Cyber Resilience

← ISO 27001 Annex A

A.8.18 Technological

Use of privileged utility programs

AttributesPreventiveC·I·AProtectSystem and network securitySecure configurationApplication securityProtection

Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?

The implementation guidance for this control is published in ISO/IEC 27002:2022 and is not reproduced here. The structured attributes and the cross-walk rationales below are derived facts and our own AI-authored analysis.

Mapped NIST 800-53 r5 controls (17)

Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.

Direction: ← other covers this; → this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Aligned NIST CSF 2.0 outcomes (24)

NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).

Direction: ← other covers this; → this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Related OWASP ASVS 5.0 requirements (10)

Application-security verification requirements (OWASP ASVS 5.0) this ISO control aligns with; links open the ASVS chapter. Our AI-authored analysis (authority llm_unverified, under review) — many ISO controls have no ASVS counterpart.

Direction: ← other covers this; → this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Related weaknesses / CWE (36)

Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).

Direction: ← other covers this; → this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Mitigated MITRE ATT&CK techniques (1092)

Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).

Direction: ← other covers this; → this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

T1001.001←MT1001.002←MT1001.003←MT1003←M →PT1003.001←M →PT1003.002←M →PT1003.003←M →PT1003.004←M →PT1003.005→PT1003.006←M →PT1003.007←M →PT1003.008←M →PT1006←M →PT1007→PT1014←M →PT1016→PT1018→PT1021←M →PT1021.002←M →PT1021.003→PT1021.004←M →PT1021.005→PT1021.006→PT1021.008←M →PT1027.001←MT1027.002←MT1027.004←PT1027.005←MT1027.006←MT1027.007←MT1027.008←MT1027.009←MT1027.010←MT1027.011←MT1027.012←MT1027.013←MT1027.014←MT1027.016←MT1027.017←MT1027.018←MT1033→PT1036←M →PT1036.002←MT1036.003←M →PT1036.004←MT1036.005←MT1036.006←MT1036.007←MT1036.008←MT1036.009←MT1036.011←MT1037←M →PT1037.001→PT1037.002←M →PT1037.003←P →PT1037.004←M →PT1037.005→PT1040←M →PT1047←M →PT1048←MT1049→PT1053←M →PT1053.002→PT1053.003←M →PT1053.005←M →PT1053.006←M →PT1053.007→PT1055←M →PT1055.001←M →PT1055.002←M →PT1055.003←M →PT1055.004←M →PT1055.005←MT1055.008←M →PT1055.009←M →PT1055.011←MT1055.012←M →PT1055.013←M →PT1055.014←M →PT1055.015←M →PT1056.001→PT1056.002←MT1056.004←M →PT1057→PT1059←M →PT1059.001←M →PT1059.002→PT1059.003←M →PT1059.004←M →PT1059.006←M →PT1059.008→PT1059.009→PT1059.010→PT1059.011→PT1059.012←M →PT1059.013←M →PT1068←M →PT1069.002→PT1070←M →PT1070.003←M →PT1070.004←M →PT1070.005→PT1070.006←M →PT1070.007←M →PT1070.008←M →PT1070.009→PT1070.010←M →PT1071←MT1071.001←MT1071.002←MT1071.004←MT1072←M →PT1078→PT1078.001←M →PT1078.002→PT1078.003→PT1078.004←M →PT1080→PT1082→PT1083→PT1087→PT1087.001→PT1087.004→PT1090←MT1090.001←MT1090.002←MT1090.003←MT1091←MT1095←MT1098←P →PT1098.001←M →PT1098.002←P →PT1098.003←M →PT1098.004←M →PT1098.005←MT1098.006←M →PT1098.007→PT1102←MT1102.001←MT1102.002←MT1104←MT1105←MT1106←MT1110←M →PT1110.001→MT1110.002→PT1110.003←M →PT1110.004→PT1111←PT1112←M →PT1127→PT1127.001→PT1127.002←M →PT1127.003←M →PT1129→PT1132.001←PT1132.002←MT1133←MT1134←M →PT1134.001←M →PT1134.002←M →PT1134.003←M →PT1134.004←MT1134.005←M →PT1136→PT1136.001←M →PT1136.002→PT1137→PT1137.001←M →PT1137.002→PT1137.003←M →PT1137.005←M →PT1137.006→PT1140←M →PT1176←MT1176.001←M →PT1185←M →PT1187→PT1197←M →PT1199→PT1202→PT1204←PT1204.002←MT1204.003←MT1204.004←MT1204.005←MT1205←MT1205.001←MT1205.002←M →PT1207←M →PT1210←M →PT1211←M →PT1212←MT1216←M →PT1216.001←M →PT1216.002←M →PT1218←M →PT1218.001←MT1218.002←M →PT1218.003←M →PT1218.004→PT1218.005→PT1218.007→PT1218.008→PT1218.009→PT1218.010←M →PT1218.011←M →PT1218.012←M →PT1218.013→PT1218.014→PT1219←M →PT1219.001←M →PT1219.002←M →PT1219.003←MT1220→PT1221←MT1222←M →PT1222.001←M →PT1222.002←M →PT1480.001←MT1482→PT1484←M →PT1484.001←M →PT1484.002←M →PT1485←P →PT1485.001←PT1489←M →PT1490→PT1491.001→PT1495→PT1496.001→PT1497←MT1505←M →PT1505.001→PT1505.002←P →PT1505.003←M →PT1505.004←M →PT1505.005←M →PT1505.006←M →PT1518.001→PT1518.002→PT1528←M →PT1529→PT1530→PT1531←P →PT1535←MT1537←MT1539←M →PT1542←MT1542.002←MT1542.003←M →PT1542.004←M →PT1542.005←M →PT1543←M →PT1543.001←M →PT1543.002←M →PT1543.003←M →PT1543.004←M →PT1543.005←P →PT1546←M →PT1546.001←M →PT1546.002←M →PT1546.003←M →PT1546.004←M →PT1546.006←M →PT1546.007←M →PT1546.008←M →PT1546.009→PT1546.010←M →PT1546.011←M →PT1546.012←M →PT1546.013←M →PT1546.014→PT1546.015←M →PT1546.016←M →PT1546.017←M →PT1546.018←M →PT1547←M →PT1547.001←M →PT1547.002→PT1547.003→PT1547.004←M →PT1547.005←M →PT1547.006←M →PT1547.008→PT1547.009→PT1547.010←M →PT1547.012←P →PT1547.013→PT1547.014→PT1547.015→PT1548→PT1548.001→PT1548.002→PT1548.003→MT1548.004←M →PT1548.005←M →PT1548.006←M →PT1550←M →PT1550.001←MT1550.002←M →PT1550.003←M →PT1550.004←FT1552→PT1552.001←M →PT1552.006→PT1553←M →PT1553.001←MT1553.002←MT1553.003←M →PT1553.004←P →PT1553.005←MT1553.006→PT1554←M →PT1555←M →PT1555.001←M →PT1555.004←M →PT1555.005→PT1555.006→PT1556←M →PT1556.001←M →PT1556.002←M →PT1556.003←M →PT1556.004←MT1556.005←P →PT1556.006←M →PT1556.007←M →PT1556.008←M →PT1556.009←M →PT1557←MT1558←M →PT1558.001←M →PT1558.002←M →PT1558.005←M →PT1559.003←M →PT1560→PT1560.001←M →PT1561←P →PT1561.001←P →PT1561.002←P →PT1563→PT1563.001←M →PT1563.002←M →PT1564→PT1564.006→PT1564.012→PT1564.013→PT1564.014→PT1565→PT1565.001→PT1565.002→PT1565.003→PT1568.003←PT1569←P →PT1569.001←M →PT1569.002←M →PT1569.003←M →PT1571←MT1572←M →PT1574←M →PT1574.001←M →PT1574.004←M →PT1574.005←M →PT1574.006←M →PT1574.007←M →PT1574.008←M →PT1574.009←M →PT1574.010←M →PT1574.011←M →PT1574.012←M →PT1574.013←M →PT1574.014→PT1578←M →PT1578.001←M →PT1578.002←M →PT1578.003←M →PT1578.004←M →PT1578.005←P →PT1583.007←MT1588.001←PT1599←MT1599.001←M →PT1600←PT1600.001←PT1601←P →PT1601.001←M →PT1601.002←MT1602.001→PT1602.002→PT1606←MT1606.001←MT1606.002←MT1609←M →PT1610←P →PT1611←M →PT1612←M →PT1615→PT1620←M →PT1621←PT1622←MT1647←MT1649←P →PT1651→PT1653←P →PT1654→PT1665←PT1666←PT1671←MT1674←PT1675→PT1677←M →PT1678←PT1679←PT1685←M →PT1685.001←M →PT1685.002←M →PT1685.003←MT1685.004←M →PT1685.005←M →PT1685.006←M →PT1686←M →PT1686.001←M →PT1686.002←M →PT1686.003←M →PT1687←P →PT1688←MT1689←MT1690←M
Why these map — AI rationale (under review)

Prevented OWASP Web Top 10 (2025) risks (12)

OWASP Web Top 10 (2025) risk categories this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).

Direction: ← other covers this; → this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.