Skip to main content

Proof of competence

ISO/IEC 27001:2022 Annex A · Control 5.32

Intellectual Property Rights: A Practical Implementation Guide

Respect, protect and prove rights relating to software, content, data, designs and licensed materials.

This control addresses procedures for protecting intellectual property rights and complying with related legal, regulatory and contractual requirements.

Practical interpretation: Organizations are both users and owners of intellectual property. Controls must address authorized acquisition and use as well as protection of internally created assets.

What should the control achieve?

  • Relevant intellectual property is inventoried.
  • Software and content use follows licenses.
  • Ownership and permitted use are contractually clear.
  • Suspected infringement is escalated.

Step-by-step implementation

1

Identify IP categories

Cover software, source code, designs, trademarks, content, data sets and trade secrets.

2

Define ownership

Use employment, contractor and supplier agreements to assign rights.

3

Control acquisition

Approve software and content sources and retain license evidence.

4

Manage licenses

Track users, devices, terms, restrictions, renewals and end-of-use.

5

Protect organizational IP

Apply access, classification, confidentiality and disclosure controls.

6

Monitor and respond

Review usage, open-source obligations and infringement claims.

What this could look like in practice

A development company maintains a software inventory and open-source approval process. Dependency scanning identifies licenses; Legal reviews restrictive terms. Contractor agreements assign deliverable rights and repositories restrict source access.

ActivityPractical implementationEvidence
Software purchaseProcurement verifies license and authorized quantity.License record
Open sourceComponent and obligations are reviewed before use.Approval and SBOM
Contractor workAgreement assigns rights and confidentiality.Executed contract

Implementation evidence

  • IP policy
  • Software and license inventory
  • Purchase records
  • Open-source reviews
  • Employment and contractor clauses
  • Trademark records
  • Access restrictions
  • Infringement process

Useful metrics

  • Unlicensed installations
  • Licenses reconciled
  • Components with unresolved license risk
  • Contracts with IP clauses

Common mistakes

  • Assuming internet content is free to use.
  • Ignoring open-source obligations.
  • No proof of purchased licenses.
  • Failing to assign contractor-created rights.
  • Protecting patents but not code or data.

Questions an auditor may ask

  • How is software license compliance maintained?
  • How are open-source components approved?
  • Who owns employee and contractor work?
  • How is organizational IP protected?
Implementation test: Select a deployed software component and prove lawful acquisition, applicable terms, permitted use and current ownership.

Continue through Annex A

Explore the growing library of practical guides for all 93 Annex A controls.

Open the ISO 27001 Annex A Control Library

This independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.