ISO 27002:2022
Organizational controls – ISO 27002:2022

ISO 27002:2022 5.18: Access rights

Granting, reviewing, changing and withdrawing access rights to information and associated assets is to comply with the rules and the access control policy of the organization. Purpose: keep access to information and assets defined and approved in line with business needs. Guidance on provisioning and revocation of physical and logical rights attached to an authenticated identity: get the asset owner's authorization (5.9), with separate management approval where suitable; weigh business need and the access control policy; apply segregation, keeping approval apart from implementation and conflicting roles apart; withdraw rights when no longer needed and promptly for leavers; consider time-limited access that expires automatically, especially for temporary staff or temporary needs; check the level granted fits the policy (5.15) and other requirements such as segregation of duties (5.3); activate rights, including by service providers, only after authorization is complete; keep a central record of rights held by each user identifier; change rights when people change job; remove or adjust rights by revoking or replacing keys, credentials, ID cards or subscriptions; and log every change to logical and physical rights. Reviews should regularly look at rights after internal moves (promotion, demotion, job change) or employment end (6.1 to 6.5) and at privileged authorizations. Before a change or termination, rights are reviewed and reduced or removed based on risk: who initiated it and why, the person's current duties and the value of what they can reach. Other information: role-based access profiles make requests and reviews easier; contracts can set sanctions for attempted unauthorized access (see 5.20 and 6.2, 6.4 and 6.6); people dismissed or resigning may sabotage systems or gather information; copying one user's access to another (cloning) is convenient but should be based on defined roles, since it tends to grant excess rights.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 112 controls across 33 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

FedRAMP High · 13 controls

  • AC-2 Account Management
  • AC-2(1) Automated System Account Management
  • AC-2(13) Disable Accounts for High-Risk Individuals
  • AC-2(2) Automated Temporary and Emergency Account Management
  • AC-2(3) Disable Accounts
  • AC-2(5) Inactivity Logout
  • AC-2(7) Privileged User Accounts
  • AC-2(9) Restrictions on Use of Shared and Group Accounts
  • AC-6 Least Privilege
  • AC-6(7) Review of User Privileges
  • CM-12 Information Location (CM-12)
  • IA-5(2) Public Key-Based Authentication
  • PS-5 Personnel Transfer

FedRAMP Moderate · 13 controls

  • AC-2 Account Management
  • AC-2(1) Automated System Account Management
  • AC-2(13) Disable Accounts for High-Risk Individuals
  • AC-2(2) Automated Temporary and Emergency Account Management
  • AC-2(3) Disable Accounts
  • AC-2(5) Inactivity Logout
  • AC-2(7) Privileged User Accounts
  • AC-2(9) Restrictions on Use of Shared and Group Accounts
  • AC-6 Least Privilege
  • AC-6(7) Review of User Privileges
  • CM-12 Information Location (CM-12)
  • IA-5(2) Public Key-Based Authentication
  • PS-5 Personnel Transfer

PCI DSS 4.0 · 11 controls

  • 3.5.1.2 3.5.1.2 Disk or partition encryption only on removable media
  • 7.2.2 7.2.2 User access assigned by job function and least privilege
  • 7.2.3 7.2.3 Privileges approved by authorized personnel
  • 7.2.5.1 7.2.5.1 Application and system account access reviewed periodically
  • 7.3.2 7.3.2 Access control system enforces role-based permissions
  • 8.2.4 8.2.4 User ID lifecycle changes authorized
  • 8.2.5 8.2.5 Terminated users' access revoked immediately
  • 9.4.1 9.4.1 Physical security of all media
  • 3.6.1 3.6.1 Procedures protect keys against disclosure and misuse
  • 7.2.4 7.2.4 User accounts and privileges reviewed every six months
  • 7.2.5 7.2.5 Application and system accounts least privilege

NIST SP 800-53 Rev 5 · 8 controls

CIS Controls v8 · 6 controls

  • CIS-12.5 Centralize Network Authentication, Authorization, and Auditing (AAA)
  • CIS-5.3 Disable Dormant Accounts
  • CIS-6.1 Establish an Access Granting Process
  • CIS-6.2 Establish an Access Revoking Process
  • CIS-6.7 Centralize Access Control
  • CIS-6.8 Define and Maintain Role-Based Access Control

ACSC Essential Eight · 4 controls

  • E8-ADMIN-ML2 Restrict Administrative Privileges (ML2)
  • E8-ADMIN-ISM-1507 Restrict administrative privileges (ISM-1507): Requests for privileged access to systems, applications and data repositories are validated when first requested
  • E8-ADMIN-ISM-1647 Restrict administrative privileges (ISM-1647): Privileged access to systems, applications and data repositories is disabled after 12 months unless revalidated
  • E8-ADMIN-ISM-1648 Restrict administrative privileges (ISM-1648): Privileged access to systems and applications is disabled after 45 days of inactivity
  • ASBv3-PA-4 Review and reconcile user access regularly
  • ASBv3-PA-5 Set up emergency access
  • PA-2 Avoid standing access for user accounts and permissions
  • PA-3 Manage lifecycle of identities and entitlements

C5 (Germany) · 4 controls

  • C5-IDM-02 Granting and change of user accounts and access rights
  • C5-IDM-03 Locking and withdrawal of user accounts in the event of inactivity or multiple failed logins
  • C5-IDM-04 Withdraw or adjust access rights as the task area changes
  • C5-IDM-05 Regular review of access rights

HIPAA Security Rule · 4 controls

NIST SP 800-66 Rev 2 · 4 controls

SOC 2 · 4 controls

  • SOC2-CC6.1 CC6.1 Logical access security over protected information assets
  • SOC2-CC6.2 CC6.2 Registering and authorising users before issuing credentials
  • SOC2-CC6.3 CC6.3 Role-based access, least privilege and segregation of duties
  • SOC2-P5.1 P5.1 Data subject access

UK Cyber Essentials · 4 controls

  • CE-AC.1 User Account Approval Process
  • CE-AC.3 Remove or Disable Accounts When No Longer Required
  • CE-AC.4 Privileged Account Approval and Tracking
  • CE-AC.6 Periodic Review of Privileged Access
  • ANSSI-HYG-05 Maintain an Exhaustive Inventory of Privileged Accounts
  • ANSSI-HYG-06 Organise Joiner, Leaver and Role Change Procedures
  • ANSSI-HYG-09 Assign the Correct Rights on Sensitive Resources
  • ISM-0405 Validating unprivileged access requests
  • ISM-0430 Same-day removal of access
  • ISM-1404 Disabling unprivileged access after 45 days inactivity

NIST SP 800-171 Rev 3 · 3 controls

CMMC 2.0 · 2 controls

  • B.5.2 B.5.2 Implementing entry and access control systems
  • ASD37-18 Restrict administrative privileges (Essential)
  • AUCDR-IS-1 Limit risk of unauthorised access to the CDR data environment
  • MYHR-SEC-2 Access controls and user account management

DORA · 1 control

ISO 27001:2022 · 1 control

ISO 27701:2019 · 1 control

  • 6.6.2 User access management

MTCS (Singapore) · 1 control

  • 22.4 Administrator access review and revocation

NIS2 Directive · 1 control

  • Art.21.2.i Human resources security, access control policies and asset management
  • NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties

NY DFS 23 NYCRR 500 · 1 control

  • §500.7 Access Privileges and Management
  • 0186 0186 Withdraw access on separation or transfer

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Organizational controls – ISO 27002:2022

You are reading one control. How much of ISO 27002:2022 have you already done?

ISO 27002:2022 5.18 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 112 it maps to, and the evidence behind each claim, over MCP and REST.