ISO 27701:2019
PIMS-specific guidance related to ISO/IEC 27002, ISO 27701:2019

ISO 27701:2019 6.6.2: User access management

User registration and deregistration for people who administer or operate systems processing personal data must address compromise of their access credentials, deactivated or expired user identifiers must never be reissued for those systems, and the organization must keep an accurate current record of authorised user profiles so that access to personal data and any additions, deletions or changes can be attributed to a person; where the organization processes personal data as a service, any customer responsibility for identity or access management must be documented and the means to exercise it provided.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 126 controls across 24 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

PCI DSS 4.0 · 26 controls

  • 10.3.1 10.3.1 Audit log read access limited to job need
  • 12.2.1 12.2.1 Rules for acceptable use of end-user technology
  • 7.2.2 7.2.2 User access assigned by job function and least privilege
  • 7.2.3 7.2.3 Privileges approved by authorized personnel
  • 7.2.5.1 7.2.5.1 Application and system account access reviewed periodically
  • 7.3.2 7.3.2 Access control system enforces role-based permissions
  • 8.2.1 8.2.1 Unique ID assigned to every user
  • 8.2.2 8.2.2 Shared and generic IDs only by exception
  • 8.2.4 8.2.4 User ID lifecycle changes authorized
  • 8.2.5 8.2.5 Terminated users' access revoked immediately
  • 8.2.6 8.2.6 Inactive accounts removed within 90 days
  • 8.2.7 8.2.7 Third-party remote access accounts controlled
  • 8.3.1 8.3.1 Access authenticated with at least one factor
  • 8.3.11 8.3.11 Tokens, smart cards and certificates individually assigned
  • 8.3.4 8.3.4 Lockout after 10 attempts for 30 minutes
  • 8.3.9 8.3.9 Single-factor passwords changed every 90 days or dynamic analysis
  • 8.4.2 8.4.2 MFA for all non-console CDE access
  • 8.5.1 8.5.1 MFA system resistant to replay and bypass
  • 9.2.3 9.2.3 Physical protection of network hardware and lines
  • 9.4.1 9.4.1 Physical security of all media
  • 9.4.4 9.4.4 Management approval for media leaving facility
  • 6.5.4 6.5.4 Separate roles between production and pre-production
  • 7.2.4 7.2.4 User accounts and privileges reviewed every six months
  • 7.2.5 7.2.5 Application and system accounts least privilege
  • 7.3.1 7.3.1 Need-to-know access control system covers all components
  • 8.6.3 8.6.3 System account passwords protected against misuse

NIST SP 800-53 Rev 5 · 13 controls

CIS Controls v8 · 12 controls

  • CIS-12.7 Ensure Remote Devices Utilize a VPN and are Connecting to an Enterprise’s AAA Infrastructure
  • CIS-13.5 Manage Access Control for Remote Assets
  • CIS-3.3 Configure Data Access Control Lists
  • CIS-5.1 Establish and Maintain an Inventory of Accounts
  • CIS-5.3 Disable Dormant Accounts
  • CIS-5.4 Restrict Administrator Privileges to Dedicated Administrator Accounts
  • CIS-5.5 Establish and Maintain an Inventory of Service Accounts
  • CIS-6.1 Establish an Access Granting Process
  • CIS-6.2 Establish an Access Revoking Process
  • CIS-6.3 Require MFA for Externally-Exposed Applications
  • CIS-6.5 Require MFA for Administrative Access
  • CIS-6.7 Centralize Access Control

CMMC 2.0 · 10 controls

HIPAA Security Rule · 9 controls

NIST SP 800-66 Rev 2 · 9 controls

ISO 27001:2022 · 7 controls

  • 5.15 Access control
  • 5.16 Identity management
  • 5.17 Authentication information
  • 5.18 Access rights
  • 8.2 Privileged access rights
  • 8.3 Information access restriction
  • 8.5 Secure authentication

ISO 27002:2022 · 5 controls

  • 5.16 Identity management
  • 5.18 Access rights
  • 8.2 Privileged access rights
  • 8.3 Information access restriction
  • 8.5 Secure authentication

SOC 2 · 5 controls

  • SOC2-CC6.1 CC6.1 Logical access security over protected information assets
  • SOC2-CC6.2 CC6.2 Registering and authorising users before issuing credentials
  • SOC2-CC6.3 CC6.3 Role-based access, least privilege and segregation of duties
  • SOC2-CC6.8 CC6.8 Preventing and detecting unauthorised or malicious software
  • SOC2-P5.1 P5.1 Data subject access
  • ASBv3-IM-2 Protect identity and authentication systems
  • ASBv3-PA-4 Review and reconcile user access regularly
  • IM-1 Use centralized identity and authentication system
  • PA-3 Manage lifecycle of identities and entitlements

FedRAMP High · 3 controls

  • AC-2 Account Management
  • AC-2(4) Automated Audit Actions
  • IA-4 Identifier Management

FedRAMP Moderate · 3 controls

  • AC-2 Account Management
  • AC-2(4) Automated Audit Actions
  • IA-4 Identifier Management

C5 (Germany) · 2 controls

  • C5-IDM-02 Granting and change of user accounts and access rights
  • C5-PSS-08 Roles and Rights Concept
  • NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization
  • NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties

NIST SP 800-161 Rev 1 · 2 controls

NIST SP 800-171 Rev 3 · 2 controls

  • AUCDR-IS-1 Limit risk of unauthorised access to the CDR data environment

ISO 27017:2015 · 1 control

  • 9.2 User access management

ISO 27018:2019 · 1 control

  • 9.2 User access management

ISO/IEC 27043:2015 · 1 control

  • ISO27043-12 User access management and provisioning

ISO/SAE 21434 · 1 control

  • ISO21434-12 User access management and provisioning

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in PIMS-specific guidance related to ISO/IEC 27002, ISO 27701:2019

You are reading one control. How much of ISO 27701:2019 have you already done?

ISO 27701:2019 6.6.2 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27701:2019 your existing evidence covers. Hold SOC 2 and 58 of 108 ISO 27701:2019 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 289 were rejected on the SOC 2 pair alone.

Query this from an agent

The graph holds this control, the 126 it maps to, and the evidence behind each claim, over MCP and REST.