Skip to content
Phishing for Trouble –
The IO Podcast returns for Series 2
Listen now



What Is The Purpose of Annex A 5.32?

ISO 27001:2022 Annex A 5.32 describes the steps organisations need to take to ensure compliance with intellectual property (IP) rights, including using proprietary software purchased, subscribed to, or leased from a third party.

According to ISO, intellectual property rights fall into one or more of the following categories:

  • Trademark rights.
  • Patents.
  • Source code licences.
  • Software copyright.
  • Document copyright.
  • Design rights.

“Legal, statutory, regulatory or contractual” agreements often place restrictions on the use of proprietary software, including restrictions on copying, extracting, or reverse-engineering the source code. ISO 27001:2022 Annex A 5.32 does not cover situations where the organisation is the IP holder but focuses instead on their obligations towards third parties whose intellectual property rights are covered by licence agreements, data sharing agreements, etc.

Copyright and/or IP infringement can lead to severe financial & legal consequences for any organisation that wilfully or unwittingly breaches an agreement. For this reason, Annex A 5.32 should be given adequate consideration in order to avoid any unnecessary business interruptions or information security incidents.




ISMS.online gives you an 81% Headstart from the moment you log on

ISO 27001 made easy

We’ve done the hard work for you, giving you an 81% Headstart from the moment you log on. All you have to do is fill in the blanks.




General Guidance on Annex A 5.32

ISO 27001:2022 Annex A 5.32 is a preventive control that maintains risk by enforcing procedures that ensure that the business remains compliant with any prevailing IP or copyright requirements, including mitigating the risk that employees will not adhere to their own obligations.

According to Annex A 5.32, organisations should consider the following guidelines when safeguarding data, software, or assets that might be regarded as intellectual property:

  • Protecting IP rights on a case-by-case basis, in accordance with their unique operational requirements by implementing a “topic-specific” policy.
  • To remain compliant with IP standards, publish and communicate procedures that categorically define how software and ICT products should be operated.
  • To avoid any inadvertent copyright breaches, acquire software from reputable sources.
  • Identification of ICT assets with IP requirements using an organisational asset register.
  • The organisation should be able to provide proof of ownership at any time, including physical and electronic licensing documents, communications, and files.
  • Complying with software usage limits, including concurrent users, virtual resources and more.
  • Through periodic reviews, ensure the organisation’s ICT estate doesn’t contain any unlicensed or unauthorised software.
  • Keep licenses up-to-date through operational and financial procedures.
  • Provide safe, responsible, and legally compliant practices for the transfer or disposal of software assets.
  • Ensure that any software acquired from the public domain complies with the terms and conditions and fair use guidelines.
  • Any commercial recordings used by the organisation may not be extracted, copied, converted, or manipulated in any way that is not specified within the software’s terms and conditions (including licensing) or by prevailing copyright laws.
  • Observing and respecting the copyright laws or licensing terms of textual data, such as standards, books, articles, and reports.

What Are the Changes From ISO 27001:2013?

ISO 27001:2022 Annex A 5.32 replaces ISO 27001:2013 Annex A 18.1.2 (Intellectual Property Rights).

Generally speaking, ISO 27001:2022 Annex A 5.31 contains the same set of guidelines as its 2013 counterpart, with two minor changes:

  • ISO 27001:2022 Annex A 5.31 provides advice on how to manage IP-related issues under a data-sharing agreement.
  • ISO 27001:2013 Annex A 18.1.2 does not mention the residual benefits to organisations seeking to manage employee behaviour toward IP agreements and using software.

Table of All ISO 27001:2022 Annex A Controls

In the table below you’ll find more information on each individual ISO 27001:2022 Annex A Control.

