ISO 27001:2022
Organizational controls – ISO 27001:2022

ISO 27001:2022 5.15: Access control

Rules that govern both physical entry and logical access to information and associated assets are to be set and applied on the basis of business and information security requirements. Purpose (stated in ISO/IEC 27002:2022): ensures access to information and associated assets is authorized and unauthorized access is prevented. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 5.15.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 88 controls across 38 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

CIS Controls v8 · 8 controls

  • CIS-12.2 Establish and Maintain a Secure Network Architecture
  • CIS-3.3 Configure Data Access Control Lists
  • CIS-4.12 Separate Enterprise Workspaces on Mobile End-User Devices
  • CIS-6.1 Establish an Access Granting Process
  • CIS-6.2 Establish an Access Revoking Process
  • CIS-6.7 Centralize Access Control
  • CIS-6.8 Define and Maintain Role-Based Access Control
  • CIS-9.4 Restrict Unnecessary or Unauthorized Browser and Email Client Extensions

SOC 2 · 7 controls

  • SOC2-CC5.1 CC5.1 Selecting control activities that mitigate risk (COSO principle 10)
  • SOC2-CC6.1 CC6.1 Logical access security over protected information assets
  • SOC2-CC6.2 CC6.2 Registering and authorising users before issuing credentials
  • SOC2-CC6.3 CC6.3 Role-based access, least privilege and segregation of duties
  • SOC2-CC6.4 CC6.4 Restricting physical access to facilities and assets
  • SOC2-CC6.7 CC6.7 Restricting and protecting information in transmission, movement and removal
  • SOC2-P5.1 P5.1 Data subject access

NIST SP 800-53 Rev 5 · 6 controls

PCI DSS 4.0 · 6 controls

  • 3.3.3 3.3.3 Issuer SAD storage limited, justified and encrypted
  • 7.2.1 7.2.1 Access control model defined
  • 7.2.2 7.2.2 User access assigned by job function and least privilege
  • 3.6.1 3.6.1 Procedures protect keys against disclosure and misuse
  • 7.3.1 7.3.1 Need-to-know access control system covers all components
  • 8.6.1 8.6.1 Interactive use of system accounts controlled

HIPAA Security Rule · 4 controls

  • ASBv3-GS-6 Define and implement identity and privileged access strategy
  • ASBv3-PA-7 Follow just enough administration (least privilege) principle
  • IM-7 Restrict resource access based on conditions

ISO 27701:2019 · 3 controls

  • 6.6 Access control
  • 6.6.1 Business requirements of access control
  • 6.6.2 User access management
  • NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
  • NIST-CSF-PR.AA-06 Physical access to assets is managed, monitored, and enforced commensurate with risk
  • NIST-CSF-PR.IR-01 Networks and environments are protected from unauthorized logical access and usage

NIST SP 800-171 Rev 3 · 3 controls

NIST SP 800-66 Rev 2 · 3 controls

  • ANSSI-HYG-08 Identify Each Person by Name and Separate User and Administrator Roles
  • ANSSI-HYG-09 Assign the Correct Rights on Sensitive Resources
  • MYHR-SEC-2 Access controls and user account management
  • MYHR-SEC-7 Consumer access controls and consent

C5 (Germany) · 2 controls

CMMC 2.0 · 2 controls

COBIT 2019 · 2 controls

  • DSS05.04 DSS05.04 Manage user identity and logical access
  • DSS06.03 DSS06.03 Manage roles, responsibilities, access privileges and levels of authority

FedRAMP High · 2 controls

  • AC-1 Policy and Procedures
  • AC-3 Access Enforcement

FedRAMP Moderate · 2 controls

  • AC-1 Policy and Procedures
  • AC-3 Access Enforcement

ISO 27001:2013 · 2 controls

  • A.9.1.1 Access control policy
  • A.9.1.2 Access to networks and network services
  • Art. 132-ter Art. 132-ter Secure communications services and traffic and location data with measures proportionate to risk
  • Art. 2-quaterdecies Art. 2-quaterdecies Designate and authorise the people who process data under your authority

API 1164 · 1 control

  • API1164-06 Access Control
  • AUCDR-IS-1 Limit risk of unauthorised access to the CDR data environment
  • AESCSF-IAM-2 Access control
  • AEO-3 Satisfactory System for Management of Commercial Records
  • SD134-9 Access Control
  • ITSG33-AC Access Control (AC)

DORA · 1 control

EU AI Act · 1 control

  • EUAI-Art.59 Further processing of personal data for developing certain AI systems in the public interest in the AI regulatory sandbox
  • CJIS-5.5 Access Control

ISO 27002:2022 · 1 control

NIS2 Directive · 1 control

  • Art.21.2.i Human resources security, access control policies and asset management

NIST SP 800-172 · 1 control

  • 3.1.2e Restrict Access to Organization-Owned, Provisioned, or Issued Information Resources

OWASP ASVS · 1 control

UK Cyber Essentials · 1 control

  • CE-AC.1 User Account Approval Process

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Organizational controls – ISO 27001:2022

You are reading one control. How much of ISO 27001:2022 have you already done?

ISO 27001:2022 5.15 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27001:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27001:2022 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 170 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 88 it maps to, and the evidence behind each claim, over MCP and REST.