ISO/IEC 27001:2022 Annex A · Control 5.18
Access Rights: A Practical Implementation Guide
Grant, review, change and revoke access rights through accountable business decisions.
This control focuses on provisioning and reviewing access rights in accordance with access-control policy and changing business needs.
What should the control achieve?
- Rights are approved before provisioning.
- Changes reflect role and risk.
- Reviews examine actual entitlements.
- Rights are removed when no longer required.
Step-by-step implementation
Define request information
Require user, system, role, entitlement, reason, duration and manager.
Route approval
Use asset or data owners for sensitive rights and separate provisioning.
Provision consistently
Prefer roles and automated workflows; verify successful implementation.
Control temporary rights
Set expiry and monitor extensions.
Review entitlements
Give owners understandable lists and require decisions with evidence.
Remove promptly
Integrate termination, transfer and contract-end triggers.
What this could look like in practice
Finance-system roles are catalogued with conflict rules. Managers request roles, the Finance Owner approves and IT provisions automatically. Quarterly reviews show both role and underlying permissions, with removals tracked to completion.
| Activity | Practical implementation | Evidence |
|---|---|---|
| New right | Business reason and owner approval precede provisioning. | Request and system log |
| Temporary project | Access automatically expires after 60 days. | Expiry record |
| Review | Owner certifies or removes each entitlement. | Review report |
| Leaver | Rights are disabled from authoritative event. | Removal log |
Implementation evidence
- Access-rights procedure
- Role catalogue
- Approval records
- Provisioning logs
- Temporary-access expiry
- Access reviews
- Removal tickets
- Exception register
Useful metrics
- Unapproved entitlements
- Review completion rate
- Removal time
- Temporary rights past expiry
Common mistakes
- Approving broad roles without entitlement detail.
- Letting requesters approve their own access.
- Keeping project rights permanently.
- Treating a spreadsheet review as complete without removals.
- Failing to review privileged rights more frequently.
Questions an auditor may ask
- Who approves each right?
- How do temporary rights expire?
- Show evidence that review removals were completed.
- How are conflicts identified?
Continue through Annex A
Explore the growing library of practical guides for all 93 Annex A controls.
Open the ISO 27001 Annex A Control LibraryThis independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.