Home / Rules / ISO/IEC 27001:2022 / ISO/IEC 27001:2022 Annex A 8.2 Privileged access rights
ISO/IEC 27001:2022 Annex A 8.2 Privileged access rights
The granting and use of privileged access rights are to be limited and managed. Purpose (stated in ISO/IEC 27002:2022): limits privileged access to authorized people, software components and services.
Steps that cite it
- KC-01 S6 Decide the vendor's access
Evidence commonly asked for
- Statement of Applicability entry for control A.8.2, showing inclusion or justified exclusion, implementation status and the risks it treats
- An inventory of privileged accounts per system (operating systems, databases, applications, cloud consoles) mapped to named individuals
- Authorization records for each privileged grant with approver, justification and expiry
- Privileged access management configuration showing time-limited elevation, step-up authentication and session recording
Accepted citation forms are listed on the answer format page.