Home / Rules / ISO/IEC 27001:2022 / ISO/IEC 27001:2022 Annex A 5.16 Identity management
ISO/IEC 27001:2022 Annex A 5.16 Identity management
Identities are to be managed throughout their whole life cycle. Purpose (stated in ISO/IEC 27002:2022): enables unique identification of people and systems accessing organizational assets and appropriate assignment of access rights.
Steps that cite it
- KC-01 S6 Decide the vendor's access
Evidence commonly asked for
- Statement of Applicability entry for control A.5.16, showing inclusion or justified exclusion, implementation status and the risks it treats
- Identity management procedure covering creation, verification, activation, change, disablement and removal
- Evidence that identities are verified against trusted documents before issue
- A register of shared identities with the business justification and approval for each
Accepted citation forms are listed on the answer format page.