What is ISO 27001 Annex A 5.32 – Intellectual Property Rights?
ISO 27001 Annex A 5.32 requires the organization to implement appropriate procedures to protect intellectual property rights and ensure that the organization uses intellectual property in accordance with applicable legal, contractual, and licensing requirements.
Intellectual property (IP) can include:
- Software source code
- Applications
- Algorithms
- Databases
- Product designs
- Technical documentation
- Architecture diagrams
- Business processes
- Trademarks
- Logos
- Written content
- Training material
- Designs
- Research and development
- Proprietary methodologies
- Customer-developed material
- Licensed software
- Third-party content
Simple Explanation
“Know what intellectual property you own or use, protect it appropriately, and make sure you have the right to use, copy, modify, distribute, or share it.”
A.5.32 is therefore concerned with both sides of intellectual property:
Protecting your own IP
and
Respecting the IP of others.
Why is A.5.32 Important?
For many modern organizations, intellectual property is one of their most valuable assets.
For a software startup, for example:
- Source code may represent years of development.
- Algorithms may provide competitive advantage.
- Product designs may contain confidential information.
- Customer deliverables may contain proprietary material.
- Internal documentation may contain valuable know-how.
At the same time, organizations regularly use third-party intellectual property:
- Open-source software
- Commercial software
- Stock images
- Fonts
- Libraries
- APIs
- SaaS platforms
- Training material
- Customer content
Improper use can result in:
- Legal disputes
- License violations
- Financial penalties
- Forced removal of software
- Loss of customer trust
- Intellectual property leakage
- Security risks
Simple Principle
“Protect what you create and respect what others have created.”
What Does Intellectual Property Include?
Intellectual property is broader than software.
A startup should consider at least four major categories.
1. Software and Technology
Examples:
- Source code
- Object code
- Scripts
- Algorithms
- APIs
- Databases
- Machine-learning models
- Infrastructure code
- Automation scripts
2. Business and Creative Content
Examples:
- Website content
- Marketing material
- Product documentation
- Training material
- Presentations
- Graphics
- Videos
- Designs
- Internal methodologies
3. Brand and Business Assets
Examples:
- Company name
- Product names
- Logos
- Trademarks
- Domain names
- Brand assets
4. Third-Party Intellectual Property
Examples:
- Open-source libraries
- Commercial software
- Licensed images
- Fonts
- Templates
- APIs
- SDKs
- Customer-owned content
A.5.32 Has Two Important Dimensions
Protect Your Intellectual Property
The organization should prevent unauthorized:
- Access
- Copying
- Modification
- Distribution
- Disclosure
- Theft
- Commercial use
Respect Third-Party Intellectual Property
The organization should ensure that it does not:
- Use unlicensed software
- Violate open-source licenses
- Copy copyrighted material without permission
- Use unauthorized images
- Reuse customer-owned content improperly
- Distribute software beyond its license terms
Example: Software Startup
Imagine a SaaS startup has developed a proprietary application.
Its intellectual property includes:
- Source code
- Database schema
- Product architecture
- Proprietary algorithms
- Internal deployment scripts
- Product documentation
The company also uses:
- Open-source libraries
- Commercial development tools
- Cloud services
- Third-party APIs
The organization therefore needs to manage both:
Its own intellectual property
and
Third-party intellectual property.
Activities Required to Implement A.5.32
1. Identify Intellectual Property
Create an inventory of important intellectual property.
Example:
| IP Asset | Owner | Classification | Location | Protection |
|---|---|---|---|---|
| Production source code | Company | Confidential | Git repository | Access control |
| Product architecture | Company | Confidential | Documentation platform | Restricted access |
| Logo | Company | Internal/Public | Brand repository | Trademark management |
| Customer documentation | Customer/Company | Confidential | Document repository | Access control |
| Open-source library | Third party | Public/License-controlled | Code repository | License review |
| Commercial software | Third party | Licensed | Employee systems | License tracking |
The inventory does not have to contain every minor file.
It should focus on important intellectual property and relevant licensing obligations.
2. Determine Ownership
The organization should understand who owns the IP.
Possible owners include:
- Organization
- Employee
- Contractor
- Customer
- Supplier
- Third-party developer
- Open-source community
- Licensing provider
This becomes particularly important when software is developed by:
- Employees
- Freelancers
- Contractors
- Development agencies
- Partners
Contracts should clearly address IP ownership where appropriate.
3. Protect Source Code
For software companies, source code is often one of the most critical IP assets.
