Skip to main content

Proof of competence

ISO/IEC 27001:2022 Annex A · Control 5.16

Identity Management: A Practical Implementation Guide

Manage every human and non-human identity through a controlled, traceable lifecycle.

Identity management ensures that identities are uniquely established, changed, monitored and removed in line with business relationships and access needs.

Practical interpretation: An identity is not the same as an account. The organization needs confidence about who or what an identity represents and must control its lifecycle across connected systems.

What should the control achieve?

  • Identities are unique and reliably linked to owners.
  • Creation and change use authorized sources.
  • Duplicate, orphan and dormant identities are detected.
  • Service and shared identities receive explicit ownership.

Step-by-step implementation

1

Define identity types

Cover employees, contractors, customers, suppliers, service accounts, devices and automated workloads.

2

Establish authoritative sources

Use HR, contractor and customer systems as trusted lifecycle triggers.

3

Verify identities

Apply proportionate proofing before issuing credentials or high-risk access.

4

Automate lifecycle events

Create, update, suspend and remove identities through integrated workflows.

5

Control non-human identities

Assign owners, purpose, expiry and credential-rotation requirements.

6

Reconcile directories

Detect unmatched, duplicate, dormant and orphan identities.

What this could look like in practice

HR creates the authoritative worker record. The identity platform generates a unique ID and standard accounts. Termination suspends central identity immediately and removes connected access. Service accounts require an owner and annual reapproval.

ActivityPractical implementationEvidence
JoinerVerified HR event creates identity and baseline accounts.Identity workflow
Contract extensionSponsor approval updates expiry date.Extension record
TerminationAuthoritative event disables identity across connected systems.Disablement log
Service identityNamed owner and purpose are recorded.Service-account register

Implementation evidence

  • Identity management policy
  • Identity-type inventory
  • Authoritative-source mapping
  • Proofing procedure
  • Lifecycle workflows
  • Reconciliation reports
  • Service-account register
  • Orphan remediation

Useful metrics

  • Orphan identities
  • Dormant identities
  • Termination-to-disable time
  • Service identities without owners

Common mistakes

  • Creating accounts outside authoritative processes.
  • Confusing email addresses with stable identity.
  • No expiry for contractors.
  • Ignoring service, device and API identities.
  • Deleting evidence before investigations or retention needs are met.

Questions an auditor may ask

  • What is the authoritative source for each identity type?
  • How are identities verified?
  • Show termination propagation.
  • How are service identities owned and reviewed?
Implementation test: Select a terminated worker and a service account and trace identity creation, changes, ownership and current state.

Continue through Annex A

Explore the growing library of practical guides for all 93 Annex A controls.

Open the ISO 27001 Annex A Control Library

This independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.