 Rev 2 · 2 controls

  • E8-ADMIN-ML1 Restrict Administrative Privileges (ML1)
  • AUCDR-IS-1 Limit risk of unauthorised access to the CDR data environment
  • AESCSF-IAM-1 Identity management

DORA · 1 control

ISO 27001:2022 · 1 control

  • 5.16 Identity management

ISO 27701:2019 · 1 control

  • 6.6.2 User access management

NIS2 Directive · 1 control

  • Art.21.2.i Human resources security, access control policies and asset management
  • 16.1.30.C.01 16.1.30.C.01 Risk assessment of centralised access management and SSO
  • P1-5.2.2 P1-5.2.2 Unique account ID per individual
  • 0134 0134 Unique identification, authentication and authorisation for classified systems

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Organizational controls – ISO 27002:2022

You are reading one control. How much of ISO 27002:2022 have you already done?

ISO 27002:2022 5.16 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 125 it maps to, and the evidence behind each claim, over MCP and REST.