ISO27001:2022 – A5.16
Identity management
Introduction to ISO 27001 – A5.16
ISO27001 often includes controls that sound technical, but are actually quite simple once you understand their intent. ISO 27001 – A5.16 is a good example — it focuses on something that seems obvious, but is critically important.
What does ISO 27001 – A5.16 require?
The standard states that:
“The full life cycle of identities should be managed.” (ISO 27001 – A5.16 – Identity Management)
In this context, “identities” refers to both people and systems that access your physical or digital assets.
Why is this required?
If everyone shares the same login details, you lose all traceability. For example, in Annex A8.15 (Logging), you’ll need to track activity — but that’s impossible if multiple users share one identity.
One real-world example involved a company that lost 65,000 customer records. Initially, it looked like an external cyberattack. However, all 80 employees used the same login credentials for the CRM system. This made internal investigation difficult and raised suspicion across the whole team. Eventually, CCTV and access logs revealed it was a disgruntled employee — but this could have been avoided with proper identity management.
Additionally, shared login details may violate software license agreements (e.g. “per seat” licensing), putting your business at legal and contractual risk — which in turn violates ISO27001 requirements.
What the auditor is looking for
While a written identity management policy is not required, the auditor will want to see how identity lifecycle is handled — especially:
- How new user IDs are issued (e.g. during onboarding)
- How user IDs are deactivated (e.g. during offboarding)
- That credentials (usernames/passwords) are never shared
You should be able to show your onboarding process includes ID creation (e.g. email accounts, system logins), and that your leaver process includes timely account deactivation.
Q & A
Do I need a written policy?
No — a documented policy is not required. However, you must be able to clearly explain and demonstrate:
- How accounts are issued
- How they are monitored
- How they are revoked
Is it possible to get this wrong?
Yes. Sharing login credentials is a clear violation — of ISO27001, your own system security, and possibly your software license terms. Avoid it entirely.
Difficulty rating
We rate this a 1 out of 5. It requires minimal technical skill. You simply need to define who is responsible for allocating and deactivating identities and ensure software licenses are used correctly.
More questions?
As always, ISO27001 controls are interconnected. Review our FAQs and cross-referenced controls (e.g. A6.1, A6.5, A8.15) for deeper understanding. If you need help implementing identity management or RBAC practices, contact us — we’re happy to help.
We are ISO 27001 Consultants who provide ‘Compliance without Complexity’® and we know we can help you… we even wrote a book about it. For more information on how to implement ISO 27001, written by ISO 27001 consultants like us, you should buy our book…“The Real Easy Guide to ISO27001”, available on Amazon.
