Skip to content
compliancebase
ISO 27001A.5 — Access rights

A.5.18

Access rights

ISO 27001 · ISO/IEC 27001:2022 · Last verified July 2026

Objective

Provision, review, modify, and remove access rights according to topic policy and business needs.

Points of focus

  • Request and approval workflow
  • Periodic access reviews
  • Modification on role change
  • Timely removal on exit

Implementation notes

Drive grants from IdP groups mapped to job functions. Require ticketed approval for production and customer-data roles. Run scheduled reviews with mandatory outcomes. Automate movers from HRIS where possible. Align with A.5.15 policy and A.8.2 privileged paths; reuse SOC 2 CC6.2/CC6.3 evidence.

Audit tip: Provide one joiner, one mover, and one leaver packet with timestamps.

Evidence auditors typically request:

  • Access request tickets with approver
  • Quarterly review packets
  • Mover workflow samples
  • Leaver revocation SLA metrics

Common gaps

  • Standing broad roles never trimmed
  • Reviews rubber-stamped without removals
  • Role changes without access delta

Cross-Framework Mapping

FrameworkRequirementImplementation note
ISO 27001A.5.18This control
SOC 2CC6.2, CC6.3Related Trust Services Criteria themes — map in your crosswalk; not identical requirements.
GDPRArticle 32Related GDPR articles for personal-data security or processor themes — not a compliance claim.

Primary sources

Frequently Asked Questions

A.5.15 sets access control rules; A.5.18 is the lifecycle of rights under those rules.

Include them in inventory, owners, and reviews — not only human users.

Quarterly is common for SaaS; increase for privileged and production-data roles.

Framework versions referenced in this page:

  • ISO/IEC 27001ISO/IEC 27001:2022

Last verified: July 2026 · Primary sources linked above