ISO 27001A.8 — Use of privileged utility programs
A.8.18
Use of privileged utility programs
ISO 27001 · ISO/IEC 27001:2022 · Last verified August 2026
Objective
Restrict and control use of utility programs that can override system and application controls.
Points of focus
- Inventory privileged utilities
- Restrict installation and execution
- Log use
- Separate from normal admin paths where needed
Implementation notes
Remove unnecessary compilers/debuggers from production images. Gate cloud CLIs via SSO roles. Use temporary elevation for powerful tools. Prefer audited admin paths over shared bastions with unconstrained binaries.
Audit tip: Show production image hardening and who can invoke break-glass utilities with logs.
Evidence auditors typically request:
- Privileged utility inventory
- Endpoint/application allowlists
- Production access jump host controls
- Session logs for privileged tools
Common gaps
- Unrestricted kubectl/admin CLIs on all laptops
- No logging of break-glass utilities
- Debug tools left on production images
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| ISO 27001 | A.8.18 | This control |
| SOC 2 | CC6.1, CC6.2 | Related SOC 2 themes (CC6.1, CC6.2) — map in your crosswalk; not identical requirements. |
Primary sources
- ISO/IEC 27001:2022 Annex A: ISO/IEC 27001:2022 Annex A (A.8.18)
Frequently Asked Questions
Focus on tools that bypass controls; manage package install via A.8.19.
Control production execution paths more tightly than local IDEs.
Privileged access monitoring under CC6/CC7 themes.
Even without owned data centers, use of privileged utility programs still applies to how you operate endpoints, IdP, cloud consoles, and vendor services in scope. Exclude controls in the SoA only with a documented, risk-based rationale.
Start with privileged utility inventory, assign a named control owner, and retain dated samples from your ticketing or GRC system — not one-off screenshots assembled before audit fieldwork.