Granting, reviewing, changing and withdrawing access rights to information and associated assets is to comply with the rules and the access control policy of the organization. Purpose: keep access to information and assets defined and approved in line with business needs. Guidance on provisioning and revocation of physical and logical rights attached to an authenticated identity: get the asset owner's authorization (5.9), with separate management approval where suitable; weigh business need and the access control policy; apply segregation, keeping approval apart from implementation and conflicting roles apart; withdraw rights when no longer needed and promptly for leavers; consider time-limited access that expires automatically, especially for temporary staff or temporary needs; check the level granted fits the policy (5.15) and other requirements such as segregation of duties (5.3); activate rights, including by service providers, only after authorization is complete; keep a central record of rights held by each user identifier; change rights when people change job; remove or adjust rights by revoking or replacing keys, credentials, ID cards or subscriptions; and log every change to logical and physical rights. Reviews should regularly look at rights after internal moves (promotion, demotion, job change) or employment end (6.1 to 6.5) and at privileged authorizations. Before a change or termination, rights are reviewed and reduced or removed based on risk: who initiated it and why, the person's current duties and the value of what they can reach. Other information: role-based access profiles make requests and reviews easier; contracts can set sanctions for attempted unauthorized access (see 5.20 and 6.2, 6.4 and 6.6); people dismissed or resigning may sabotage systems or gather information; copying one user's access to another (cloning) is convenient but should be based on defined roles, since it tends to grant excess rights.
This control maps to 112 controls across 33 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
E8-ADMIN-ISM-1507 Restrict administrative privileges (ISM-1507): Requests for privileged access to systems, applications and data repositories are validated when first requested
E8-ADMIN-ISM-1647 Restrict administrative privileges (ISM-1647): Privileged access to systems, applications and data repositories is disabled after 12 months unless revalidated
E8-ADMIN-ISM-1648 Restrict administrative privileges (ISM-1648): Privileged access to systems and applications is disabled after 45 days of inactivity
NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
You are reading one control. How much of ISO 27002:2022 have you already done?
ISO 27002:2022 5.18 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.