Identities are to be managed throughout their whole life cycle. Purpose: make it possible to identify each person and system that accesses the organization's information and assets uniquely, and to assign access rights properly. Guidance: identity processes should ensure that an identity issued to a person is tied to that one person so they can be held accountable; that identities used by several people (shared identities) are allowed only where the business or operations genuinely need them, each with its own approval, and documented; that identities for non-human entities go through appropriately segregated approval and are independently overseen on an ongoing basis; that identities are disabled or removed promptly once no longer needed, for example when the entity is retired or the person leaves or changes role; that within a given domain each entity has only one identity so duplicates are avoided; and that records are kept of all significant events in the use and management of identities and authentication information. A supporting process handles changes to identity information and may include re-checking trusted documents about a person. Where third-party identities are accepted (for example social media logins), the organization confirms they give the trust level required and that the associated risks are understood and treated, including through supplier controls (5.19) and authentication information controls (5.17). Other information: granting or withdrawing access typically involves confirming the business need for an identity, verifying the entity before assigning a logical identity, creating it, configuring and activating it together with its authentication services, and then granting or revoking specific rights based on authorization decisions (5.18).
This control maps to 125 controls across 35 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
You are reading one control. How much of ISO 27002:2022 have you already done?
ISO 27002:2022 5.16 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.