A.5.18 Organizational
Access rights
Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?
Mapped NIST 800-53 r5 controls (11)
Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- AC-2mostlyaligns with — Both controls establish the full lifecycle of account provisioning, modification, and timely revocation tied to personnel changes and business need.
- AC-3mostlyaligns with — Both enforce that access decisions are made only after explicit authorization and that granted rights are consistent with policy and risk.
- PS-4mostlyaligns with — Both mandate review and removal of access rights before or upon personnel termination or role change to reduce residual risk.
- PS-5mostlyaligns with — Both require adjustment of access rights when individuals transfer or change positions within the organization.
- AC-5partialaligns with — Both embed segregation-of-duties considerations into the approval and implementation steps of granting access rights.
- AC-6partialaligns with — Both require that the scope of access granted is limited to what is necessary and that privileged rights receive additional scrutiny.
Aligned NIST CSF 2.0 outcomes (8)
NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- PR.AA-05fullcovers — The ISO control's detailed provisioning, review, and revocation procedures directly implement the CSF outcome of defining, managing, enforcing, and reviewing access permissions and authorizations.
- PR.AA-01mostlyaligns with — Managing the full lifecycle of identities and credentials through authorization, activation, modification, and timely removal aligns with the CSF requirement to manage identities and credentials for authorized users.
- GV.RR-02partialaligns with — Establishing explicit approval, segregation of duties, and record-keeping for access rights supports the CSF outcome of defining and communicating roles, responsibilities, and authorities for cybersecurity risk management.
- ID.AM-08partialaligns with — Requiring access rights to be adjusted or removed when personnel change roles or leave the organization contributes to managing assets throughout their life cycles.
Related OWASP ASVS 5.0 requirements (13)
Application-security verification requirements (OWASP ASVS 5.0) this ISO control aligns with; links open the ASVS chapter. Our AI-authored analysis (authority llm_unverified, under review) — many ISO controls have no ASVS counterpart.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- V8.2.1mostlyaligns with — The ISO control's requirement to grant access only after explicit authorization and to enforce topic-specific access policies directly supports the ASVS mandate that function-level access be restricted to consumers with explicit permissions.
- V8.2.2mostlyaligns with — By requiring authorization from asset owners and maintaining a central record of granted rights, the ISO control ensures that data-specific access is limited to consumers who have explicit permissions for those items.
- V6.3.2partialaligns with — The ISO control's explicit removal of access rights for users who leave or change roles supports the ASVS requirement to disable or remove default and unused accounts.
- V8.3.1partialaligns with — The ISO guidance that access rights must be activated only after authorization procedures complete and must be enforced at a trusted service layer aligns with the ASVS requirement to enforce authorization rules outside untrusted consumer control.
- V8.3.2partialaligns with — Regular reviews and immediate adjustment of access rights when roles change or employment ends ensure that authorization decisions reflect current permissions without delay.
- V8.4.2partialaligns with — Requiring separate approval, segregation of duties, and privileged-access reviews in the ISO control aligns with the ASVS demand for layered security around administrative interfaces.
Related weaknesses / CWE (104)
Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CWE-284fullprevents — Formal authorization, role-based provisioning, and timely revocation of access rights directly stop the creation of accounts or permissions that exceed what the business actually needs.
- CWE-1334mostlyprevents — Managing access rights restricts privileges that could be abused to inject faults into redundant components.
- CWE-15mostlyprevents — Access rights assignment determines who may change system settings.
- CWE-202mostlyprevents — Granular access rights reduce the ability of users to craft inference queries.
- CWE-250mostlyprevents — Requiring explicit justification and time-limited grants discourages the routine allocation of unnecessary privileges that would otherwise allow execution with more rights than required.
- CWE-266mostlyprevents — The access-rights control governs the entire lifecycle of privilege assignment, directly eliminating incorrect assignments.
- CWE-269mostlyprevents — Requiring owner approval, segregation of duties, and periodic reviews prevents the assignment of excessive or unnecessary privileges to users or processes.
- CWE-286mostlyprevents — Access rights provisioning and de-provisioning ensure users are correctly created, modified, and removed.
- CWE-402mostlyprevents — Managing access rights helps ensure resources are not granted to untrusted parties.
- CWE-527mostlyprevents — Managing access rights ensures only authorized personnel can access source-code repositories.
- CWE-530mostlyprevents — Proper access-rights provisioning prevents unauthorized actors from reaching backup locations.
- CWE-612mostlyprevents — Managing access rights ensures only authorized users can reach indexed sensitive content.
- CWE-732mostlyprevents — Documented provisioning and revocation procedures reduce the chance that critical resources retain overly permissive default or leftover permissions after personnel changes.
- CWE-842mostlyprevents — Access rights control explicitly requires review and approval of group memberships, preventing erroneous placement.
- CWE-921mostlyprevents — Granting and reviewing access rights prevents unauthorized access to sensitive data on storage media.
- CWE-1220partialprevents — Defines the assignment and review of access rights; insufficient granularity in those rights is the root of CWE-1220.
- CWE-1268partialprevents — Directly governs the assignment and review of access rights, addressing inconsistent privilege mappings between agents.
- CWE-213partialmitigates — Rights assignment can be aligned with the strictest applicable stakeholder policy.
- CWE-219partialmitigates — Granting only the minimum rights prevents unauthorized retrieval of sensitive files.
- CWE-268partialprevents — Managing access rights helps prevent the accumulation or chaining of privileges that lead to unsafe actions.
- CWE-270partialprevents — Managing access rights includes privilege assignment but not runtime context-switch enforcement.
- CWE-274partialprevents — Access-rights provisioning and review reduce privilege gaps, yet do not address the software’s failure to handle insufficient privileges gracefully.
