FORM AWT-1 · AGENT CHECK SHEET · LIBRARY 1.0SCORER 1.0.0 · 8 PUBLIC SCENARIOS · SPECIMEN DATA
AI Agent Compliance Workflow Tester

Home / Rules / ISO/IEC 27001:2022 / ISO/IEC 27001:2022 Annex A 5.18 Access rights

ISO/IEC 27001:2022 Annex A 5.18 Access rights

Access rights to information and associated assets are to be granted, reviewed, changed and withdrawn in line with the access control rules and policy the organization has set. Purpose (stated in ISO/IEC 27002:2022): keeps access to information and assets defined and approved against what the business needs.

ISO/IEC 27001:2022. Edition: ISO/IEC 27001:2022 (third edition, October 2022) with Amendment 1:2024. Checked 2026-10-07. Our statement of the clause, cited; the standard is licensed and not quoted. Official source. The framework on compliance.theartofservice.com.

Steps that cite it

Evidence commonly asked for

Accepted citation forms are listed on the answer format page.