Controls may include:
- Repository access control
- MFA
- Branch protection
- Code review
- Privileged access management
- Logging
- Encryption
- Backup
- Secrets management
- Offboarding
- Access reviews
Example:
Developers receive access only to repositories required for their role.
A departing developer’s repository access should be removed promptly.
4. Manage Open-Source Software
Open-source software is widely used by startups.
Examples include:
- Programming frameworks
- Libraries
- Database components
- Security libraries
- UI components
- Development tools
However, open-source does not automatically mean:
“No restrictions.”
Different licenses have different requirements.
The organization should establish a process for:
- Identifying open-source components
- Tracking licenses
- Reviewing license obligations
- Maintaining software bills of materials where appropriate
- Managing dependencies
- Reviewing redistribution requirements
5. Maintain Software License Compliance
Organizations should track commercially licensed software.
Examples:
- Operating systems
- Developer tools
- Security tools
- Database software
- Design software
- Productivity software
A simple register can record:
| Software | License Type | Seats | Expiry | Owner |
|---|---|---|---|---|
| Development Tool A | Commercial | 10 | Dec 2026 | Engineering |
| Security Tool B | Subscription | 5 | Mar 2027 | Security |
| Database Tool C | Commercial | 3 | Jun 2027 | Engineering |
This helps prevent unauthorized or expired software use.
6. Control Use of Third-Party Content
Employees may download:
- Images
- Videos
- Fonts
- Templates
- Documents
- Code snippets
- Training content
The organization should have guidance on what employees are permitted to use.
For example:
Employees should use only content that the organization has created, licensed, or otherwise has permission to use.
7. Protect Customer-Owned Intellectual Property
A company may receive customer:
- Source code
- Designs
- Documentation
- Data
- Product specifications
- Business processes
- Algorithms
Customer-owned IP should be clearly identified and protected.
Contractual requirements may specify:
- Ownership
- Permitted use
- Storage
- Access
- Confidentiality
- Return
- Deletion
8. Address Employee and Contractor IP
Startups frequently use contractors and freelancers.
Contracts should address appropriate matters such as:
- Ownership of work product
- Confidentiality
- Permitted use
- Assignment/licensing where applicable
- Return or deletion of company information
This is particularly important when external developers create source code or other product assets.
9. Protect IP Through Access Control
Intellectual property should be protected using appropriate access restrictions.
For example:
Product Source Code
→ Engineering access
Financial Models
→ Finance access
Customer Architecture
→ Authorized technical team
Trademark Files
→ Marketing/Legal
Proprietary Algorithms
→ Restricted engineering group
The principle is:
Access should be based on business need, not convenience.
10. Address IP in Contracts
Contracts with employees, contractors, customers and suppliers may need to address intellectual property.
Review relevant agreements for:
- Ownership
- Licensing
- Confidentiality
- Permitted use
- Restrictions
- Distribution rights
- Return/deletion
- Third-party components
This should align with the organization’s legal requirements identified under A.5.31.
Startup Example
Consider a SaaS startup with 15 developers.
The startup owns:
- SaaS source code
- Product architecture
- Proprietary automation scripts
- Product documentation
- Brand assets
The product also contains 150 open-source dependencies.
The startup implements:
Internal IP Protection
- Git repository protected with MFA
- Role-based repository access
- Branch protection
- Code review
- Developer offboarding
- Backup
- Logging
Third-Party IP Management
- Open-source dependency inventory
- License tracking
- Commercial software register
- Approval process for new third-party components
Contractor Management
Contractors sign agreements addressing:
- Confidentiality
- Work-product/IP arrangements
- Access restrictions
- Return/deletion of company information
Result
The startup can demonstrate:
What IP it owns
↓
What third-party IP it uses
↓
Who can access it
↓
Under what license or agreement it can be used
↓
How it is protected
Startup-Focused Quick Summary
For a startup, A.5.32 can be implemented using a simple model:
1. Identify
What IP do we own and use?
2. Determine Ownership
Who owns each important asset?
3. Protect
Who should have access?
4. License
Do we have permission to use third-party IP?
5. Contract
Are IP ownership and usage rights addressed in relevant agreements?
6. Monitor
Are licenses and permissions still valid?
7. Offboard
Are IP and repository accesses removed when people leave?
