Short answer
ISO 27001 Annex A control 5.18, Access rights, requires access rights to information and associated assets to be provisioned, reviewed, modified and removed in line with your access control policy and rules. In practice that means approved joiner and mover requests, timely removal for leavers, and periodic reviews where owners confirm each user still needs their access.
Key takeaways
- Covers the whole life cycle: provision, change, review and removal.
- Leavers' access must be removed promptly; this is the most sampled item.
- Periodic reviews need a named reviewer and a recorded decision.
- Privileged access deserves more frequent review.
What the control says
A.5.18 requires access rights to be provisioned, reviewed, modified and removed according to your topic-specific policy and rules for access control. ISO/IEC 27002 guidance covers authorisation by the asset owner, separation between approving and implementing access, keeping a central record of access granted, reviewing rights after changes and at regular intervals, and removing or adjusting rights when employment or contracts change.
Joiners, movers and leavers
| Event | What should happen | Record auditors look for |
|---|---|---|
| Joiner | Access granted by role, approved by the asset owner | Approved request matching the role matrix |
| Mover | Old access removed, new access granted | Change ticket showing removal as well as addition |
| Leaver | All access removed promptly, usually on the last day | Termination date compared with deactivation date |
Running access reviews
- Export current access for each in-scope system.
- Send each list to the system or data owner, not the IT team.
- Owners confirm or revoke each user and permission.
- Revocations are carried out and evidenced.
- Keep the signed review, the revocation tickets and the date.
Quarterly reviews are common for systems holding sensitive data and for privileged access; semi-annual or annual reviews for lower-risk systems. Set the frequency in your policy and stick to it.
The most common nonconformity is a leaver whose account stayed active for weeks. Compare HR termination dates with account deactivation dates before the auditor does.
Evidence auditors sample
- A sample of joiners with approved requests
- A sample of leavers with termination and deactivation dates
- Completed access reviews with reviewer sign-off and resulting changes
- Privileged account lists and their reviews (see A.8.2)
A.5.18Access rightsSOC 2 CC6.2User registration and removalA.5.18Access rightsSOC 2 CC6.3Least privilegeA.5.18Access rightsPCI DSS 7.2.4Six-monthly account reviews
Put this into practice on QULDEX
Frequently asked questions
How often should ISO 27001 access reviews happen?
The standard doesn't set a frequency. Set one in your policy based on risk; quarterly for sensitive and privileged access is common.
Who should perform the access review?
The owner of the system or data, who knows whether each user still needs access. IT can prepare the list but shouldn't approve it alone.