Back to all 93 controls
Annex A 8.2
Technological
A.8.2 Privileged access rights
Restrict and monitor privileged access.
What good looks like
Privileged accounts inventoried, JIT/JEA where possible, session logging.
Evidence an auditor will ask for
PAM reports, privileged account list, session logs.
Reviewed & Verified by a Certified ISO/IEC 27001 Lead Implementer
Built for practitioners, by practitioners. Every template, control definition, and audit checklist in this directory is aligned with the latest ISO 27001:2022 standard and structured around real-world certification audit requirements.
Certified Lead Implementer
2022 Standard Aligned
Audit-Ready Materials
Put this control into practice
Check whether your organisation already meets Annex A 8.2 with the free Gap Analysis tool, or get implementation-ready templates for every Annex A control with the Document Pack.