- CWE-278partialprevents — Managing access rights includes reviewing and adjusting permissions when objects are copied or inherited.
- CWE-283partialprevents — Access rights reviews can enforce checks that only legitimate owners retain privileges over critical assets.
- CWE-288partialprevents — Access rights provisioning and review prevent bypass via unmonitored or alternate channels.
- CWE-289partialprevents — Access-rights provisioning can enforce canonical-name validation when granting rights.
- CWE-290partialprevents — Access rights assignment limits exposure but does not enforce authentication strength.
- CWE-291partialprevents — Access-rights assignment should be tied to authenticated identities, not network location.
- CWE-302partialmitigates — Access-rights reviews can detect and revoke rights granted via tampered immutable data.
- CWE-408partialprevents — Access rights provisioning can restrict expensive operations until authorization is granted.
- CWE-424partialprevents — Managing access rights must cover every alternate path that could bypass intended restrictions.
- CWE-528partialprevents — Granting only the minimum rights needed can prevent unauthorized access to core dumps, but does not address how or where they are generated.
- CWE-529partialprevents — Managing access rights includes ensuring ACL files themselves are not exposed outside their intended sphere.
- CWE-638partialprevents — Managing access rights lifecycle ensures checks reflect current privileges on each use.
- CWE-639partialprevents — Managing access rights includes ensuring users can only access their own records and not bypass authorization by altering identifiers.
- CWE-642partialprevents — Managing access rights prevents unauthorized actors from altering critical state stored externally.
- CWE-708partialprevents — Access-rights provisioning includes ownership assignment; fixing CWE-708 directly supports this control's intent.
- CWE-862partialprevents — Mandatory authorization checks and central records of granted rights ensure that every access attempt is preceded by an explicit decision rather than relying on missing checks.
- CWE-863partialprevents — Enforcing policy-driven approval and role-change reviews stops incorrect or stale authorization decisions from remaining in effect after job changes or terminations.
- CWE-262nonenone — Defines access rights provisioning but does not mandate password aging rules.
- CWE-267nonenone — Access rights assignment can restrict privileges to intended actions, yet does not guarantee the privilege itself is safe.
- CWE-280nonenone — Specifies how access rights are granted, reviewed and revoked, directly addressing privilege handling.
- CWE-281nonenone — Access-rights provisioning and review processes directly address the risk of overly permissive copied objects.
- CWE-282nonemitigates — Managing access rights includes verifying and maintaining proper ownership of resources.
- CWE-308nonenone — Access rights provisioning can require MFA, yet the control is broader than authentication strength.
- CWE-309nonenone — Access rights assignment assumes authentication has already occurred; does not address password weaknesses.
- CWE-425nonenone — Managing access rights ensures every URL/script/file is explicitly authorized, mitigating direct request attacks.
- CWE-441nonenone — Explicit access-rights assignment can restrict the product’s ability to act as an unintended proxy for external actors.
- CWE-566nonenone — Managing access rights ensures users receive only the privileges needed, reducing the blast radius of a primary-key bypass.
- CWE-640nonenone — Proper access-rights provisioning can limit who can trigger recovery, but does not fix the recovery mechanism itself.
- CWE-645nonenone — Access rights administration must include procedures for unlocking accounts and reviewing lockout events.
- CWE-653noneprevents — Managing access rights is the operational mechanism for compartmentalizing privileges.
- CWE-654nonenone — Access rights assignment can enforce MFA, yet the control itself is broader than authentication strength.
- CWE-669nonemitigates — Managing access rights reduces risk of unauthorized resource transfer.
- CWE-671nonenone — Access rights management enables administrators to adjust privileges and security parameters as needed.
- CWE-673nonemitigates — Managing access rights prevents unauthorized external actors from altering sphere definitions.
- CWE-837nonenone — Managing access rights can include rules that limit an action to one occurrence, yet the control addresses rights in general.
Mitigated MITRE ATT&CK techniques (8)
Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- T1078mostlyprevents — Strict authorization, timely revocation on role change or departure, and central logging of access rights directly limit an adversary’s ability to retain or abuse valid accounts after employment ends or privileges are altered.
- T1078.002mostlyprevents — Enforcing segregation of duties and periodic reviews of privileged domain accounts makes it harder for attackers to maintain long-term access via compromised domain credentials.
- T1098mostlyprevents — Requiring documented approval and maintaining a central record of access-right changes makes unauthorized account manipulation or privilege additions more detectable and harder to sustain.
- T1136mostlyprevents — Authorization workflows and separation of duties reduce the likelihood that an adversary can create new local, domain, or cloud accounts without detection.
- T1136.001mostlyprevents — Requiring documented approval before any new local account is provisioned makes covert creation of local accounts for persistence significantly harder.
- T1078.001partialmitigates — Requiring explicit authorization and prompt removal of default or shared accounts reduces the window during which attackers can exploit lingering default credentials.
- T1078.003partialprevents — Mandatory revocation of local accounts when users leave or change roles shrinks the pool of stale local credentials an attacker could leverage.
- T1098.007partialmitigates — Segregation between approval and implementation roles, plus regular reviews, limits an attacker’s ability to quietly add themselves to additional local or domain groups.
Prevented OWASP Web Top 10 (2025) risks (2)
OWASP Web Top 10 (2025) risk categories this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- A01fullprevents — Formal authorization, segregation of duties, timely revocation on role change or termination, and periodic reviews directly stop users from retaining or obtaining unauthorized access to resources.
- A07partialmitigates — Enforcing least-privilege provisioning and prompt removal of credentials when employment ends reduces the window during which stale or excessive authentication rights can be abused.
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.