ISO 27001A.5 — Access rights
A.5.18
Access rights
ISO 27001 · ISO/IEC 27001:2022 · Last verified July 2026
Objective
Provision, review, modify, and remove access rights according to topic policy and business needs.
Points of focus
- Request and approval workflow
- Periodic access reviews
- Modification on role change
- Timely removal on exit
Implementation notes
Drive grants from IdP groups mapped to job functions. Require ticketed approval for production and customer-data roles. Run scheduled reviews with mandatory outcomes. Automate movers from HRIS where possible. Align with A.5.15 policy and A.8.2 privileged paths; reuse SOC 2 CC6.2/CC6.3 evidence.
Audit tip: Provide one joiner, one mover, and one leaver packet with timestamps.
Evidence auditors typically request:
- Access request tickets with approver
- Quarterly review packets
- Mover workflow samples
- Leaver revocation SLA metrics
Common gaps
- Standing broad roles never trimmed
- Reviews rubber-stamped without removals
- Role changes without access delta
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| ISO 27001 | A.5.18 | This control |
| SOC 2 | CC6.2, CC6.3 | Related Trust Services Criteria themes — map in your crosswalk; not identical requirements. |
| GDPR | Article 32 | Related GDPR articles for personal-data security or processor themes — not a compliance claim. |
Primary sources
- ISO/IEC 27001:2022 Annex A: ISO/IEC 27001:2022 Annex A (A.5.18)
Frequently Asked Questions
A.5.15 sets access control rules; A.5.18 is the lifecycle of rights under those rules.
Include them in inventory, owners, and reviews — not only human users.
Quarterly is common for SaaS; increase for privileged and production-data roles.