ISO27001:2022 – A5.32 – Intellectual property rights
Introduction to ISO 27001 – A5.32
ISO 27001 – A5.32 works closely with Annex A5.31 – Identification of legal, statutory, regulatory and contractual requirements. While A5.31 helps you identify those requirements, ISO 27001 – A5.32 ensures you actively protect intellectual property (IP)—both your own and that of others.
What does ISO 27001 – A5.32 require?
“The organisation shall implement appropriate procedures to protect intellectual property rights.”
(ISO 27001 – A5.32 – Intellectual property rights)
Why is this required?
Your organisation invests heavily in software, data, designs, and other valuable ideas. If left unprotected, these assets can be copied or stolen—resulting in:
- Loss of competitive advantage
- Reputational damage
- Financial losses and potential legal action
We’ve seen firsthand the damage this can cause. A client once lost their market lead after a developer uploaded proprietary code to an online forum, where it was copied by a competitor. A costly mistake, and a preventable one.
What the auditor is looking for
The auditor will expect to see:
- Reference to IP protection in your legal register
- Contract clauses covering IP ownership for staff, contractors, and suppliers
- Evidence of software licence audits—to ensure you’re respecting others’ IP
- Internal policies that address acceptable use, classification, and access control of IP
What do you need to do?
- Update your legal register to reference IP-related clauses and obligations.
- Review and update contracts to clearly define ownership and permitted use of IP.
- Enhance your Information Classification Scheme (see A5.12) to include IP as a distinct category—classify as ‘Confidential’ or higher.
- Restrict access to IP based on the ‘need to know’ principle (see A5.15 – Access Control).
- Update your Acceptable Use Policy (see A5.10) to include guidance on handling your organisation’s IP and respecting others’ IP (e.g. copyright on images or licensed content).
- Conduct a software audit to verify licence compliance and remove unauthorised or unlicensed apps.
Key reminder
Remember: IP isn’t just source code or patented ideas. It includes customer lists, internal pricing models, supplier contracts, and any information that gives you a market edge.
Q & A
What types of IP should we protect?
Common examples include:
- Source code, software, and databases
- Marketing and design materials
- Customer and supplier data
- Creative content such as reports, graphics, and internal tools
- Pricing models, business strategies, and proprietary methodologies
What about third-party IP?
You must also protect intellectual property owned by others. For example, don’t use unlicensed images, software, or text in your documents or websites. Maintain records of licences and usage rights.
Difficulty Rating
2 out of 5 – This control requires contract and policy review more than technical expertise, but it touches on several other ISO27001 controls such as A5.10, A5.12, and A5.15. Keeping it coordinated is key.
More Questions?
Remember, ISO27001 is an interconnected system. Controls support each other, and protecting IP ensures that your business remains legally compliant, competitive, and trustworthy. Still unsure? Reach out or check out our FAQ.
We are ISO 27001 Consultants who provide ‘Compliance without Complexity’® and we know we can help you… we even wrote a book about it. For more information on how to implement ISO 27001, written by ISO 27001 consultants like us, you should buy our book… “The Real Easy Guide to ISO27001” (available on Amazon) a great companion on your compliance journey.
