ISO 27002:2022
Organizational controls – ISO 27002:2022

ISO 27002:2022 5.32: Intellectual property rights

Suitable procedures are to be put in place to protect intellectual property rights. Purpose: comply with the legal, regulatory and contractual requirements concerning intellectual property and the use of proprietary products. Guidance: to protect anything that can count as intellectual property, consider a topic-specific policy on intellectual property protection, communicated to those it concerns; publishing compliance procedures that define lawful use of software and information products; buying software only from known, reputable sources so copyright is not infringed; keeping asset registers that flag every asset with intellectual property protection needs; keeping proof of ownership of licences, manuals and similar; ensuring licence limits on users or resources such as CPUs are not exceeded; checking installations so that nothing unlicensed or unapproved is present; procedures to keep licence conditions met; procedures for getting rid of software or handing it on; respecting the conditions attached to software and content taken from public networks or other outside sources; not duplicating, converting or extracting from commercial audio or video recordings beyond what copyright law or licences allow; and not reproducing all or part of published works such as standards, books, papers or reports beyond what copyright or licences permit. Other information: intellectual property covers copyright in software and documents, designs, trade marks, patents and licences to source code; proprietary software licences commonly restrict use to named machines or limit copying to backups (see ISO/IEC 19770); data acquired from outside is normally covered by a data sharing agreement that should state permitted processing and provenance (ISO/IEC 23751); infringement can bring fines and criminal proceedings; and the risk of staff or third parties failing to respect the organization's own intellectual property should also be managed.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 10 controls across 8 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

SOC 2 · 3 controls

  • SOC2-C1.1 C1.1 Identifying and maintaining confidential information
  • SOC2-CC6.1 CC6.1 Logical access security over protected information assets
  • SOC2-CC6.3 CC6.3 Role-based access, least privilege and segregation of duties

C5 (Germany) · 1 control

  • C5-COM-01 Identification of applicable legal, regulatory, self-imposed or contractual requirements

CIS Controls v8 · 1 control

  • CIS-2.1 Establish and Maintain a Software Inventory

FedRAMP High · 1 control

  • CM-10 Software Usage Restrictions

FedRAMP Moderate · 1 control

  • CM-10 Software Usage Restrictions

ISO 27001:2022 · 1 control

  • 5.32 Intellectual property rights

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Organizational controls – ISO 27002:2022

You are reading one control. How much of ISO 27002:2022 have you already done?

ISO 27002:2022 5.32 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 10 it maps to, and the evidence behind each claim, over MCP and REST.