Intellectual property rights
Purpose
Put procedures in place to protect intellectual property rights and ensure compliant use of proprietary products.
How to meet this control
In short: Implement procedures to protect intellectual property rights.
- Step 01Publish an intellectual property policy and prohibit unlicensed or unauthorised software in the Acceptable Use Policy
- Step 02Maintain a software licence register with proof of ownership and stay within licensed user or resource limits
- Step 03Acquire software only from known reputable sources to avoid copyright infringement
- Step 04Run periodic scans for unauthorised or unlicensed software across endpoints
- Step 05Define procedures for licence transfer and for disposing of software securely
Tip: Track software licences and prohibit unlicensed software in your AUP.
What ISO 27002 says to cover
Reference points from the ISO/IEC 27002:2022 guidance for this control. Use them to check the steps above cover everything relevant to you.
- ›Define and communicate a topic-specific policy on protecting intellectual property rights
- ›Publish procedures defining compliant use of software and information products
- ›Acquire software only from known, reputable sources to avoid infringing copyright
- ›Keep asset registers and retain proof of ownership for licences and manuals
- ›Stay within licensed user or resource limits and review installations for unauthorised software
- ›Provide procedures for maintaining licence conditions and for disposing of or transferring software
- ›Comply with terms for material from public networks and outside sources
- ›Do not copy or convert copyrighted material beyond what the licence permits
Audit evidence to keep
- - Intellectual property or software use policy
- - Software licence register with proof of ownership and current entitlements
- - Records of software audits checking for unauthorised installations
- - Evidence that software is sourced from reputable suppliers
Common mistakes
- - Writing a policy but not operating the process
- - Keeping evidence in personal folders where auditors cannot trace it
- - Letting exceptions stay open with no owner or expiry date
Owner, cadence, and proof
Assign one accountable owner for A.5.32. Review this control at least annually, after related incidents, and whenever the underlying process, supplier, system, office, or legal obligation changes. The control is audit-ready when the owner can show the policy or procedure, the latest operating evidence, the latest review, and any open exceptions with due dates.
Policy templates for this control
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.