ISO/IEC 27000 Use of Privileged Utility Programs, v2022

Specifies requirements in accordance with the security and privacy controls specified by ISO/IEC Publication 27001:2022, related to use of privileged utility programs.

Assessment Step

1
Use of Privileged Utility Programs (UseofPrivilegedUtilityPrograms)
Is the use of utility programs that are capable of overriding system and application controls restricted and tightly controlled?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.

Conformance Criteria (1)

Use of Privileged Utility Programs
The use of utility programs that can be capable of overriding system and application controls shall be restricted and tightly controlled.
Citations
27001
Annex A, Control 8.18
27002
Section 8.18