ISO/IEC 27001:2022 Annex A · Control 5.32
Intellectual Property Rights: A Practical Implementation Guide
Respect, protect and prove rights relating to software, content, data, designs and licensed materials.
This control addresses procedures for protecting intellectual property rights and complying with related legal, regulatory and contractual requirements.
What should the control achieve?
- Relevant intellectual property is inventoried.
- Software and content use follows licenses.
- Ownership and permitted use are contractually clear.
- Suspected infringement is escalated.
Step-by-step implementation
Identify IP categories
Cover software, source code, designs, trademarks, content, data sets and trade secrets.
Define ownership
Use employment, contractor and supplier agreements to assign rights.
Control acquisition
Approve software and content sources and retain license evidence.
Manage licenses
Track users, devices, terms, restrictions, renewals and end-of-use.
Protect organizational IP
Apply access, classification, confidentiality and disclosure controls.
Monitor and respond
Review usage, open-source obligations and infringement claims.
What this could look like in practice
A development company maintains a software inventory and open-source approval process. Dependency scanning identifies licenses; Legal reviews restrictive terms. Contractor agreements assign deliverable rights and repositories restrict source access.
| Activity | Practical implementation | Evidence |
|---|---|---|
| Software purchase | Procurement verifies license and authorized quantity. | License record |
| Open source | Component and obligations are reviewed before use. | Approval and SBOM |
| Contractor work | Agreement assigns rights and confidentiality. | Executed contract |
Implementation evidence
- IP policy
- Software and license inventory
- Purchase records
- Open-source reviews
- Employment and contractor clauses
- Trademark records
- Access restrictions
- Infringement process
Useful metrics
- Unlicensed installations
- Licenses reconciled
- Components with unresolved license risk
- Contracts with IP clauses
Common mistakes
- Assuming internet content is free to use.
- Ignoring open-source obligations.
- No proof of purchased licenses.
- Failing to assign contractor-created rights.
- Protecting patents but not code or data.
Questions an auditor may ask
- How is software license compliance maintained?
- How are open-source components approved?
- Who owns employee and contractor work?
- How is organizational IP protected?
Continue through Annex A
Explore the growing library of practical guides for all 93 Annex A controls.
Open the ISO 27001 Annex A Control LibraryThis independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.