Skip to content
compliancebase
ISO 27001A.8 — Use of privileged utility programs

A.8.18

Use of privileged utility programs

ISO 27001 · ISO/IEC 27001:2022 · Last verified August 2026

Objective

Restrict and control use of utility programs that can override system and application controls.

Points of focus

  • Inventory privileged utilities
  • Restrict installation and execution
  • Log use
  • Separate from normal admin paths where needed

Implementation notes

Remove unnecessary compilers/debuggers from production images. Gate cloud CLIs via SSO roles. Use temporary elevation for powerful tools. Prefer audited admin paths over shared bastions with unconstrained binaries.

Audit tip: Show production image hardening and who can invoke break-glass utilities with logs.

Evidence auditors typically request:

  • Privileged utility inventory
  • Endpoint/application allowlists
  • Production access jump host controls
  • Session logs for privileged tools

Common gaps

  • Unrestricted kubectl/admin CLIs on all laptops
  • No logging of break-glass utilities
  • Debug tools left on production images

Cross-Framework Mapping

FrameworkRequirementImplementation note
ISO 27001A.8.18This control
SOC 2CC6.1, CC6.2Related SOC 2 themes (CC6.1, CC6.2) — map in your crosswalk; not identical requirements.

Primary sources

Frequently Asked Questions

Focus on tools that bypass controls; manage package install via A.8.19.

Control production execution paths more tightly than local IDEs.

Privileged access monitoring under CC6/CC7 themes.

Even without owned data centers, use of privileged utility programs still applies to how you operate endpoints, IdP, cloud consoles, and vendor services in scope. Exclude controls in the SoA only with a documented, risk-based rationale.

Start with privileged utility inventory, assign a named control owner, and retain dated samples from your ticketing or GRC system — not one-off screenshots assembled before audit fieldwork.

Framework versions referenced in this page:

  • ISO/IEC 27001ISO/IEC 27001:2022

Last verified: August 2026 · Primary sources linked above