ISO/IEC 27001

⌘K
  1. Home
  2. Docs
  3. ISO/IEC 27001
  4. 2. ISO 27001 Annex A Cont...
  5. ISO 27001 Annex A 5.32 Intellectual property rights

ISO 27001 Annex A 5.32 Intellectual property rights

What is ISO 27001 Annex A 5.32 – Intellectual Property Rights?

ISO 27001 Annex A 5.32 requires the organization to implement appropriate procedures to protect intellectual property rights and ensure that the organization uses intellectual property in accordance with applicable legal, contractual, and licensing requirements.

Intellectual property (IP) can include:

  • Software source code
  • Applications
  • Algorithms
  • Databases
  • Product designs
  • Technical documentation
  • Architecture diagrams
  • Business processes
  • Trademarks
  • Logos
  • Written content
  • Training material
  • Designs
  • Research and development
  • Proprietary methodologies
  • Customer-developed material
  • Licensed software
  • Third-party content

Simple Explanation

“Know what intellectual property you own or use, protect it appropriately, and make sure you have the right to use, copy, modify, distribute, or share it.”

A.5.32 is therefore concerned with both sides of intellectual property:

Protecting your own IP

and

Respecting the IP of others.


Why is A.5.32 Important?

For many modern organizations, intellectual property is one of their most valuable assets.

For a software startup, for example:

  • Source code may represent years of development.
  • Algorithms may provide competitive advantage.
  • Product designs may contain confidential information.
  • Customer deliverables may contain proprietary material.
  • Internal documentation may contain valuable know-how.

At the same time, organizations regularly use third-party intellectual property:

  • Open-source software
  • Commercial software
  • Stock images
  • Fonts
  • Libraries
  • APIs
  • SaaS platforms
  • Training material
  • Customer content

Improper use can result in:

  • Legal disputes
  • License violations
  • Financial penalties
  • Forced removal of software
  • Loss of customer trust
  • Intellectual property leakage
  • Security risks

Simple Principle

“Protect what you create and respect what others have created.”


What Does Intellectual Property Include?

Intellectual property is broader than software.

A startup should consider at least four major categories.

1. Software and Technology

Examples:

  • Source code
  • Object code
  • Scripts
  • Algorithms
  • APIs
  • Databases
  • Machine-learning models
  • Infrastructure code
  • Automation scripts

2. Business and Creative Content

Examples:

  • Website content
  • Marketing material
  • Product documentation
  • Training material
  • Presentations
  • Graphics
  • Videos
  • Designs
  • Internal methodologies

3. Brand and Business Assets

Examples:

  • Company name
  • Product names
  • Logos
  • Trademarks
  • Domain names
  • Brand assets

4. Third-Party Intellectual Property

Examples:

  • Open-source libraries
  • Commercial software
  • Licensed images
  • Fonts
  • Templates
  • APIs
  • SDKs
  • Customer-owned content

A.5.32 Has Two Important Dimensions

Protect Your Intellectual Property

The organization should prevent unauthorized:

  • Access
  • Copying
  • Modification
  • Distribution
  • Disclosure
  • Theft
  • Commercial use

Respect Third-Party Intellectual Property

The organization should ensure that it does not:

  • Use unlicensed software
  • Violate open-source licenses
  • Copy copyrighted material without permission
  • Use unauthorized images
  • Reuse customer-owned content improperly
  • Distribute software beyond its license terms

Example: Software Startup

Imagine a SaaS startup has developed a proprietary application.

Its intellectual property includes:

  • Source code
  • Database schema
  • Product architecture
  • Proprietary algorithms
  • Internal deployment scripts
  • Product documentation

The company also uses:

  • Open-source libraries
  • Commercial development tools
  • Cloud services
  • Third-party APIs

The organization therefore needs to manage both:

Its own intellectual property

and

Third-party intellectual property.


Activities Required to Implement A.5.32

1. Identify Intellectual Property

Create an inventory of important intellectual property.

Example:

IP AssetOwnerClassificationLocationProtection
Production source codeCompanyConfidentialGit repositoryAccess control
Product architectureCompanyConfidentialDocumentation platformRestricted access
LogoCompanyInternal/PublicBrand repositoryTrademark management
Customer documentationCustomer/CompanyConfidentialDocument repositoryAccess control
Open-source libraryThird partyPublic/License-controlledCode repositoryLicense review
Commercial softwareThird partyLicensedEmployee systemsLicense tracking

The inventory does not have to contain every minor file.

It should focus on important intellectual property and relevant licensing obligations.


2. Determine Ownership

The organization should understand who owns the IP.

