/ solutionsISO/IEC 27001:2022 Certification

Automate ISO 27001 Access Reviews & Annex A Controls

Fulfill ISO/IEC 27001:2022 controls for access rights management, privileged access rights, and authentication information with continuous discovery and closed-loop enforcement.

View Published Pricing

ISO 27001:2022 Access Control Requirements

The updated ISO/IEC 27001:2022 standard places stringent demands on how organizations manage user access, privilege sprawl, and authentication secrets. Specifically, Annex A controls require comprehensive, demonstrable governance:

  • Control 5.15 (Access Control): Rules for access control must be established, documented, and reviewed periodically based on business requirements.
  • Control 5.16 (Identity Management): The full lifecycle of identities — provisioning, modifying, and de-registering — must be continuously managed.
  • Control 5.18 (Access Rights): User access rights must be allocated and reviewed at regular intervals or upon role change.
  • Control 8.2 (Privileged Access Rights): The allocation and use of privileged access rights must be restricted and controlled.

The Non-Human Identity Blindspot: ISO 27001 auditors increasingly scrutinize machine identities (API keys, service principals, automated deployment tokens). If your access control review only includes human employees and ignores service accounts, you face immediate audit non-conformities.

How NDGM Meets Annex A Controls Out-of-the-Box

CONTROL 5.15 & 5.18

Blueprint-Driven Certifications

Configure role-based governance blueprints that trigger recurring access certifications. Department managers certify access with contextual AI insights.

CONTROL 8.2

Privileged Access Monitoring

Flags standing administrator privileges in cloud environments (AWS, Azure, GCP) and SaaS tools. Enforces just-in-time or ephemeral access principles.

CONTROL 5.16

Automated Joiner-Mover-Leaver

Syncs with your HR sources (Workday, BambooHR, HiBob) to identify orphaned accounts from leavers or role transitions across all downstream applications.

CONTROL 5.17

Authentication Information Management

Reeve Edge Agent uncovers sprawled API keys, dotfiles, and secrets on developer endpoints, automatically scheduling rotation and vaulting into Keeper.

Audit-Ready Evidence for Certification Bodies

During BSI, LRQA, or DNV surveillance audits, presenting disorganized tickets and manual email threads invites deeper sampling. NDGM generates standardized, tamper-evident verification files that certify:

  • 100% of active accounts mapped to an identified owner and business purpose.
  • Zero dormant accounts active beyond your defined retention policy (e.g. 30/60/90 days).
  • Demonstrated segregation of duties (SoD) across development, deployment, and administrative roles.
  • Immutable SHA-256 evidence logs proving each review decision was finalized without retrospective alteration.

UK Sovereignty & Data Residency

NDGM is developed and operated entirely within the United Kingdom. For organizations subject to UK GDPR and strict information security policies, our sovereign self-host option ensures that identity graphs, employee directories, and credentials never cross borders or touch third-party model providers.

GOVERNANCE THAT FIXES WHAT IT FINDS

Ready to automate your identity certifications?

Connect your first identity source in 15 minutes. 100% evidence-backed, immutable SHA-256 audit packs, deployed in your estate.

© 2026 NDGM · United Kingdom[email protected]

NDGM is a trading name of Agile Tech Global Solutions Limited, registered in England and Wales (company no. 14654678). Registered office: 27 Old Gloucester Street, London, WC1N 3AX. VAT registration no. GB 486 3793 36.