Compliance hub
ISO 27001 access control: implementing Annex A with IamLogic
ISO/IEC 27001:2022's Annex A dedicates a cluster of controls to identity: access control policy (5.15), identity management (5.16), authentication information (5.17), access rights (5.18) and privileged/utility restrictions (8.2–8.5). IamLogic implements these controls operationally — and we hold the certificate ourselves, so we know what auditors ask.
Context
What the framework expects
IamLogic is built by an ISO/IEC 27001:2022 certified organisation, with the certification scope covering the full product lifecycle.
For certification and surveillance audits, the recurring identity questions are: how are access rights granted, reviewed and removed; how is authentication protected; and where is the evidence.
Identity obligations
The requirements that touch IAM
- A.5.15 Access control — rules governing physical and logical access
- A.5.16 Identity management — full lifecycle of identities
- A.5.17 Authentication information — secure handling of credentials
- A.5.18 Access rights — provisioning, review and revocation
- A.8.2 Privileged access rights — restricted and managed allocation
- A.8.5 Secure authentication — strong authentication techniques
Control mapping
Requirement → IamLogic control
The table your compliance team and your auditor both want: each identity-relevant requirement, the product control that implements it, and which product it lives in.
| Requirement | IamLogic control | Product |
|---|---|---|
| A.5.15 / A.5.18: rights provisioned, reviewed, revoked per policy | Role-based provisioning, certification campaigns and automated revocation with full trails | IamLogic IGA |
| A.5.16: identity lifecycle management | Joiner–mover–leaver automation from authoritative sources | IamLogic IGA |
| A.5.17: authentication information protection | Credential vaulting with automatic rotation for legacy apps; SSPR with policy controls | Access Manager |
| A.8.2: privileged access restraint | Just-in-time, time-bound elevated access and SoD policies | IamLogic IGA |
| A.8.5: secure authentication | MFA and passwordless WebAuthn with adaptive step-up | Access Manager |
This page is provided for general information and maps regulatory expectations to IamLogic product capabilities. It is not legal advice. Regulatory obligations and timelines evolve — confirm your organisation's specific requirements with your compliance counsel.
FAQ
Common questions
Will IamLogic help with our certification audit itself?
Beyond the product, our services team offers ISO 27001-aligned consulting — assessing your identity controls and aligning them with both the standard and the platform's capabilities. We've been through the audit ourselves.
Map ISO 27001 to your environment
A working session with our engineers: your systems, this framework's requirements, and a concrete gap list you keep either way.