ISO 27001:2022 Organisational Controls
Annex A Control Type ISO/IEC 27001:2022 Annex A Identifier ISO/IEC 27001:2013 Annex A Identifier Annex A Name
Organisational Controls Annex A 5.1 Annex A 5.1.1
Annex A 5.1.2
Policies for Information Security
Organisational Controls Annex A 5.2 Annex A 6.1.1 Information Security Roles and Responsibilities
Organisational Controls Annex A 5.3 Annex A 6.1.2 Segregation of Duties
Organisational Controls Annex A 5.4 Annex A 7.2.1 Management Responsibilities
Organisational Controls Annex A 5.5 Annex A 6.1.3 Contact With Authorities
Organisational Controls Annex A 5.6 Annex A 6.1.4 Contact With Special Interest Groups
Organisational Controls Annex A 5.7 NEW Threat Intelligence
Organisational Controls Annex A 5.8 Annex A 6.1.5
Annex A 14.1.1
Information Security in Project Management
Organisational Controls Annex A 5.9 Annex A 8.1.1
Annex A 8.1.2
Inventory of Information and Other Associated Assets
Organisational Controls Annex A 5.10 Annex A 8.1.3
Annex A 8.2.3
Acceptable Use of Information and Other Associated Assets
Organisational Controls Annex A 5.11 Annex A 8.1.4 Return of Assets
Organisational Controls Annex A 5.12 Annex A 8.2.1 Classification of Information
Organisational Controls Annex A 5.13 Annex A 8.2.2 Labelling of Information
Organisational Controls Annex A 5.14 Annex A 13.2.1
Annex A 13.2.2
Annex A 13.2.3
Information Transfer
Organisational Controls Annex A 5.15 Annex A 9.1.1
Annex A 9.1.2
Access Control
Organisational Controls Annex A 5.16 Annex A 9.2.1 Identity Management
Organisational Controls Annex A 5.17 Annex A 9.2.4
Annex A 9.3.1
Annex A 9.4.3
Authentication Information
Organisational Controls Annex A 5.18 Annex A 9.2.2
Annex A 9.2.5
Annex A 9.2.6
Access Rights
Organisational Controls Annex A 5.19 Annex A 15.1.1 Information Security in Supplier Relationships
Organisational Controls Annex A 5.20 Annex A 15.1.2 Addressing Information Security Within Supplier Agreements
Organisational Controls Annex A 5.21 Annex A 15.1.3 Managing Information Security in the ICT Supply Chain
Organisational Controls Annex A 5.22 Annex A 15.2.1
Annex A 15.2.2
Monitoring, Review and Change Management of Supplier Services
Organisational Controls Annex A 5.23 NEW Information Security for Use of Cloud Services
Organisational Controls Annex A 5.24 Annex A 16.1.1 Information Security Incident Management Planning and Preparation
Organisational Controls Annex A 5.25 Annex A 16.1.4 Assessment and Decision on Information Security Events
Organisational Controls Annex A 5.26 Annex A 16.1.5 Response to Information Security Incidents
Organisational Controls Annex A 5.27 Annex A 16.1.6 Learning From Information Security Incidents
Organisational Controls Annex A 5.28 Annex A 16.1.7 Collection of Evidence
Organisational Controls Annex A 5.29 Annex A 17.1.1
Annex A 17.1.2
Annex A 17.1.3
Information Security During Disruption
Organisational Controls Annex A 5.30 NEW ICT Readiness for Business Continuity
Organisational Controls Annex A 5.31 Annex A 18.1.1
Annex A 18.1.5
Legal, Statutory, Regulatory and Contractual Requirements
Organisational Controls Annex A 5.32 Annex A 18.1.2 Intellectual Property Rights
Organisational Controls Annex A 5.33 Annex A 18.1.3 Protection of Records
Organisational Controls Annex A 5.34 Annex A 18.1.4 Privacy and Protection of PII
Organisational Controls Annex A 5.35 Annex A 18.2.1 Independent Review of Information Security
Organisational Controls Annex A 5.36 Annex A 18.2.2
Annex A 18.2.3
Compliance With Policies, Rules and Standards for Information Security
Organisational Controls Annex A 5.37 Annex A 12.1.1 Documented Operating Procedures
ISO 27001:2022 People Controls
Annex A Control Type ISO/IEC 27001:2022 Annex A Identifier ISO/IEC 27001:2013 Annex A Identifier Annex A Name
People Controls Annex A 6.1 Annex A 7.1.1 Screening
People Controls Annex A 6.2 Annex A 7.1.2 Terms and Conditions of Employment
People Controls Annex A 6.3 Annex A 7.2.2 Information Security Awareness, Education and Training
People Controls Annex A 6.4 Annex A 7.2.3 Disciplinary Process
People Controls Annex A 6.5 Annex A 7.3.1 Responsibilities After Termination or Change of Employment
People Controls Annex A 6.6 Annex A 13.2.4 Confidentiality or Non-Disclosure Agreements
People Controls Annex A 6.7 Annex A 6.2.2 Remote Working
