Access control decisions only become effective when access rights are correctly granted, changed, and removed in real time. Over my 30 years in governance, risk, and compliance, I have seen far too many organisations draft spotless access control policies, only to suffer catastrophic breaches because a departed employee’s VPN account remained active for six months, or an internal transfer accumulated rights across four different departments over five years (“privilege creep”). Attackers rarely break down encryption doors—they simply walk through open doors left behind by sloppy, unmonitored access rights management. Annex A 5.18 turns your access policy into day-to-day operational execution across the full user lifecycle.
ISO 27001:2022 includes Annex A 5.18 to ensure your organisation manages the provisioning, modification, and revocation of access rights in a controlled, business-led, and timely manner. This control updates former 2013 requirements (9.2.2 and 9.2.6) and serves as the operational bridge connecting identity management (Annex A 5.16), authentication (Annex A 8.5), privileged access management (Annex A 8.2), and physical access controls (Annex A 7.2).
Quick Summary: What ISO 27001 Annex A 5.18 Requires
At a practical level, Annex A 5.18 is about enforcing the Principles of Least Privilege and Need-to-Know across all systems, applications, data stores, and physical facilities. It does not require installing expensive Identity Governance and Administration (IGA) software suites on day one; it expects a consistent, documented, and auditable workflow for handling access provisioning, role adjustments, and account deprovisioning. Here is what you need to do in plain English:
- Require Pre-Approval for All Access Requests: Ensure access rights are provisioned only after explicit, documented approval from the designated asset owner or line manager.
- Enforce Role-Based Access Control (RBAC): Map default access permissions strictly to job descriptions to eliminate ad-hoc, “just-in-case” permission granting.
- Adjust Access Rights Promptly During Role Changes: Modify access permissions immediately when an employee transfers, gets promoted, or changes duties, preventing privilege accumulation.
- Revoke Access Instantly Upon Termination: Execute immediate logical and physical account revocation during HR offboarding, ensuring leavers cannot access corporate resources (Annex A 6.5).
- Tightly Govern Privileged & Emergency Access: Apply strict, time-boxed approval workflows and enhanced logging for administrative or emergency “break-glass” privileges (Annex A 8.2).
- Maintain an Auditable Access History: Log all access provisioning, modification, and revocation tickets inside a central, access-controlled system for audit review (Annex A 8.15).
Why Sloppy Access Rights Execution Is a Critical Hazard
When access rights management is handled informally via chat messages or verbal requests, access drift sets in rapidly. Users accumulate excessive permissions, legacy accounts remain active quietly, and internal segregation-of-duties boundaries dissolve.
Ignoring structured access rights lifecycle controls exposes your business to severe hazards:
- Malicious Leaver Attacks: Terminated employees retaining active corporate credentials (VPN, Microsoft 365, AWS) and exfiltrating intellectual property or deploying malicious scripts post-exit.
- Dangerous Privilege Creep & Insider Threat: Long-standing employees accumulating administrative rights across multiple legacy roles, enabling unmonitored fraud or accidental widespread system corruption.
- Uncontrolled Third-Party Credential Exposure: External contractors retaining active system access months after project completion due to missing vendor offboarding gates (Annex A 5.19).
- Severe ISO 27001 Non-Conformities: Failing external certification audits because auditors spot active user accounts belonging to staff who left the business over a year ago.
My 8 Step Plan to Implement Annex A 5.18 Fast
You do not need a multi-million-pound identity platform to satisfy an ISO 27001 auditor. Here is my pragmatic, 8-step plan to establish an audit-ready access rights management framework.
1. Establish a Formal Access Provisioning Workflow
Eliminate informal or undocumented access granting across all operational teams:
- Mandate that all new access requests must be submitted via a centralized ticketing tool (e.g., Jira, ServiceNow, or a dedicated Helpdesk portal).
- Require explicit sign-off from the designated Information Asset Owner or System Lead before IT provisions access (Annex A 8.9).
- Prohibit IT helpdesk staff from provisioning access based on verbal requests or direct messages from peers.
2. Implement Role-Based Access Control (RBAC) Profiles
Simplify access management by grouping permissions into predefined role profiles aligned with job functions:
- Define standard “starter packs” for core roles (e.g., Finance Associate, Software Engineer, HR Specialist) detailing baseline apps, folder rights, and cloud permissions.
- Enforce the Principle of Least Privilege: users receive only the exact permissions necessary to perform their current job role, and no more.
- Review and update RBAC profiles annually to reflect changing software tools and operational workflows.