Simple Model
Identify → Establish Ownership → Protect → License → Control Access → Monitor
Example Intellectual Property Register
| ID | IP Asset | Type | Owner | Location | Classification | Protection |
|---|---|---|---|---|---|---|
| IP-001 | SaaS source code | Software | Company | Git repository | Confidential | RBAC + MFA |
| IP-002 | Product architecture | Technical | Company | Documentation system | Confidential | Restricted access |
| IP-003 | Proprietary algorithm | Technology | Company | Code repository | Highly Confidential | Restricted access |
| IP-004 | Company logo | Brand | Company | Brand repository | Internal/Public | Brand controls |
| IP-005 | Customer design | Customer IP | Customer | Project repository | Confidential | Customer-specific access |
| IP-006 | Open-source library | Third-party | Third party | Code repository | License-controlled | License tracking |
Open-Source Software Register
For technology startups, maintaining an open-source register can be particularly useful.
| Component | Version | License | Used In | Approval | Review |
|---|---|---|---|---|---|
| Library A | 2.x | MIT | Web application | Approved | Annual |
| Library B | 4.x | Apache 2.0 | API | Approved | Annual |
| Library C | 1.x | GPL | Internal tool | Legal review | As required |
The exact review requirements should depend on how the component is used and the organization’s legal and product requirements.
Software License Register
| Software | Vendor | License | Users/Devices | Renewal | Owner |
|---|---|---|---|---|---|
| Development IDE | Vendor A | Commercial | 12 | Annual | Engineering |
| Security Scanner | Vendor B | Subscription | 5 | Annual | Security |
| Design Software | Vendor C | Subscription | 4 | Annual | Marketing |
| Database Tool | Vendor D | Commercial | 3 | Annual | Engineering |
Audit Evidence for A.5.32
An auditor may request:
IP Inventory
- Intellectual Property Register
- Source-code inventory
- Critical technology asset inventory
Ownership
- Employee agreements
- Contractor agreements
- IP assignment/licensing agreements
- Customer agreements
Software Licensing
- Software license register
- License purchase records
- Subscription records
- Renewal records
Open Source
- Open-source inventory
- Software Bill of Materials (SBOM), where maintained
- Open-source license records
- Dependency management records
- License review/approval records
Access Protection
- Repository access lists
- Access reviews
- MFA configuration
- Offboarding evidence
- Repository logs
Third-Party Content
- Content licenses
- Image licenses
- Font licenses
- Software licenses
A.5.32 Audit Checklist
| Audit Question | Evidence |
|---|---|
| Has important intellectual property been identified? | IP register |
| Is ownership documented? | Contracts/agreements |
| Is source code protected? | Repository controls |
| Is access restricted? | Access review |
| Is MFA enabled for important repositories? | MFA evidence |
| Are commercial software licenses tracked? | License register |
| Are open-source components identified? | Dependency/SBOM records |
| Are applicable open-source licenses reviewed? | License review |
| Are customer-owned assets identified? | Customer agreements |
| Are contractor IP arrangements documented? | Contractor contracts |
| Are third-party content licenses retained? | License evidence |
| Are departing employees’ IP-related accesses removed? | Offboarding evidence |
| Are IP requirements addressed in contracts? | Contract review |
| Are license obligations periodically reviewed? | Review records |
Common Mistakes
1. Assuming Open Source Means “Free of Restrictions”
Open-source software can have license conditions.
The organization should understand the licenses applicable to the components it uses and distributes.
2. No Source-Code Access Control
A startup may have its entire product in a Git repository with overly broad access.
Source-code repositories should be protected according to the sensitivity and business value of the code.
3. No Contractor IP Arrangements
A company may hire a developer or agency without clearly addressing ownership or permitted use of the resulting work.
This can create uncertainty over IP rights.
4. Using Images or Content Without Proper Rights
Marketing teams may copy images, graphics, fonts or documents from the internet without checking usage rights.
5. Expired Software Licenses
Organizations sometimes continue using commercial software after the applicable license expires or changes.
6. No Customer IP Separation
Customer-owned source code, documentation or designs may become mixed with company-owned assets.
The organization should clearly understand ownership and permitted use.
7. No Offboarding
Former employees or contractors may retain access to:
- Source code
- Documentation
- Design repositories
- Cloud environments
- Intellectual property
Access should be removed as part of the organization’s offboarding process.
8. Treating IP Protection as Only a Legal Issue
Legal ownership is important, but information security also matters.
An organization may legally own source code but still fail to protect it adequately.
Practical Startup Implementation Model
A startup can implement A.5.32 using this sequence:
Step 1 – Identify
Identify important company-owned, customer-owned and third-party IP.
Step 2 – Classify
Determine the sensitivity and importance of each asset.
