ISO 27001A.5 — Intellectual property rights
A.5.32
Intellectual property rights
ISO 27001 · ISO/IEC 27001:2022 · Last verified July 2026
Objective
Implement appropriate procedures to protect intellectual property rights.
Points of focus
- IP ownership and license rules for staff/contractors
- Open-source license compliance process
- Protection of proprietary source and models
- Customer content IP boundaries
Implementation notes
Clarify employee/contractor IP assignment in agreements. Run license scanning on distributed software. Train engineers on what customer content they may not reuse. Protect source repositories with access control (A.8.4 when published). Align marketing claims about models/data use with contracts.
Audit tip: Show OSS scanning in CI and a contractor agreement IP clause.
Evidence auditors typically request:
- IP / open-source policy
- Contributor license or employment IP clauses
- OSS license scan reports for releases
- Contractor agreements with IP assignment
Common gaps
- Copy-pasted code of unknown license
- Contractors without IP assignment
- Customer data treated as training fodder against contract
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| ISO 27001 | A.5.32 | This control |
Primary sources
- ISO/IEC 27001:2022 Annex A: ISO/IEC 27001:2022 Annex A (A.5.32)
Frequently Asked Questions
Legal sets rules; engineering and security implement repo access, scanning, and training evidence.
Only if relevant to your business. Focus first on copyright, licenses, and trade secrets in source/data.
Treat support attachments as customer-owned; limit retention and access.