ISO/IEC 27000 Privileged Access Rights, v2022

Specifies requirements in accordance with the security and privacy controls specified by ISO/IEC Publication 27001:2022, related to privileged access rights.

Assessment Step

1
Privileged Access Rights (PrivilegedAccessRights)
Is the allocation and use of privileged access rights restricted and managed?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.

Conformance Criteria (1)

Privileged Access Rights
The allocation and use of privileged access rights shall be restricted and managed.
Citations
27001
Annex A, Control 8.2
27002
Section 8.2