ISO 27002:2022 8.18: Use of privileged utility programs
Utility programs able to override system and application controls are to have their use limited and tightly controlled. Purpose: prevent utility programs from undermining system and application security controls. Guidance: consider limiting such utilities to the smallest practical number of trusted, authorized users (8.2); applying identification, authentication and authorization to their use, including uniquely identifying each person using them; defining and documenting authorization levels for them; requiring authorization for one-off use; withholding them from application users on systems that depend on separated duties; removing or disabling all unneeded utilities; separating utilities logically from application software at a minimum, and where practical keeping their network traffic apart from application traffic; making them available only for limited periods, such as the duration of an authorized change; and logging every use. Other information: most systems include utilities that can bypass controls, such as diagnostic, patching, anti-virus, defragmentation, debugging, backup and network tools.
This control maps to 58 controls across 26 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST-CSF-DE.CM-03 Personnel activity and technology usage are monitored to find potentially adverse events
NIST-CSF-DE.CM-09 Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events
NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
NIST-CSF-PR.PS-05 Installation and execution of unauthorized software are prevented
You are reading one control. How much of ISO 27002:2022 have you already done?
ISO 27002:2022 8.18 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.