ISO 27018:2019
Access control – ISO 27018:2019

ISO 27018:2019 9.2: User access management

Guidance that ISO/IEC 27018:2019 applies to every control under ISO/IEC 27002:2013 objective 9.2. Depending on the service category, the cloud service customer may handle some or all access management for the cloud service users it controls; where appropriate the processor equips the customer to manage their access, for example by giving it administrative rights to change or end that access.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 5 controls across 5 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27017:2015 · 1 control

  • 9.2 User access management

ISO 27701:2019 · 1 control

  • 6.6.2 User access management

ISO/IEC 27043:2015 · 1 control

  • ISO27043-12 User access management and provisioning

ISO/SAE 21434 · 1 control

  • ISO21434-12 User access management and provisioning

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Access control – ISO 27018:2019

Query this from an agent

The graph holds this control, the 5 it maps to, and the evidence behind each claim, over MCP and REST.