Requirement 7: Restrict access to system components and cardholder data by business need to know
People should only access the data and systems their job requires, on a least-privilege basis.
Sub-requirements
7.1
Processes and mechanisms are defined and understood
2 defined requirementsDocument an access control policy.
View defined requirements →7.2
Access is appropriately defined and assigned
7 defined requirementsAssign access by role and need-to-know, with documented approval.
View defined requirements →7.3
Access is managed via an access control system
3 defined requirementsEnforce access through a system set to deny-all by default.
View defined requirements →Tips
- ›Define roles and map data access to each; default to deny.
- ›Keep approval records for every access grant.
Evidence to keep
- ✓Access control policy
- ✓Role definitions
- ✓Access-grant approvals
Example
Access is role-based in the IdP, default-deny, and each grant has a documented approval ticket.
Policy templates for this control
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.
Access control policyUse for ISO 27001 A.5.15, A.5.16, A.5.17, A.5.18, A.8.2, SOC 2 Security, and PCI DSS requirements 7 and 8.Change management policyUse for ISO 27001 A.8.32, A.8.9, SOC 2 change management criteria, and PCI DSS requirement 6 change controls.Data retention and disposal policyUse for ISO 27001 A.5.33, A.5.34, A.8.10, SOC 2 Confidentiality and Privacy, and PCI DSS requirement 3.Physical and environmental security policyUse for ISO 27001 A.7.1 to A.7.14, SOC 2 Security, and PCI DSS requirement 9 physical access controls.
Open the control-to-policy map