Possible owners include:

  • Organization
  • Employee
  • Contractor
  • Customer
  • Supplier
  • Third-party developer
  • Open-source community
  • Licensing provider

This becomes particularly important when software is developed by:

  • Employees
  • Freelancers
  • Contractors
  • Development agencies
  • Partners

Contracts should clearly address IP ownership where appropriate.


3. Protect Source Code

For software companies, source code is often one of the most critical IP assets.

Controls may include:

  • Repository access control
  • MFA
  • Branch protection
  • Code review
  • Privileged access management
  • Logging
  • Encryption
  • Backup
  • Secrets management
  • Offboarding
  • Access reviews

Example:

Developers receive access only to repositories required for their role.

A departing developer’s repository access should be removed promptly.


4. Manage Open-Source Software

Open-source software is widely used by startups.

Examples include:

  • Programming frameworks
  • Libraries
  • Database components
  • Security libraries
  • UI components
  • Development tools

However, open-source does not automatically mean:

“No restrictions.”

Different licenses have different requirements.

The organization should establish a process for:

  • Identifying open-source components
  • Tracking licenses
  • Reviewing license obligations
  • Maintaining software bills of materials where appropriate
  • Managing dependencies
  • Reviewing redistribution requirements

5. Maintain Software License Compliance

Organizations should track commercially licensed software.

Examples:

  • Operating systems
  • Developer tools
  • Security tools
  • Database software
  • Design software
  • Productivity software

A simple register can record:

SoftwareLicense TypeSeatsExpiryOwner
Development Tool ACommercial10Dec 2026Engineering
Security Tool BSubscription5Mar 2027Security
Database Tool CCommercial3Jun 2027Engineering

This helps prevent unauthorized or expired software use.


6. Control Use of Third-Party Content

Employees may download:

  • Images
  • Videos
  • Fonts
  • Templates
  • Documents
  • Code snippets
  • Training content

The organization should have guidance on what employees are permitted to use.

For example:

Employees should use only content that the organization has created, licensed, or otherwise has permission to use.


7. Protect Customer-Owned Intellectual Property

A company may receive customer:

  • Source code
  • Designs
  • Documentation
  • Data
  • Product specifications
  • Business processes
  • Algorithms

Customer-owned IP should be clearly identified and protected.

Contractual requirements may specify:

  • Ownership
  • Permitted use
  • Storage
  • Access
  • Confidentiality
  • Return
  • Deletion

8. Address Employee and Contractor IP

Startups frequently use contractors and freelancers.

Contracts should address appropriate matters such as:

  • Ownership of work product
  • Confidentiality
  • Permitted use
  • Assignment/licensing where applicable
  • Return or deletion of company information

This is particularly important when external developers create source code or other product assets.


9. Protect IP Through Access Control

Intellectual property should be protected using appropriate access restrictions.

For example:

Product Source Code

→ Engineering access

Financial Models

→ Finance access

Customer Architecture

→ Authorized technical team

Trademark Files

→ Marketing/Legal

Proprietary Algorithms

→ Restricted engineering group

The principle is:

Access should be based on business need, not convenience.


10. Address IP in Contracts

Contracts with employees, contractors, customers and suppliers may need to address intellectual property.

Review relevant agreements for:

  • Ownership
  • Licensing
  • Confidentiality
  • Permitted use
  • Restrictions
  • Distribution rights
  • Return/deletion
  • Third-party components

This should align with the organization’s legal requirements identified under A.5.31.


Startup Example

Consider a SaaS startup with 15 developers.

The startup owns:

  • SaaS source code
  • Product architecture
  • Proprietary automation scripts
  • Product documentation
  • Brand assets

The product also contains 150 open-source dependencies.

The startup implements:

Internal IP Protection

  • Git repository protected with MFA
  • Role-based repository access
  • Branch protection
  • Code review
  • Developer offboarding
  • Backup
  • Logging

Third-Party IP Management

  • Open-source dependency inventory
  • License tracking
  • Commercial software register
  • Approval process for new third-party components

Contractor Management

Contractors sign agreements addressing:

  • Confidentiality
  • Work-product/IP arrangements
  • Access restrictions
  • Return/deletion of company information

Result

The startup can demonstrate:

What IP it owns

↓

What third-party IP it uses

↓

Who can access it

↓

Under what license or agreement it can be used

↓

How it is protected


Startup-Focused Quick Summary

For a startup, A.5.32 can be implemented using a simple model:

1. Identify

What IP do we own and use?

2. Determine Ownership

Who owns each important asset?

3. Protect

Who should have access?

4. License

Do we have permission to use third-party IP?