People Controls Annex A 6.8 Annex A 16.1.2
Annex A 16.1.3
Information Security Event Reporting
ISO 27001:2022 Physical Controls
Annex A Control Type ISO/IEC 27001:2022 Annex A Identifier ISO/IEC 27001:2013 Annex A Identifier Annex A Name
Physical Controls Annex A 7.1 Annex A 11.1.1 Physical Security Perimeters
Physical Controls Annex A 7.2 Annex A 11.1.2
Annex A 11.1.6
Physical Entry
Physical Controls Annex A 7.3 Annex A 11.1.3 Securing Offices, Rooms and Facilities
Physical Controls Annex A 7.4 NEW Physical Security Monitoring
Physical Controls Annex A 7.5 Annex A 11.1.4 Protecting Against Physical and Environmental Threats
Physical Controls Annex A 7.6 Annex A 11.1.5 Working In Secure Areas
Physical Controls Annex A 7.7 Annex A 11.2.9 Clear Desk and Clear Screen
Physical Controls Annex A 7.8 Annex A 11.2.1 Equipment Siting and Protection
Physical Controls Annex A 7.9 Annex A 11.2.6 Security of Assets Off-Premises
Physical Controls Annex A 7.10 Annex A 8.3.1
Annex A 8.3.2
Annex A 8.3.3
Annex A 11.2.5
Storage Media
Physical Controls Annex A 7.11 Annex A 11.2.2 Supporting Utilities
Physical Controls Annex A 7.12 Annex A 11.2.3 Cabling Security
Physical Controls Annex A 7.13 Annex A 11.2.4 Equipment Maintenance
Physical Controls Annex A 7.14 Annex A 11.2.7 Secure Disposal or Re-Use of Equipment
ISO 27001:2022 Technological Controls
Annex A Control Type ISO/IEC 27001:2022 Annex A Identifier ISO/IEC 27001:2013 Annex A Identifier Annex A Name
Technological Controls Annex A 8.1 Annex A 6.2.1
Annex A 11.2.8
User Endpoint Devices
Technological Controls Annex A 8.2 Annex A 9.2.3 Privileged Access Rights
Technological Controls Annex A 8.3 Annex A 9.4.1 Information Access Restriction
Technological Controls Annex A 8.4 Annex A 9.4.5 Access to Source Code
Technological Controls Annex A 8.5 Annex A 9.4.2 Secure Authentication
Technological Controls Annex A 8.6 Annex A 12.1.3 Capacity Management
Technological Controls Annex A 8.7 Annex A 12.2.1 Protection Against Malware
Technological Controls Annex A 8.8 Annex A 12.6.1
Annex A 18.2.3
Management of Technical Vulnerabilities
Technological Controls Annex A 8.9 NEW Configuration Management
Technological Controls Annex A 8.10 NEW Information Deletion
Technological Controls Annex A 8.11 NEW Data Masking
Technological Controls Annex A 8.12 NEW Data Leakage Prevention
Technological Controls Annex A 8.13 Annex A 12.3.1 Information Backup
Technological Controls Annex A 8.14 Annex A 17.2.1 Redundancy of Information Processing Facilities
Technological Controls Annex A 8.15 Annex A 12.4.1
Annex A 12.4.2
Annex A 12.4.3
Logging
Technological Controls Annex A 8.16 NEW Monitoring Activities
Technological Controls Annex A 8.17 Annex A 12.4.4 Clock Synchronization
Technological Controls Annex A 8.18 Annex A 9.4.4 Use of Privileged Utility ProgramsAccess Rights
Technological Controls Annex A 8.19 Annex A 12.5.1
Annex A 12.6.2
Installation of Software on Operational Systems
Technological Controls Annex A 8.20 Annex A 13.1.1 Networks Security
Technological Controls Annex A 8.21 Annex A 13.1.2 Security of Network Services
Technological Controls Annex A 8.22 Annex A 13.1.3 Segregation of Networks
Technological Controls Annex A 8.23 NEW Web filtering
Technological Controls Annex A 8.24 Annex A 10.1.1
Annex A 10.1.2
Use of Cryptography
Technological Controls Annex A 8.25 Annex A 14.2.1 Secure Development Life Cycle
Technological Controls Annex A 8.26 Annex A 14.1.2
Annex A 14.1.3
Application Security Requirements
Technological Controls Annex A 8.27 Annex A 14.2.5 Secure System Architecture and Engineering PrinciplesLearning From Information Security Incidents
Technological Controls Annex A 8.28 NEW Secure Coding
Technological Controls Annex A 8.29 Annex A 14.2.8
Annex A 14.2.9
Security Testing in Development and Acceptance
Technological Controls Annex A 8.30 Annex A 14.2.7 Outsourced Development
Technological Controls Annex A 8.31 Annex A 12.1.4
Annex A 14.2.6
Separation of Development, Test and Production Environments
Technological Controls Annex A 8.32 Annex A 12.1.2
Annex A 14.2.2
Annex A 14.2.3
Annex A 14.2.4
Change Management
Technological Controls Annex A 8.33 Annex A 14.3.1 Test Information
Technological Controls Annex A 8.34 Annex A 12.7.1 Protection of Information Systems During Audit Testing




