ISO27001:2022 – A8.18

Use of privileged utility programs

Want to fast track your ISO 27001 journey? 

Our “ISO 27001:2022 Policy Pack” gives you everything you need to comply with this, and all ISO 27001 requirements. Take a look, and when you buy it, you also receive our “Real Easy Guide To ISO27001” book (available on Amazon).

Introduction to ISO 27001 – A8.18

ISO27001 requires you to manage not only what people can access, but also how privileged utility programs can be used.  But what exactly is meant by utility programs? 

What does ISO 27001 – A8.18 require?

The standard states that “The use of utility programs that can be capable of overriding system and application controls shall be restricted and tightly controlled.” (A8.18 – Use of privileged utility programs)

For this ISO27001 control, keep in mind that utility programs can include any software tools which perform maintenance or management of your systems.

These can include.

  • Antivirus and malware protection software.
  • Disk de-fragmentation tools.
  • System diagnostics tools.
  • Backup and restore software.
  • Debuggers (used for troubleshooting software code).
  • Network management and monitoring tools (e.g. Intrusion Detection and Prevention Tools).

Why is this required?

This ISO27001 control aims to ensure that you control utility programs to prevent them from causing harm to the systems and applications used in your business.

These utility programs require low-level access to the infrastructure they are in place to manage. Therefore, they have the potential to cause significant damage to the infrastructure, which could lead to data breaches or outages.

They have privileged access because they carry out actions and activities which have the potential to change how your operation operates, and therefore could affect how your business operates. Accidental damage or deliberate actions, when using these tools, can have a significant and far-reaching impact on your business, making recovery difficult. That’s why it is important to have tight control over their use.

What the auditor is looking for

For this ISO27001 control, the auditor will expect to see a variety of security measures that might include;

What do you need to do?

Consult your IT team to understand the types of utility programs used in your business. Refer to the list provided above as a starting point, and determine what other kinds of utility programs are used.  

The purpose of this ISO27001 control is to ensure that you control the use of these tools, so you must review the access rights for the tools and restrict their use to a ‘needs only’ basis. This principle is known as ‘least privilege’ access. For example, if you develop code, not everyone will need access to debugging software. Not everyone will need access to your system monitoring tools and applications, so restrict this to the people who need access.

If you find that there are no controls in place, and people can make changes as they see fit, then this needs to be addressed through your risk management process and discussed with your Management Review Team (MRT).

Difficulty rating

We rate this a 1.5 out of 5 difficulty rating. There’s not much to this control except for you to identify and appropriately control the utility programmes in use.

Q&A

Do I need a policy?

No, you don’t need a topic-specific policy, but you might look to include reference to utility programs in your access control policy, or acceptable use policy. What you need to do is evidence that you have identified utility programs used in your business, and that you have considered who has permission to use them.  Reviewing access rights and access allocation can provide evidence for this. role-based access control) processes.

More questions?

We are ISO 27001 Consultants who provide ‘Compliance without Complexity’® and we know we can help you… we even wrote a book about it. For more information on how to implement ISO 27001, written by ISO 27001 consultants like us, you should buy our book… “The Real Easy Guide to ISO27001” which is available on Amazon.

Fastback your journey to ISO27001 and buy our Policies to get started TODAY!

Take a look at our “ISO 27001:2022 Policy Pack” and when coupled with our book you’ll have everything you need to succeed in achieving ISO 27001 certification!

ISO 27001 – A8.18 - Use of privileged utility programs