Home / Rules / ISO/IEC 27001:2022 / ISO/IEC 27001:2022 Annex A 5.18 Access rights
ISO/IEC 27001:2022 Annex A 5.18 Access rights
Access rights to information and associated assets are to be granted, reviewed, changed and withdrawn in line with the access control rules and policy the organization has set. Purpose (stated in ISO/IEC 27002:2022): keeps access to information and assets defined and approved against what the business needs.
Steps that cite it
- KC-01 S6 Decide the vendor's access
- KC-08 S1 Find the leaver exceptions
- KC-08 S3 Fix the still-open access
Evidence commonly asked for
- Statement of Applicability entry for control A.5.18, showing inclusion or justified exclusion, implementation status and the risks it treats
- Access request records showing owner authorization, and management approval where required, before rights were activated
- A central record of access rights per user identifier across logical and physical access
- Periodic access review records including privileged access, with evidence that removals identified in the review were actioned
Accepted citation forms are listed on the answer format page.