SekitCrosswalk
ISO/IEC 27001:2022 · derived mapping target

A.5.32Intellectual property rights

Protect intellectual property and respect the rights of others, including software licensing terms. This avoids both legal exposure and the misuse of your own valuable assets.

Mapping at a glance

A.5.32 is covered by 2 Sekit CSF controls. Open in the full graph

Mapped from the Sekit CSF

The Sekit controls that cover this requirement, lens by lens.

NIST CSF 2.0 counterparts

Reached through the Sekit CSF controls both map to — a mapping, not a formal equivalence.

ISO/IEC 42001:2023 — Annex A counterparts

Cyber Essentials counterparts

Evidence that proves this control

What an auditor, or Sekit's evidence engine, asks for.

Software and SaaS inventory
The list of installed software and cloud apps the company uses, with their licences, and a sense of which tools people use that are not officially approved.
From the Sekit evidence catalog

In practice

IP exposure at most SMEs comes from software, not trademarks: unlicensed copies, expired subscriptions still running in production, and tools an employee signed up for on a personal card that nobody tracked. The inventory that would catch this often exists as a spreadsheet nobody updates after the initial rollout. A working control requires new software to be requested and approved before installation, keeps licence counts and renewal dates current in the register, and removes tools the moment a subscription lapses or a project ends, so a vendor audit does not surface unlicensed seats.

Common gaps

The software inventory was built once during setup and has not been updated as new tools and SaaS subscriptions were added.
Employees install software with personal credit cards and no approval step, so unlicensed or unsupported tools end up handling company data.
Licence counts in the register do not match what a vendor's true-up audit reports, exposing the company to unbudgeted licensing fees.

Questions your auditor will ask

Where is the current list of software the company uses and licenses?
In the software and SaaS inventory, which records each tool, its licence status, and the person who owns it.
How does someone get approval before installing new software?
They submit a request, the tool is checked for licensing and security fit, and only approved software gets added to the inventory.
What happens to a software licence once the tool is no longer needed?
It is removed from the inventory and the subscription is cancelled, closing off an unused entry point into company systems.

Where regulation demands it

NIS2 12.4 requires a maintained asset inventory, and ENS op.exp.1 sets the same expectation for Spanish public-sector suppliers tracking every software asset in use.
NIS2 6.9 covers protection against unauthorised software, which an enforced approval step for new tools directly addresses.

Related controls

Via the shared Sekit CSF topic, not the framework's own index.

Ask Sekura: “What evidence proves A.5.32?”
Also via MCP, free with account