ISO 27001:2022
Technological controls – ISO 27001:2022

ISO 27001:2022 8.3: Information access restriction

The organization is to limit who can reach information and associated assets, following its established access control policy. Purpose (stated in ISO/IEC 27002:2022): ensures only authorized access to information and associated assets and prevents unauthorized access. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 8.3.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 109 controls across 32 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 13 controls

PCI DSS 4.0 · 13 controls

  • 1.4.4 1.4.4 Cardholder data stores not reachable from untrusted networks
  • 1.4.5 1.4.5 Internal IP and routing disclosure limited
  • 3.4.2 3.4.2 Remote access blocks copying or relocating PAN
  • 3.5.1.2 3.5.1.2 Disk or partition encryption only on removable media
  • 3.6.1.2 3.6.1.2 Permitted storage forms for secret and private keys
  • 3.6.1.3 3.6.1.3 Cleartext key component access limited to minimum custodians
  • 7.3.3 7.3.3 Access control default deny all
  • 9.4.1 9.4.1 Physical security of all media
  • 7.2.4 7.2.4 User accounts and privileges reviewed every six months
  • 7.2.5 7.2.5 Application and system accounts least privilege
  • 7.2.6 7.2.6 Query access to stored cardholder data restricted
  • 7.3.1 7.3.1 Need-to-know access control system covers all components
  • 8.6.1 8.6.1 Interactive use of system accounts controlled

FedRAMP High · 8 controls

  • AC-3 Access Enforcement
  • AC-6 Least Privilege
  • CM-11 User-Installed Software
  • CM-12 Information Location (CM-12)
  • CM-5 Access Restrictions for Change
  • CM-5(1) Access Restrictions for Change | Automated Access Enforcement and Audit Records (CM-5(1))
  • MP-2 Media Access
  • SC-28 Protection of Information at Rest

FedRAMP Moderate · 8 controls

  • AC-3 Access Enforcement
  • AC-6 Least Privilege
  • CM-11 User-Installed Software
  • CM-12 Information Location (CM-12)
  • CM-5 Access Restrictions for Change
  • CM-5(1) Access Restrictions for Change | Automated Access Enforcement and Audit Records (CM-5(1))
  • MP-2 Media Access
  • SC-28 Protection of Information at Rest

SOC 2 · 7 controls

  • SOC2-CC5.1 CC5.1 Selecting control activities that mitigate risk (COSO principle 10)
  • SOC2-CC6.1 CC6.1 Logical access security over protected information assets
  • SOC2-CC6.2 CC6.2 Registering and authorising users before issuing credentials
  • SOC2-CC6.3 CC6.3 Role-based access, least privilege and segregation of duties
  • SOC2-CC6.7 CC6.7 Restricting and protecting information in transmission, movement and removal
  • SOC2-P5.1 P5.1 Data subject access
  • SOC2-PI1.2 PI1.2 Controls over system inputs

CMMC 2.0 · 6 controls

  • NIST-CSF-GV.PO-01 Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced
  • NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
  • NIST-CSF-PR.AA-06 Physical access to assets is managed, monitored, and enforced commensurate with risk
  • NIST-CSF-PR.DS-01 The confidentiality, integrity, and availability of data-at-rest are protected
  • NIST-CSF-PR.IR-01 Networks and environments are protected from unauthorized logical access and usage
  • NIST-CSF-PR.PS-05 Installation and execution of unauthorized software are prevented
  • ASBv3-AM-4 Limit access to asset management
  • ASBv3-DP-8 Ensure security of key and certificate repository
  • DP-2 Monitor anomalies and threats targeting sensitive data
  • IM-7 Restrict resource access based on conditions

CIS Controls v8 · 4 controls

  • CIS-2.7 Allowlist Authorized Scripts
  • CIS-3.3 Configure Data Access Control Lists
  • CIS-6.1 Establish an Access Granting Process
  • CIS-6.8 Define and Maintain Role-Based Access Control

HIPAA Security Rule · 4 controls

NIST SP 800-66 Rev 2 · 4 controls

C5 (Germany) · 3 controls

ISO 27701:2019 · 3 controls

  • 6.6.2 User access management
  • 6.6.4 System and application access control
  • 7.3.6 Access, correction and/or erasure

NIST SP 800-171 Rev 3 · 3 controls

UK Cyber Essentials · 2 controls

  • CE-AC.2 Authenticate Users Before Granting Access
  • CE-AC.4 Privileged Account Approval and Tracking
  • E8-ADMIN-ML3 Restrict Administrative Privileges (ML3)
  • ANSSI-HYG-09 Assign the Correct Rights on Sensitive Resources

APPI · 1 control

  • ASD37-22 Network segmentation (Excellent)
  • AUCDR-IS-1 Limit risk of unauthorised access to the CDR data environment

DORA · 1 control

EU AI Act · 1 control

  • EUAI-Art.59 Further processing of personal data for developing certain AI systems in the public interest in the AI regulatory sandbox

GDPR · 1 control

ISO 27001:2013 · 1 control

  • A.9.4.1 Information access restriction

ISO 27002:2022 · 1 control

  • 8.3 Information access restriction

NIS2 Directive · 1 control

  • Art.21.2.i Human resources security, access control policies and asset management

NIST SP 800-172 · 1 control

  • 3.13.2e Introduce Unpredictability into System Operations

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Technological controls – ISO 27001:2022

You are reading one control. How much of ISO 27001:2022 have you already done?

ISO 27001:2022 8.3 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27001:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27001:2022 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 170 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 109 it maps to, and the evidence behind each claim, over MCP and REST.