A.5.15A.5 Organizational controls

Access control

A.5EVIDENCEA.6EVIDENCEA.7EVIDENCEA.8EVIDENCECONTROL MAPA.5.15 Evidence MapPOLICY / CONTROL / EVIDENCE / REVIEW

Purpose

Allow authorised access and prevent unauthorised access to information and associated assets.

How to meet this control

In short: Establish and implement access control rules based on business and security requirements.

  1. Step 01Publish an access control policy stating least-privilege, need-to-know, deny-by-default and the chosen model (role-based or attribute-based)
  2. Step 02Have asset owners define the access requirements for their assets and document who may have which level of access
  3. Step 03Implement access through roles or groups in the identity provider rather than per-user grants where possible
  4. Step 04Segregate the request, approval and administration steps so no single person grants their own access
  5. Step 05Cover both physical and logical access and all connection types including remote and third-party access

Tip: Document an Access Control Policy stating least-privilege and need-to-know.

What ISO 27002 says to cover

Reference points from the ISO/IEC 27002:2022 guidance for this control. Use them to check the steps above cover everything relevant to you.

  • ›Have asset owners set access control requirements based on business and security needs
  • ›Define and communicate a topic-specific policy on access control
  • ›Apply the need-to-know and need-to-use principles when granting access
  • ›Base rules on least privilege, where everything is forbidden unless expressly permitted
  • ›Map access rights consistently to classification and to physical perimeter needs
  • ›Cover both physical and logical access and all connection types in distributed environments
  • ›Segregate access control functions such as request, authorisation and administration
  • ›Choose an access model (for example role-based or attribute-based) and support it with documented procedures

Audit evidence to keep

  • - Approved access control policy stating least-privilege and need-to-know principles
  • - Access requirements defined by asset owners for key systems
  • - Role or group definitions mapping job functions to access rights
  • - Evidence that request, approval and administration of access are separated

Common mistakes

  • - Approving access in chat with no retained record
  • - Copying access from another user without checking least privilege
  • - Reviewing access but not proving removals were completed

Owner, cadence, and proof

Assign one accountable owner for A.5.15. Review this control at least annually, after related incidents, and whenever the underlying process, supplier, system, office, or legal obligation changes. The control is audit-ready when the owner can show the policy or procedure, the latest operating evidence, the latest review, and any open exceptions with due dates.

Policy templates for this control

Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.

Open the control-to-policy map
Back to all organizational controls or see the requirements (clauses 4 to 10). To run this control with automation, read how AI manages controls.