A.8.18
    Technological Controls

    Use of privileged utility programs

    The use of utility programs that can be capable of overriding system and application controls should be restricted and tightly controlled.

    Purpose

    To prevent misuse of privileged utilities that could bypass security controls.

    Implementation Guidance

    Identify and inventory privileged utilities

    Restrict access to privileged utilities

    Log all use of privileged utilities

    Monitor and audit utility program usage

    Segregate privileged utilities from normal systems

    Recommended Tools

    ISO 27001 Services from the Directory

    These providers can help you implement A.8.18 and achieve ISO 27001 certification.

    By the team behind ISMS Directory

    Implementing A.8.18 for a client?

    ISMS Copilot drafts policies, evidence, and SoA wording for A.8.18 Use of privileged utility programs. Built for compliance professionals.

    Try ISMS Copilot free