5. Contract

Are IP ownership and usage rights addressed in relevant agreements?

6. Monitor

Are licenses and permissions still valid?

7. Offboard

Are IP and repository accesses removed when people leave?

Simple Model

Identify → Establish Ownership → Protect → License → Control Access → Monitor


Example Intellectual Property Register

IDIP AssetTypeOwnerLocationClassificationProtection
IP-001SaaS source codeSoftwareCompanyGit repositoryConfidentialRBAC + MFA
IP-002Product architectureTechnicalCompanyDocumentation systemConfidentialRestricted access
IP-003Proprietary algorithmTechnologyCompanyCode repositoryHighly ConfidentialRestricted access
IP-004Company logoBrandCompanyBrand repositoryInternal/PublicBrand controls
IP-005Customer designCustomer IPCustomerProject repositoryConfidentialCustomer-specific access
IP-006Open-source libraryThird-partyThird partyCode repositoryLicense-controlledLicense tracking

Open-Source Software Register

For technology startups, maintaining an open-source register can be particularly useful.

ComponentVersionLicenseUsed InApprovalReview
Library A2.xMITWeb applicationApprovedAnnual
Library B4.xApache 2.0APIApprovedAnnual
Library C1.xGPLInternal toolLegal reviewAs required

The exact review requirements should depend on how the component is used and the organization’s legal and product requirements.


Software License Register

SoftwareVendorLicenseUsers/DevicesRenewalOwner
Development IDEVendor ACommercial12AnnualEngineering
Security ScannerVendor BSubscription5AnnualSecurity
Design SoftwareVendor CSubscription4AnnualMarketing
Database ToolVendor DCommercial3AnnualEngineering

Audit Evidence for A.5.32

An auditor may request:

IP Inventory

  • Intellectual Property Register
  • Source-code inventory
  • Critical technology asset inventory

Ownership

  • Employee agreements
  • Contractor agreements
  • IP assignment/licensing agreements
  • Customer agreements

Software Licensing

  • Software license register
  • License purchase records
  • Subscription records
  • Renewal records

Open Source

  • Open-source inventory
  • Software Bill of Materials (SBOM), where maintained
  • Open-source license records
  • Dependency management records
  • License review/approval records

Access Protection

  • Repository access lists
  • Access reviews
  • MFA configuration
  • Offboarding evidence
  • Repository logs

Third-Party Content

  • Content licenses
  • Image licenses
  • Font licenses
  • Software licenses

A.5.32 Audit Checklist

Audit QuestionEvidence
Has important intellectual property been identified?IP register
Is ownership documented?Contracts/agreements
Is source code protected?Repository controls
Is access restricted?Access review
Is MFA enabled for important repositories?MFA evidence
Are commercial software licenses tracked?License register
Are open-source components identified?Dependency/SBOM records
Are applicable open-source licenses reviewed?License review
Are customer-owned assets identified?Customer agreements
Are contractor IP arrangements documented?Contractor contracts
Are third-party content licenses retained?License evidence
Are departing employees’ IP-related accesses removed?Offboarding evidence
Are IP requirements addressed in contracts?Contract review
Are license obligations periodically reviewed?Review records

Common Mistakes

1. Assuming Open Source Means “Free of Restrictions”

Open-source software can have license conditions.

The organization should understand the licenses applicable to the components it uses and distributes.


2. No Source-Code Access Control

A startup may have its entire product in a Git repository with overly broad access.

Source-code repositories should be protected according to the sensitivity and business value of the code.


3. No Contractor IP Arrangements

A company may hire a developer or agency without clearly addressing ownership or permitted use of the resulting work.

This can create uncertainty over IP rights.


4. Using Images or Content Without Proper Rights

Marketing teams may copy images, graphics, fonts or documents from the internet without checking usage rights.


5. Expired Software Licenses

Organizations sometimes continue using commercial software after the applicable license expires or changes.


6. No Customer IP Separation

Customer-owned source code, documentation or designs may become mixed with company-owned assets.

The organization should clearly understand ownership and permitted use.


7. No Offboarding

Former employees or contractors may retain access to:

  • Source code
  • Documentation
  • Design repositories
  • Cloud environments
  • Intellectual property

Access should be removed as part of the organization’s offboarding process.


8. Treating IP Protection as Only a Legal Issue

Legal ownership is important, but information security also matters.

An organization may legally own source code but still fail to protect it adequately.


Practical Startup Implementation Model

A startup can implement A.5.32 using this sequence:

Step 1 – Identify

Identify important company-owned, customer-owned and third-party IP.

