ISO27001:2022 – A5.18

Access rights

Introduction to ISO 27001 – A5.18

Didn’t we already cover this in A5.15 (Access Control)? Sort of! While the two controls are closely related, ISO 27001 – A5.18 specifically focuses on the life cycle of access rights — how they are provisioned, reviewed, modified, and removed. It complements the broader access control framework established earlier.

What does the standard require?

The standard states:

“Access rights to information and other associated assets shall be provisioned, reviewed, modified and removed in accordance with the organisation’s topic-specific policy on, and rules for access control.” (ISO 27001 – A5.18 – Access Rights)

Why is this required?

If someone changes roles — say from Marketing to Finance to Operations — their old access rights may no longer be appropriate. Without a controlled process to update or revoke access, they could retain rights to systems or data they no longer need, creating security and confidentiality risks.

This isn’t about not trusting people, but imagine for a moment that someone has access to all the systems across your business, just because they’ve worked there a long time.  Now imagine that their accounts are compromised, and someone now has access to your systems, using THEIR identification.  An attacker won’t need to do anything too sophisticated, because they now have all the keys to your kingdom!  Opening any door, any system and any accessing any data they want… all because you didn’t turn off that persons access to systems which they no longer need.

And here’s another reason to check access… It could SAVE YOU MONEY!  Think about it… Are people accessing systems they don’t need, and using a licence that could be given to another user?  

This is why ISO 27001 talks about identifying ‘Risk and opportunities’…. Yes there are risks to allowing people to have access to more systems than they need, but there are also opportunities to save money too.

 

What the auditor is looking for

If you’ve implemented the controls required in A5.15, you’re already most of the way there. However, A5.18 adds a key focus: life cycle management of access rights.

The auditor will want to see that access rights are:

  • Provisioned: Access granted based on job role and business need
  • Reviewed: Periodic review of access rights to ensure ongoing appropriateness
  • Modified: Updated as job responsibilities change
  • Removed: Revoked when access is no longer needed (e.g. upon termination)

You should be able to show that access audits are conducted — even if informally — and be prepared to explain how frequently these are carried out. Smaller organisations may do this annually; larger or dynamic ones might require quarterly or even monthly reviews.

Q & A

Do I need a written policy?

No separate policy is needed, but this control should be clearly supported by your existing Access Control Policy.

Is it possible to get this wrong?

Yes. If you can’t show that access rights are reviewed and maintained regularly, this could result in a minor non-conformity. Make sure to include access rights reviews in your internal audit or governance programme.

Difficulty rating

We rate this control a 1 out of 5. It doesn’t require technical expertise — just awareness, documentation, and consistency. You simply need to schedule access rights reviews and maintain a record of who has access to what, why, and when it was last checked.

More questions?

As with all ISO27001 controls, this one connects to others like A5.15 (Access Control), A6.5 (Termination or change of employment responsibilities), and A6.3 (Security awareness). Check our FAQ or contact us directly for support.

 We are ISO 27001 Consultants who provide ‘Compliance without Complexity’® and we know we can help you… we even wrote a book about it. For more information on how to implement ISO 27001, written by ISO 27001 consultants like us, you should buy our book… “The Real Easy Guide to ISO27001”, available on Amazon.

ISO 27001 – A5.18