Step 3 – Establish Ownership
Document ownership or usage rights.
Step 4 – Protect
Apply access control, confidentiality and technical security measures.
Step 5 – Manage Licenses
Track commercial and open-source licensing obligations.
Step 6 – Contract
Address IP ownership and usage rights in relevant agreements.
Step 7 – Review
Periodically review IP, licenses, access and contractual arrangements.
Simple Model
Identify → Classify → Establish Ownership → Protect → License → Review
Policy vs. Process vs. Evidence
| Type | Example |
|---|---|
| Policy | Intellectual Property Protection Policy |
| Process | Software License Management Procedure |
| Process | Open-Source Software Management Procedure |
| Process | IP Access Control Procedure |
| Process | Contractor IP Review Process |
| Document | Intellectual Property Register |
| Document | Software License Register |
| Document | Open-Source Register |
| Evidence | License purchase |
| Evidence | License review |
| Evidence | Repository access review |
| Evidence | Contractor agreement |
| Evidence | Offboarding record |
Remember
Policy = What the organization requires
Process = How IP is managed
Register = What IP/licenses exist
Evidence = How the organization demonstrates that IP is protected and used appropriately
Relationship With Other ISO 27001 Controls
A.5.32 connects with several other controls.
| Control | Relationship |
|---|---|
| A.5.1 Policies for Information Security | Establishes the organization’s security expectations |
| A.5.10 Acceptable Use | Defines appropriate use of organizational information and assets |
| A.5.12 Classification of Information | Helps determine appropriate protection for sensitive IP |
| A.5.15 Access Control | Restricts access to intellectual property |
| A.5.18 Access Rights | Ensures access is granted according to business need |
| A.5.19–A.5.22 Supplier Controls | Addresses IP and licensing risks involving suppliers |
| A.5.31 Legal/Regulatory/Contractual Requirements | Identifies applicable IP and licensing obligations |
| A.5.33 Protection of Records | Protects important records containing intellectual property |
| A.5.34 Privacy and Protection of PII | Applies when IP repositories also contain personal information |
| A.8.4 Access to Source Code | Directly supports protection of source code |
| A.8.9 Configuration Management | Helps control software and technology configurations |
| A.8.32 Change Management | Helps control changes to important software and systems |
Useful Documents for A.5.32
- Intellectual Property Protection Policy – [Insert Draft Document Link]
- Intellectual Property Register – [Insert Draft Document Link]
- Software License Register – [Insert Draft Document Link]
- Open-Source Software Register – [Insert Draft Document Link]
- Open-Source License Review Checklist – [Insert Draft Document Link]
- Contractor IP Review Checklist – [Insert Draft Document Link]
- Source Code Access Review Checklist – [Insert Draft Document Link]
- Third-Party Content License Register – [Insert Draft Document Link]
Questions an Auditor May Ask
IP Identification
- What are your organization’s most important intellectual property assets?
- How do you identify and maintain your IP inventory?
- Who owns your source code?
Source Code
- Who has access to the source-code repositories?
- How is repository access controlled?
- How do you remove access when an employee leaves?
Licensing
- How do you manage commercial software licenses?
- How do you manage open-source software?
- How do you know that third-party software is appropriately licensed?
Contractors
- Who owns code developed by contractors?
- Do contractor agreements address intellectual property?
- How is contractor access removed after completion?
Customer IP
- Do you handle customer-owned intellectual property?
- How do you distinguish customer IP from your own IP?
- What does the contract permit you to do with customer IP?
Startup-Focused Final Takeaway
ISO 27001 Annex A 5.32 is not simply about registering trademarks or talking to a lawyer.
It is about protecting intellectual property and ensuring that the organization has the right to use the intellectual property it relies upon.
For a technology startup, the most important questions are often:
- Who owns our source code?
- Who can access it?
- How is it protected?
- What third-party software do we use?
- What licenses apply?
- Are open-source components being managed appropriately?
- Do employee and contractor agreements address IP?
- Are customer-owned assets clearly identified?
- Are licenses and permissions still valid?
Practical Implementation Flow
Identify IP
↓
Determine Ownership
↓
Classify & Protect
↓
Control Access
↓
Manage Licenses
↓
Address IP in Contracts
↓
Review & Monitor
The practical auditor question is:
“How does your organization identify, protect, and manage intellectual property—including its own IP, customer IP, and third-party software or content—and how do you ensure that licensing and usage requirements are followed?”
That is the practical objective of ISO 27001 Annex A 5.32 – Intellectual Property Rights.
