ISO/IEC 27001:2022 Annex A · Control 5.16
Identity Management: A Practical Implementation Guide
Manage every human and non-human identity through a controlled, traceable lifecycle.
Identity management ensures that identities are uniquely established, changed, monitored and removed in line with business relationships and access needs.
What should the control achieve?
- Identities are unique and reliably linked to owners.
- Creation and change use authorized sources.
- Duplicate, orphan and dormant identities are detected.
- Service and shared identities receive explicit ownership.
Step-by-step implementation
Define identity types
Cover employees, contractors, customers, suppliers, service accounts, devices and automated workloads.
Establish authoritative sources
Use HR, contractor and customer systems as trusted lifecycle triggers.
Verify identities
Apply proportionate proofing before issuing credentials or high-risk access.
Automate lifecycle events
Create, update, suspend and remove identities through integrated workflows.
Control non-human identities
Assign owners, purpose, expiry and credential-rotation requirements.
Reconcile directories
Detect unmatched, duplicate, dormant and orphan identities.
What this could look like in practice
HR creates the authoritative worker record. The identity platform generates a unique ID and standard accounts. Termination suspends central identity immediately and removes connected access. Service accounts require an owner and annual reapproval.
| Activity | Practical implementation | Evidence |
|---|---|---|
| Joiner | Verified HR event creates identity and baseline accounts. | Identity workflow |
| Contract extension | Sponsor approval updates expiry date. | Extension record |
| Termination | Authoritative event disables identity across connected systems. | Disablement log |
| Service identity | Named owner and purpose are recorded. | Service-account register |
Implementation evidence
- Identity management policy
- Identity-type inventory
- Authoritative-source mapping
- Proofing procedure
- Lifecycle workflows
- Reconciliation reports
- Service-account register
- Orphan remediation
Useful metrics
- Orphan identities
- Dormant identities
- Termination-to-disable time
- Service identities without owners
Common mistakes
- Creating accounts outside authoritative processes.
- Confusing email addresses with stable identity.
- No expiry for contractors.
- Ignoring service, device and API identities.
- Deleting evidence before investigations or retention needs are met.
Questions an auditor may ask
- What is the authoritative source for each identity type?
- How are identities verified?
- Show termination propagation.
- How are service identities owned and reviewed?
Continue through Annex A
Explore the growing library of practical guides for all 93 Annex A controls.
Open the ISO 27001 Annex A Control LibraryThis independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.