A.8.3A.8 Technological controls

Information access restriction

A.5EVIDENCEA.6EVIDENCEA.7EVIDENCEA.8EVIDENCECONTROL MAPA.8.3 Evidence MapPOLICY / CONTROL / EVIDENCE / REVIEW

Purpose

Allow only authorised access to information and related assets while blocking unauthorised access.

How to meet this control

In short: Restrict access to information per the access control policy.

  1. Step 01Model access as roles or groups in the identity provider and assign people to groups rather than granting permissions directly to individuals
  2. Step 02Configure systems to deny by default, so a user reaches only the data their role explicitly permits
  3. Step 03Apply attribute or context conditions for high-value data, restricting by device compliance, network location or sensitivity label
  4. Step 04Use platform features such as SharePoint sensitivity labels, database row-level security or S3 bucket policies to enforce restrictions at the data layer
  5. Step 05Block anonymous and guest access to confidential repositories and require authenticated, logged access
  6. Step 06Alert on attempts to reach data outside a role through the SIEM or the platform audit feed

Tip: Role-based access; deny by default.

What ISO 27002 says to cover

Reference points from the ISO/IEC 27002:2022 guidance for this control. Use them to check the steps above cover everything relevant to you.

  • ›Restrict access in line with the topic-specific access control policy
  • ›Block anonymous or unknown identities from sensitive data
  • ›Use system configuration to control read, write, delete and execute rights by user and group
  • ›Provide physical or logical isolation for sensitive applications, data and systems
  • ›For high-value data, use dynamic access management by identity, device, location or application
  • ›Apply encryption and authentication and define printing permissions for protected information
  • ›Record who accesses information and how, and raise alerts when misuse is attempted
  • ›Protect information across its whole life cycle

Audit evidence to keep

  • - Access control policy stating least privilege and deny-by-default
  • - Role-to-permission mapping or group membership export from the identity provider
  • - Configuration screenshot of row-level security, bucket policy or sensitivity label enforcement
  • - Audit log entries showing a blocked or alerted unauthorised access attempt
  • - Records of an access recertification covering sensitive data stores

Common mistakes

  • - Approving access in chat with no retained record
  • - Copying access from another user without checking least privilege
  • - Reviewing access but not proving removals were completed

Owner, cadence, and proof

Assign one accountable owner for A.8.3. Review this control at least annually, after related incidents, and whenever the underlying process, supplier, system, office, or legal obligation changes. The control is audit-ready when the owner can show the policy or procedure, the latest operating evidence, the latest review, and any open exceptions with due dates.

Policy templates for this control

Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.

Open the control-to-policy map
Back to all technological controls or see the requirements (clauses 4 to 10). To run this control with automation, read how AI manages controls.