NHS Professionals achieves ISO 27001 certification and improves their infosec management logo
ISO 27001 Healthcare Enterprise

NHS Professionals achieves ISO 27001 certification and improves their infosec management

Facing a tight six-month deadline and multiple existing frameworks to integrate, NHS Professionals needed a platform that could incorporate ISO 27001 without duplicating policies or adding risk to their already complex compliance landscape.

Xergy tool Proteus generates growth through ISO 27001 compliance using ISMS.online logo
ISO 27001 IT & Services Medium business

Xergy tool Proteus generates growth through ISO 27001 compliance using ISMS.online

As a start-up building software for highly regulated engineering sectors, Xergy needed ISO 27001 to generate growth through trust — and a proven external partner to handle the rigorous requirements without diverting the dev team.

How Blue Services Achieved Triple ISO Certification Success logo
ISO 14001 Technology Small business

How Blue Services Achieved Triple ISO Certification Success

Blue Services needed external support to guide them through ISO 27001, ISO 9001 and ISO 14001 implementation and best practices, and a platform to centralise their overall compliance management.

How Evolution Funding Cruised to ISO 27001 Certification Success logo
ISO 27001 FinTech Medium business

How Evolution Funding Cruised to ISO 27001 Certification Success

Achieving ISO 27001 certification was a core objective for Evolution Funding. The team needed a centralised platform with which they could implement the ISO 27001 standard and work through the compliance process.

How 4way Consulting Paved the Road to ISO 27001 Success logo
Multiple Standards Technology Small business

How 4way Consulting Paved the Road to ISO 27001 Success

Handling sensitive client data across multiple standards, 4way needed a cost and time-efficient way to pursue ISO 27001 – without building an ISMS from scratch or relying on expensive external consultants.

nesevo's Multi-Certification Compliance Success with IO logo
Multiple Standards IT & Services Small business

nesevo’s Multi-Certification Compliance Success with IO

Struggling to manage ISO 27001 compliance across scattered documents and spreadsheets, nesevo needed a centralised platform that could guide them through the standard without the ongoing cost of external consultants.




How ISMS.online Help

ISMS.online streamlines the ISO 27001:2022 implementation process by providing a sophisticated cloud-based framework for documenting information security management system procedures and checklists to assure compliance with recognised standards.

Get in touch today to book a short demo.


Toby Cane

Partner Customer Success Manager

Toby Cane is the Senior Partner Success Manager for ISMS.online. He has worked for the company for close to 4 years and has performed a range of roles, including hosting their webinars. Prior to working in SaaS, Toby was a Secondary School teacher.

ISO 27001:2022 Annex A Controls

Organisational Controls