Skip to content
arrow_back
search
Annex A 8.18 verified ISO/IEC 27001:2022

Use of Privileged Utility Programs

Restrict and control programs that can override system controls to prevent unauthorised access.

Technological controls Preventative ISO/IEC 27001:2022software installprivileged utilities
record_voice_over

Plain language

This control is about limiting and keeping a close eye on special programs that can bypass your computer''s security settings. If these programs are not controlled, someone might misuse them to sneak into your systems and access sensitive information.

Framework

ISO/IEC 27001:2022

Control effect

Preventative

ISO 27001 domain

Technological controls

Classifications

N/A

Official last update

24 Oct 2022

Control Stack last updated

30 Mar 2026

Maturity levels

N/A

Official control statement

The use of utility programs that can be capable of overriding system and application controls shall be restricted and tightly controlled.
verified ISO/IEC 27001:2022 Annex A 8.18
priority_high

Why it matters

Uncontrolled access to privileged programs can lead to data breaches, compromising sensitive information and potentially harming organisational reputation.

settings

Operational notes

Regularly review and update access permissions for utility programs to ensure they remain properly controlled as staff roles change.

Mapping detail

Mapping

Direction

Controls