Skip to content
arrow_back
verifiedISO/IEC 27001:2022

ISO 27001 Annex A 8.18Use of Privileged Utility Programs

Restrict and control programs that can override system controls to prevent unauthorised access.

Technological controlsPreventativeISO/IEC 27001:2022Software installPrivileged utilities
record_voice_over

Plain language

This control is about limiting and keeping a close eye on special programs that can bypass your computer''s security settings. If these programs are not controlled, someone might misuse them to sneak into your systems and access sensitive information.

Framework

ISO/IEC 27001:2022

Control effect

Preventative

ISO 27001 domain

Technological controls

Classifications

N/A

Official last update

24 Oct 2022

Control Stack last updated

18 June 2026

Official control statement

The use of utility programs that can be capable of overriding system and application controls shall be restricted and tightly controlled.
verifiedISO/IEC 27001:2022Annex A 8.18
priority_high

Why it matters

Uncontrolled access to privileged programs can lead to data breaches, compromising sensitive information and potentially harming organisational reputation.

settings

Operational notes

Regularly review and update access permissions for utility programs to ensure they remain properly controlled as staff roles change.

build

Implementation tips

  • The IT manager should identify which utility programs can override system controls. This involves reviewing all software used within the organisation and categorising those capable of bypassing security settings.
  • IT staff should restrict access to these programs to only a select few responsible employees. This can be done by setting up user permissions and ensuring only authorised personnel have access.
  • Human Resources, together with IT, should define clear authorisation levels for using these utility programs. This means formalising what level of access each employee will have based on their role.
  • Regular training sessions led by IT should educate employees on the proper use of these programs. This includes awareness on why restrictions are necessary and the risks of improper use.
  • Continuous monitoring should be conducted by the IT department to log and review the use of these programs. Setting up automated logging systems ensures there's an audit trail of who accessed what and when.
fact_check

Audit / evidence tips

  • Askthe list of utility programs identified by the organisationLook atwhether these programs are capable of bypassing key security controlsGooda comprehensive list that explains the function and potential risk of each program
  • Askto see the access logs for these utility programsLook atwho accessed the programs and how oftenGoodregular reviews of access logs indicating no unauthorised use
  • Askthe authorisation and access control policy documentsLook athow access is granted and managed for utility programsGoodclear policies that align with restricted access practices
  • Askrecords of employee training regarding the use of utility programsLook atthe frequency, content, and list of attendeesGoodregular training sessions with a majority of relevant staff participating
  • Askdetails on how unauthorised use of utility programs is detectedLook atthe systems in place for real-time alerts and follow-up actionsGoodconsistent monitoring with proactive alerts and investigations for any anomalies
link

Cross-framework mappings

How Annex A 8.18 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

E8

ControlNotesDetails
sync_altPartially overlaps(5)expand_less
handshakeSupports(2)expand_less

ASD ISM

ControlNotesDetails
sync_altPartially overlaps(4)expand_less
ISM-1491Annex A 8.18 requires restricting and tightly controlling utility programs that can override system and application controls, addressing ...
ISM-1592Annex A 8.18 requires that use of utility programs capable of overriding system and application controls is restricted and tightly contro...
ISM-1657Annex A 8.18 requires restricting and tightly controlling use of utility programs that can override system and application controls, effe...
ISM-1658Annex A 8.18 requires tight restriction of utilities capable of overriding system and application controls, which includes mechanisms tha...
handshakeSupports(6)expand_less
ISM-0382ISM-0382 requires that unprivileged users cannot uninstall or disable approved applications
ISM-0846Annex A 8.18 requires that utilities capable of overriding system and application controls are restricted and tightly controlled, which c...
ISM-1584ISM-1584 ensures that unprivileged users are prevented from bypassing, disabling or modifying operating system security functionality
ISM-1746Annex A 8.18 requires restricting and tightly controlling utilities that could override system and application controls, which relies on ...
ISM-1748ISM-1748 requires preventing users from changing security settings in email clients
ISM-2023Annex A 8.18 requires tight control over tools and utilities that can override system and application controls, including controlling how...

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all Technological controls controls, or browse the full ISO 27001 library. You can also track all 93 controls with the free ISO 27001 Annex A checklist.

school

Want to implement this control?

Mindset Cyber runs PECB-accredited ISO/IEC 27001 training that maps directly to the controls in this library.

Mapping detail

Mapping

Direction

Controls