ISO 27001:2022 Annex A Control 5.32: Intellectual Property Rights
Annex A control 5.32 of the 2022 version of the ISO 27001 standard can be mapped to ISO27001:2013 Annex A 18.1.2

Control 5.32 covers the necessity for, and steps towards, achieving compliance with intellectual property (IP) rights. This includes covering the use of proprietary software, whether it’s purchased, subscribed to or leased from a third party.
ISO defines intellectual property rights as falling into one or more of the following categories: patents, trademark rights, design rights, source code licenses, software copyright and document copyright.
{{snapshot}}
Control 5.32 at a glance
- What it covers: compliance with intellectual property rights, including proprietary software that is purchased, subscribed to or leased.
- Six IP categories: patents, trademark rights, design rights, source-code licences, software copyright and document copyright.
- A preventative control: proactive procedures that help the business — and individual employees — stay IP-compliant.
- Lineage: maps to ISO 27001:2013 Annex A control 18.1.2.
{{/snapshot}}
Understanding intellectual property rights
Agreements – whether they be legal, statutory, regulatory, or contractual – commonly place restrictions on the use of proprietary software. This can include restrictions on copying, extracting and reverse-engineering source codes.
Control 5.32 focuses on an organisation’s obligation towards third parties whose intellectual property they seek, with IP rights covered by data sharing agreements, licence agreements and more.
The risks of copyright infringement and IP infringement are severe, with financial and legal consequences. It’s vital that businesses study Control 5.32 carefully to avoid unnecessary information security incidents and interruptions.
Guidelines for IP in control 5.32
As a preventative control, control 5.32 looks to mitigate risks by encouraging proactive procedures to ensure IP compliance. This includes helping employees adhere to business obligations on an individual level.
When safeguarding data, assets or software that might be listed as IP, organisations need to consider 12 key guidelines. These are:
- Implementing a topic-specific policy to protect IP rights on a case-by-case basis, taking unique operational requirements into account.
- Publishing and sharing procedures that define how software and products should be operated to remain compliant with IP standards.
- Acquiring software from trusted sources to avoid inadvertent copyright breaches.
- Using an organisational asset register to identify ICT assets with IP requirements.
- Providing proof of ownership whenever necessary, whether it be physical or electronic licensing documents, communications, or files.
- Ensuring compliance with software usage limits such as virtual resources and concurrent users.
- Making sure no unlicensed or unauthorised software is used by conducting periodic reviews.
- Operational and financial procedures to make sure licenses are kept up to date.
- Ensuring the transfer and disposal of software assets is secure and compliant by providing responsible and safe practices.
- Complying with the terms and conditions and fair use guidelines when acquiring software from the public domain.
- Extracting, copying, converting or manipulating commercial recordings must be done in a way that falls in line with the software’s terms and conditions, or by prevailing copyright laws.
- Respecting copyright laws and licensing terms attached to textual data, including articles, reports, books, and standards.
{{snapshot}}
Staying IP-compliant: the essentials
- Policy and procedures: a topic-specific IP policy plus operating procedures that keep software use compliant.
- Trusted sourcing: acquire software from trusted sources and honour usage limits such as concurrent users and virtual resources.
- Asset register and proof: use an organisational asset register to track ICT assets and hold proof of ownership or licensing.
- Periodic reviews: check that no unlicensed or unauthorised software is used and keep licences up to date.
- Secure lifecycle: handle transfer and disposal responsibly and respect terms for public-domain and copyrighted material.
{{/snapshot}}
What has changed since ISO 27001:2013?
Replacing Annex A control 18.1.2 from ISO 27001:2013, control 5.32 contains much of the same guidelines, but with two significant changes. The first is that the more updated version now contains advice on how to manage IP-related issues under a data-sharing agreement.
Secondly, the 2013 version contained no mention of the potential benefits of managing employee behaviours towards IP agreements.
| Aspect | ISO 27001:2013 (18.1.2) | ISO 27001:2022 (5.32) |
|---|---|---|
| IP under data-sharing agreements | Not addressed | Advice now included |
| Managing employee behaviour toward IP | Not mentioned | Potential benefits recognised |
{{snapshot}}
What Hicomply recommends
Treat IP compliance as an asset-management problem: keep a live register of every piece of licensed software, attach the proof of entitlement, and review usage on a schedule rather than at audit time. Doing this once inside your ISMS means the same evidence answers customer, legal and certification questions. Our ISO 27001 hub walks through where control 5.32 fits.
{{/snapshot}}
Ready to Take Control of Your Privacy Compliance?
See how Hicomply can accelerate your path to CAF compliance in a 15-minute demo.


.avif)




















