Guidance that ISO/IEC 27018:2019 applies to every control under ISO/IEC 27002:2013 objective 9.2. Depending on the service category, the cloud service customer may handle some or all access management for the cloud service users it controls; where appropriate the processor equips the customer to manage their access, for example by giving it administrative rights to change or end that access.
This control maps to 5 controls across 5 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 5 it maps to, and the evidence behind each claim, over MCP and REST.