Step 2 – Classify

Determine the sensitivity and importance of each asset.

Step 3 – Establish Ownership

Document ownership or usage rights.

Step 4 – Protect

Apply access control, confidentiality and technical security measures.

Step 5 – Manage Licenses

Track commercial and open-source licensing obligations.

Step 6 – Contract

Address IP ownership and usage rights in relevant agreements.

Step 7 – Review

Periodically review IP, licenses, access and contractual arrangements.

Simple Model

Identify → Classify → Establish Ownership → Protect → License → Review


Policy vs. Process vs. Evidence

TypeExample
PolicyIntellectual Property Protection Policy
ProcessSoftware License Management Procedure
ProcessOpen-Source Software Management Procedure
ProcessIP Access Control Procedure
ProcessContractor IP Review Process
DocumentIntellectual Property Register
DocumentSoftware License Register
DocumentOpen-Source Register
EvidenceLicense purchase
EvidenceLicense review
EvidenceRepository access review
EvidenceContractor agreement
EvidenceOffboarding record

Remember

Policy = What the organization requires

Process = How IP is managed

Register = What IP/licenses exist

Evidence = How the organization demonstrates that IP is protected and used appropriately


Relationship With Other ISO 27001 Controls

A.5.32 connects with several other controls.

ControlRelationship
A.5.1 Policies for Information SecurityEstablishes the organization’s security expectations
A.5.10 Acceptable UseDefines appropriate use of organizational information and assets
A.5.12 Classification of InformationHelps determine appropriate protection for sensitive IP
A.5.15 Access ControlRestricts access to intellectual property
A.5.18 Access RightsEnsures access is granted according to business need
A.5.19–A.5.22 Supplier ControlsAddresses IP and licensing risks involving suppliers
A.5.31 Legal/Regulatory/Contractual RequirementsIdentifies applicable IP and licensing obligations
A.5.33 Protection of RecordsProtects important records containing intellectual property
A.5.34 Privacy and Protection of PIIApplies when IP repositories also contain personal information
A.8.4 Access to Source CodeDirectly supports protection of source code
A.8.9 Configuration ManagementHelps control software and technology configurations
A.8.32 Change ManagementHelps control changes to important software and systems

Useful Documents for A.5.32

  • Intellectual Property Protection Policy – [Insert Draft Document Link]
  • Intellectual Property Register – [Insert Draft Document Link]
  • Software License Register – [Insert Draft Document Link]
  • Open-Source Software Register – [Insert Draft Document Link]
  • Open-Source License Review Checklist – [Insert Draft Document Link]
  • Contractor IP Review Checklist – [Insert Draft Document Link]
  • Source Code Access Review Checklist – [Insert Draft Document Link]
  • Third-Party Content License Register – [Insert Draft Document Link]

Questions an Auditor May Ask

IP Identification

  • What are your organization’s most important intellectual property assets?
  • How do you identify and maintain your IP inventory?
  • Who owns your source code?

Source Code

  • Who has access to the source-code repositories?
  • How is repository access controlled?
  • How do you remove access when an employee leaves?

Licensing

  • How do you manage commercial software licenses?
  • How do you manage open-source software?
  • How do you know that third-party software is appropriately licensed?

Contractors

  • Who owns code developed by contractors?
  • Do contractor agreements address intellectual property?
  • How is contractor access removed after completion?

Customer IP

  • Do you handle customer-owned intellectual property?
  • How do you distinguish customer IP from your own IP?
  • What does the contract permit you to do with customer IP?

Startup-Focused Final Takeaway

ISO 27001 Annex A 5.32 is not simply about registering trademarks or talking to a lawyer.

It is about protecting intellectual property and ensuring that the organization has the right to use the intellectual property it relies upon.

For a technology startup, the most important questions are often:

  • Who owns our source code?
  • Who can access it?
  • How is it protected?
  • What third-party software do we use?
  • What licenses apply?
  • Are open-source components being managed appropriately?
  • Do employee and contractor agreements address IP?
  • Are customer-owned assets clearly identified?
  • Are licenses and permissions still valid?

Practical Implementation Flow

Identify IP

↓

Determine Ownership

↓

Classify & Protect

↓

Control Access

↓

Manage Licenses

↓

Address IP in Contracts

↓

Review & Monitor

The practical auditor question is:

“How does your organization identify, protect, and manage intellectual property—including its own IP, customer IP, and third-party software or content—and how do you ensure that licensing and usage requirements are followed?”

That is the practical objective of ISO 27001 Annex A 5.32 – Intellectual Property Rights.

How can we help?

Leave a Reply

Your email address will not be published. Required fields are marked *