Skip to main content

Proof of competence

ISO/IEC 27001:2022 Annex A · Control 8.18

Use of Privileged Utility Programs: A Practical Implementation Guide

Restrict powerful utilities that can bypass normal application and system controls.

This control concerns tightly controlling utility programs capable of overriding system and application controls.

Practical interpretation: Administrative shells, database tools, debuggers, recovery tools and vendor utilities may bypass normal authorization. Their presence and use require explicit governance.

What should the control achieve?

  • High-risk utilities are identified.
  • Availability is restricted to justified users and systems.
  • Use is authorized and logged.
  • Utilities are removed or disabled when not needed.

Step-by-step implementation

1

Identify privileged utilities

Inventory shells, database consoles, debuggers, recovery, packet capture and vendor tools.

2

Assess necessity

Remove unnecessary tools from production and sensitive endpoints.

3

Restrict access

Use separate admin identities, allowlists, elevation and controlled jump hosts.

4

Authorize use

Require purpose, ticket and duration for sensitive utilities.

5

Log and monitor

Capture execution, user, target, parameters or session where lawful.

6

Review inventory

Detect new tools and verify continued need.

What this could look like in practice

Database administrators access production consoles only through a monitored privileged workstation after ticket approval. General users cannot install or run database clients against production.

ActivityPractical implementationEvidence
Tool approvalSecurity and service owner approve utility.Utility register
ExecutionPAM provides temporary access and session logging.Session record
EmergencyBreak-glass use is alerted and reviewed.Emergency review
RemovalUnused diagnostic tool is deleted from production.Change ticket

Implementation evidence

  • Privileged-utility policy
  • Utility inventory
  • Allowlist configuration
  • Approval tickets
  • PAM logs
  • Execution monitoring
  • Emergency reviews
  • Removal records

Useful metrics

  • Unapproved utilities detected
  • Privileged utility sessions reviewed
  • Utilities without owners
  • Emergency use outside target

Common mistakes

  • Focusing only on user privilege, not tool capability.
  • Leaving vendor utilities installed permanently.
  • Allowing production use from ordinary workstations.
  • No logging of shell or database sessions.
  • Treating open-source tools as inherently safe.

Questions an auditor may ask

  • Which utilities can bypass controls?
  • Who may use them?
  • Show a monitored session.
  • How are new utilities detected?
Implementation test: Attempt to run a restricted utility from normal and approved administrative contexts and verify prevention, authorization and logging.

Continue through Annex A

Explore the growing library of practical guides for all 93 Annex A controls.

Open the ISO 27001 Annex A Control Library

This independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.