Skip to content
arrow_back
search
Annex A 5.16 verified ISO/IEC 27001:2022

Identity life cycle management

Ensure all user and system identities are managed from creation to deactivation.

record_voice_over

Plain language

This control is about managing who can access your organisation's information by properly handling identities from the moment they are created until they are no longer needed. If you don't keep track of identities like usernames and passwords, former employees or unauthorised users could access sensitive information, leading to data breaches or other security problems.

Framework

ISO/IEC 27001:2022

Control effect

Preventative

ISO 27001 domain

Organisational controls

Classifications

N/A

Official last update

24 Oct 2022

Control Stack last updated

19 Mar 2026

Maturity levels

N/A

Official control statement

The full life cycle of identities shall be managed.
verified ISO/IEC 27001:2022 Annex A 5.16
priority_high

Why it matters

Poor identity life cycle management leaves stale and orphaned accounts active, increasing the chance of unauthorised access and data breaches.

settings

Operational notes

Regularly review joiner/mover/leaver events, reconcile identity records, and disable or remove accounts promptly to prevent orphaned access paths.

Mapping detail

Mapping

Direction

Controls