3. Synchronize HR Workflows with Access Modification & Revocation
Link access rights adjustments directly to HR lifecycle triggers (Annex A 6.1 & Annex A 6.5):
- Joiners: Provision baseline RBAC profiles on day one based on HR onboarding notifications.
- Movers: Mandate an automatic “Mover Review” ticket whenever an employee changes roles or departments—stripping legacy access before granting new permissions.
- Leavers: Enforce instant, automated account disabling across Single Sign-On (SSO) and Active Directory upon HR offboarding notification.
4. Tightly Manage Privileged and Administrative Access
Administrative and system permissions present the highest operational risk and require special handling (Annex A 8.2):
- Separate standard user accounts from administrative accounts (e.g., `john.doe` vs. `john.doe-admin`).
- Enforce Just-in-Time (JIT) elevation or Privileged Access Management (PAM) workflows, granting admin rights temporarily for specific, pre-approved tasks.
- Require Multi-Factor Authentication (MFA) with hardware keys or authenticator apps globally for all privileged logins (Annex A 8.5).
5. Enforce Immediate Revocation Procedures for Leavers
Ensure that departed staff cannot access company systems after termination (Annex A 6.5):
- Automate account suspension via centralized Identity Providers (IdP) like Entra ID, Okta, or Google Workspace so a single action disables access across all federated SaaS apps.
- Revoke physical access badges, smart cards, and facility access permissions simultaneously (Annex A 7.2).
- Retrieve corporate hardware (laptops, mobile phones, security keys) immediately on or before the final working day.
6. Govern Third-Party and Contractor Access Rights
External suppliers and freelancers represent high-risk attack surfaces (Annex A 5.19 & Annex A 5.20):
- Set mandatory, hard expiration dates (e.g., 30, 60, or 90 days) on all third-party user accounts created in your directory.
- Require internal sponsor re-approval before extending any contractor account expiration date.
- Ensure third-party access is restricted strictly to the specific project resources defined in the vendor agreement.
7. Enforce Segregation of Duties (SoD) Checks
Prevent single individuals from holding permissions that enable unmonitored fraud or unauthorized system modifications (Annex A 5.3):
- Verify that access requests do not create toxic permission combinations (e.g., the ability to both create a vendor and approve vendor payments).
- Incorporate automated or manual SoD validation checks into your access approval ticketing workflow.
- Implement compensating dual-authorization or retrospective log auditing if operational constraints prevent total segregation of duties.
8. Conduct Bi-Annual Access Rights Audits and Reviews
Verify that technical access permissions match operational reality over time (Annex A 5.36):
- Execute bi-annual user access reviews requiring System Owners to inspect active user lists for all critical systems, databases, and cloud tenants.
- Identify and purge orphaned accounts, misaligned permissions, and lingering leaver credentials discovered during reviews.
- Maintain signed access review logs and ticket histories as direct evidence for ISO 27001 certification audits.
Common Implementation Pitfalls and How to Fix Them
When preparing clients for ISO 27001 audits, I frequently spot the same access rights management mistakes. Here are the main traps and how to solve them:
- Problem: Provisioning Access Based on Verbal Requests or Direct Messaging Without Auditable Approval
Ninja Solution: Mandate that IT helpdesk teams process access requests strictly through logged ticketing channels with asset owner sign-off. - Problem: Internal Transfers Accumulating Legacy Rights Across Multiple Departments over Several Years (“Privilege Creep”)
Ninja Solution: Implement a mandatory “Mover Access Reset” workflow that strips previous department permissions whenever HR logs a job transfer. - Problem: Terminated Employee Accounts Remaining Active for Days or Weeks Post-Exit
Ninja Solution: Centralize authentication via SSO/IdP and integrate HR offboarding triggers to disable user directory profiles instantly on the final working day. - Problem: Granting Users Permanent Global Administrator Access for Routine Daily Work
Ninja Solution: Enforce separate admin accounts, Just-in-Time elevation, and Least-Privilege Role-Based Access Control profiles.
The ISO 27001 Ninja Bottom Line
ISO 27001 Annex A 5.18 is about keeping access rights aligned with business reality throughout the user lifecycle. Access control does not stop at writing a policy or setting up a directory—it succeeds or fails in how permissions are granted, adjusted, and revoked every single day.
By enforcing pre-approved ticketing workflows, implementing Role-Based Access Control, linking permissions to HR lifecycles, tightly controlling privileged accounts, executing instant leaver revocations, setting hard expirations on contractor access, enforcing segregation-of-duties checks, and conducting bi-annual access reviews, you eliminate privilege creep, block insider threats, and satisfy your ISO 27001 auditor with complete confidence.
