# Access control policy

Source: https://aestech.com.au/policy-templates/#access-control-policy
Markdown URL: https://aestech.com.au/policy-templates/access-control-policy.md

Use for ISO 27001 A.5.15, A.5.16, A.5.17, A.5.18, A.8.2, SOC 2 Security, and PCI DSS requirements 7 and 8.

Frameworks: ISO 27001, SOC 2, PCI DSS

Use this as a starting point only. Adapt it to your real scope, systems, legal obligations, customer commitments and operating process.

```text
1. Purpose
This policy defines how access to company systems, data, facilities and administrative functions is requested, approved, provisioned, reviewed and removed.

2. Scope
This policy applies to all employees, contractors, service accounts, administrator accounts, production systems, business systems and third-party access.

3. Principles
- Access is granted only for a documented business need.
- Least privilege and need-to-know apply by default.
- Shared user accounts are prohibited unless explicitly approved and monitored.
- Privileged access requires separate approval and stronger monitoring.
- MFA is required for email, identity, cloud, production, code, finance and admin systems.

4. Process
- Access requests must be submitted in [ticketing system].
- The system owner approves access before provisioning.
- IT or the system administrator provisions access according to the approved role.
- Access is removed within [x] hours of termination and adjusted on role change.
- Privileged access is reviewed at least quarterly.

5. Evidence
Keep access request tickets, approval records, provisioning logs, access review sign-offs, offboarding records and exception approvals.

Owner: [role]
Review cadence: at least annually and after major system or role changes.
```

Full template pack: https://aestech.com.au/policy-templates/policy-pack.md