A.5.16
    Organizational Controls

    Identity management

    The full life cycle of identities should be managed.

    Purpose

    To ensure that only authorized users have access to systems and services, and to prevent unauthorized access.

    Implementation Guidance

    Implement formal user provisioning and de-provisioning processes

    Use unique user IDs for all personnel

    Manage identities from creation through modification to deletion

    Integrate identity management with HR processes

    Maintain audit logs of identity lifecycle events

    Recommended Tools

    ISO 27001 Services from the Directory

    These providers can help you implement A.5.16 and achieve ISO 27001 certification.

    By the team behind ISMS Directory

    Implementing A.5.16 for a client?

    ISMS Copilot drafts policies, evidence, and SoA wording for A.5.16 Identity management. Built for compliance professionals.

    Try ISMS Copilot free