ISO 27002:2022
Technological controls – ISO 27002:2022

ISO 27002:2022 8.18: Use of privileged utility programs

Utility programs able to override system and application controls are to have their use limited and tightly controlled. Purpose: prevent utility programs from undermining system and application security controls. Guidance: consider limiting such utilities to the smallest practical number of trusted, authorized users (8.2); applying identification, authentication and authorization to their use, including uniquely identifying each person using them; defining and documenting authorization levels for them; requiring authorization for one-off use; withholding them from application users on systems that depend on separated duties; removing or disabling all unneeded utilities; separating utilities logically from application software at a minimum, and where practical keeping their network traffic apart from application traffic; making them available only for limited periods, such as the duration of an authorized change; and logging every use. Other information: most systems include utilities that can bypass controls, such as diagnostic, patching, anti-virus, defragmentation, debugging, backup and network tools.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 58 controls across 26 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

FedRAMP High · 7 controls

  • AC-17(4) Privileged Commands and Access
  • AC-6(10) Prohibit Non-Privileged Users from Executing Privileged Functions
  • AC-6(9) Log Use of Privileged Functions
  • CM-7 Least Functionality
  • CM-7(2) Prevent Program Execution
  • MA-3 Maintenance Tools (MA-3)
  • MA-3(1) Maintenance Tools | Inspect Tools (MA-3(1))

FedRAMP Moderate · 7 controls

  • AC-17(4) Privileged Commands and Access
  • AC-6(10) Prohibit Non-Privileged Users from Executing Privileged Functions
  • AC-6(9) Log Use of Privileged Functions
  • CM-7 Least Functionality
  • CM-7(2) Prevent Program Execution
  • MA-3 Maintenance Tools (MA-3)
  • MA-3(1) Maintenance Tools | Inspect Tools (MA-3(1))

NIST SP 800-53 Rev 5 · 5 controls

SOC 2 · 5 controls

  • SOC2-CC5.1 CC5.1 Selecting control activities that mitigate risk (COSO principle 10)
  • SOC2-CC5.2 CC5.2 General controls over technology (COSO principle 11)
  • SOC2-CC6.1 CC6.1 Logical access security over protected information assets
  • SOC2-CC6.3 CC6.3 Role-based access, least privilege and segregation of duties
  • SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities
  • NIST-CSF-DE.CM-03 Personnel activity and technology usage are monitored to find potentially adverse events
  • NIST-CSF-DE.CM-09 Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events
  • NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
  • NIST-CSF-PR.PS-05 Installation and execution of unauthorized software are prevented
  • ISM-1491 Blocking script execution engines for unprivileged users
  • ISM-1584 Preventing users bypassing operating system security
  • ISM-1622 PowerShell Constrained Language Mode

NIST SP 800-171 Rev 3 · 3 controls

  • 03.01.07 Least Privilege - Privileged Functions
  • 03.04.06 Least Functionality
  • 03.04.08 Authorized Software - Allow by Exception

ACSC Essential Eight · 2 controls

  • E8-ADMIN-ML1 Restrict Administrative Privileges (ML1)
  • E8-APP-ML1 Application Control (ML1)
  • ASD37-01 Application control (Essential)
  • ASD37-18 Restrict administrative privileges (Essential)
  • ASBv3-AM-5 Use only approved applications in virtual machine
  • ASBv3-PA-7 Follow just enough administration (least privilege) principle

CIS Controls v8 · 2 controls

  • CIS-2.5 Allowlist Authorized Software
  • CIS-5.4 Restrict Administrator Privileges to Dedicated Administrator Accounts
  • ANSSI-HYG-29 Limit Administration Rights on Workstations to Operational Need
  • SEC06-BP03 Reduce manual management and interactive access
  • AUCDR-IS-5 Limit, prevent, detect and remove malware

C5 (Germany) · 1 control

CMMC 2.0 · 1 control

ETSI EN 303 645 · 1 control

ISO 19011:2018 · 1 control

  • 5.4.1 Roles and responsibilities of the individual(s) managing the audit programme

ISO 27001:2022 · 1 control

  • 8.18 Use of privileged utility programs

ISO 27018:2019 · 1 control

  • 9.4.4 Use of privileged utility programs

MTCS (Singapore) · 1 control

  • 14.6 Restrictions to system utilities

NIST SP 800-172 · 1 control

  • 3.13.2e Introduce Unpredictability into System Operations

PCI DSS 4.0 · 1 control

  • 9.4.4 9.4.4 Management approval for media leaving facility

UK Cyber Essentials · 1 control

  • CE-AC.5 Separate Admin Accounts for Administrative Activities

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Technological controls – ISO 27002:2022

You are reading one control. How much of ISO 27002:2022 have you already done?

ISO 27002:2022 8.18 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 58 it maps to, and the evidence behind each claim, over MCP and REST.