SekitCrosswalk
ISO/IEC 27001:2022 · derived mapping target

A.8.18Use of privileged utility programs

Restrict and closely control powerful utility programs that can override normal system and security controls, since they can bypass your other safeguards.

Mapping at a glance

A.8.18 is covered by 2 Sekit CSF controls. Open in the full graph

Mapped from the Sekit CSF

The Sekit controls that cover this requirement, lens by lens.

NIST CSF 2.0 counterparts

Reached through the Sekit CSF controls both map to — a mapping, not a formal equivalence.

Cyber Essentials counterparts

Evidence that proves this control

What an auditor, or Sekit's evidence engine, asks for.

Local admin and removable-media controls
The rules on who may have administrator rights on their own device and on the use of USB sticks and external drives.
From the Sekit evidence catalog

In practice

Privileged utility programs, the tools that can bypass normal controls like disk editors, debuggers or admin scripting consoles, need the same discipline as admin accounts themselves. What works: keep the list of who can run these tools short and tied to job need, require approval before use, and log every session so there is a record if something goes wrong. Vaulting the credentials that unlock these utilities, rather than leaving them on a shared script or a note, is the difference auditors check for. The common failure is a legacy admin script with hardcoded credentials that everyone on the IT team can run.

Common gaps

A legacy administrative script with hardcoded credentials still runs on several servers, and nobody has an inventory of who has access to trigger it.
Privileged utility use is not logged separately from regular admin activity, so a misuse of a bypass tool would blend into normal noise.
Approval for privileged tool access exists for new hires but was never re-verified for staff who changed roles and kept their old permissions.

Questions your auditor will ask

Who can run tools capable of bypassing normal security controls, and how is that access approved?
Access is limited to a short, approved list tied to job need, granted through the same privileged access approval process as administrator accounts.
Is every use of a privileged utility program logged?
Yes, sessions using these tools are logged and monitored the same way other privileged account activity is, so unusual use gets flagged.
How are the credentials for these powerful tools protected from casual access?
Credentials are vaulted rather than shared in scripts or documents, and checkout is tracked so each use is attributable to a specific person.

Where regulation demands it

NIS2 art. 11.3 requires controls specifically for privileged and administrative accounts, which extends to the tools they can run. ENS op.acc.3 expects segregation of duties that limits who can use powerful bypass tools.

Related controls

Via the shared Sekit CSF topic, not the framework's own index.

Ask Sekura: “What evidence proves A.8.18?”
Also via MCP, free with account