ISO 27002:2022
Organizational controls – ISO 27002:2022

ISO 27002:2022 5.15: Access control

Rules that govern both physical entry and logical access to information and associated assets are to be set and applied on the basis of business and information security requirements. Purpose: allow access that is authorized and block access that is not. Guidance: asset owners work out the business and security requirements for access, and a topic-specific access control policy reflecting them is defined and communicated. Requirements and policy consider: which entities need which kinds of access; application security (8.26); physical access backed by entry controls (7.2 to 7.4); dissemination and authorization including need-to-know, and classification levels (5.10, 5.12, 5.13); limits on privileged access (8.2); segregation of duties (5.3); laws, regulations and contracts restricting access to data or services (5.31 to 5.34, 8.3); separation of the access control functions of requesting, authorizing and administering; formal approval of access requests (5.16, 5.18); managing access rights (5.18); and logging (8.15). Rules are put into effect by defining access rights and restrictions and mapping them to entities, which may be people or technical items such as machines, devices or services, and roles for groups of entities simplify management. When defining the rules, keep access rights consistent with classification and with physical perimeter needs, account for every type of connection in distributed environments so entities reach only authorized networks, services and information, and consider how dynamic factors can be reflected. Other information: need-to-know and need-to-use are the usual guiding principles; rules should default to deny (least privilege) rather than default to allow; care is needed over automatic versus user-initiated label changes and system versus administrator permission changes, and over when approvals are set and reviewed. Rules are backed by documented procedures and defined responsibilities, can be implemented as MAC, DAC, RBAC or ABAC, may include dynamic elements such as past access or location and connection type, and can range from whole networks to single data fields, with finer granularity costing more, so business need and risk decide the level.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 102 controls across 34 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

PCI DSS 4.0 · 9 controls

  • 3.6.1.3 3.6.1.3 Cleartext key component access limited to minimum custodians
  • 7.2.1 7.2.1 Access control model defined
  • 7.2.2 7.2.2 User access assigned by job function and least privilege
  • 7.3.3 7.3.3 Access control default deny all
  • 9.4.1 9.4.1 Physical security of all media
  • 3.6.1 3.6.1 Procedures protect keys against disclosure and misuse
  • 7.2.4 7.2.4 User accounts and privileges reviewed every six months
  • 7.2.5 7.2.5 Application and system accounts least privilege
  • 7.3.1 7.3.1 Need-to-know access control system covers all components

CIS Controls v8 · 6 controls

  • CIS-12.7 Ensure Remote Devices Utilize a VPN and are Connecting to an Enterprise’s AAA Infrastructure
  • CIS-3.3 Configure Data Access Control Lists
  • CIS-6.1 Establish an Access Granting Process
  • CIS-6.2 Establish an Access Revoking Process
  • CIS-6.7 Centralize Access Control
  • CIS-6.8 Define and Maintain Role-Based Access Control

FedRAMP High · 6 controls

  • AC-1 Policy and Procedures
  • AC-12 Session Termination
  • AC-14 Permitted Actions Without Identification or Authentication
  • AC-3 Access Enforcement
  • AC-6 Least Privilege
  • AC-7 Unsuccessful Logon Attempts

FedRAMP Moderate · 6 controls

  • AC-1 Policy and Procedures
  • AC-12 Session Termination
  • AC-14 Permitted Actions Without Identification or Authentication
  • AC-3 Access Enforcement
  • AC-6 Least Privilege
  • AC-7 Unsuccessful Logon Attempts

ISO 27701:2019 · 6 controls

  • 6.4.2 During employment
  • 6.6 Access control
  • 6.6.1 Business requirements of access control
  • 7.3.6 Access, correction and/or erasure
  • 7.4.2 Limit processing
  • 8.3.1 Obligations to PII principals

CMMC 2.0 · 5 controls

NIST SP 800-53 Rev 5 · 5 controls

SOC 2 · 5 controls

  • SOC2-CC6.1 CC6.1 Logical access security over protected information assets
  • SOC2-CC6.2 CC6.2 Registering and authorising users before issuing credentials
  • SOC2-CC6.3 CC6.3 Role-based access, least privilege and segregation of duties
  • SOC2-CC6.4 CC6.4 Restricting physical access to facilities and assets
  • SOC2-P5.1 P5.1 Data subject access
  • ISM-0409 Foreign national access to AUSTEO and REL systems
  • ISM-0411 Foreign national access to AGAO systems
  • ISM-0432 Documenting access requirements in the SSP
  • ISM-1852 Least privilege for unprivileged access
  • ASBv3-AM-4 Limit access to asset management
  • ASBv3-GS-6 Define and implement identity and privileged access strategy
  • ASBv3-PA-7 Follow just enough administration (least privilege) principle
  • IM-7 Restrict resource access based on conditions

HIPAA Security Rule · 4 controls

  • NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization
  • NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
  • NIST-CSF-PR.AA-06 Physical access to assets is managed, monitored, and enforced commensurate with risk
  • NIST-CSF-PR.IR-01 Networks and environments are protected from unauthorized logical access and usage

NIST SP 800-66 Rev 2 · 4 controls

NIST SP 800-171 Rev 3 · 3 controls

  • 0129 0129 Facilitate access to official information
  • 0130 0130 Control access to systems, networks, infrastructure, devices and applications
  • 0131 0131 Need-to-know for classified access
  • ANSSI-HYG-08 Identify Each Person by Name and Separate User and Administrator Roles
  • ANSSI-HYG-09 Assign the Correct Rights on Sensitive Resources
  • MYHR-SEC-2 Access controls and user account management
  • MYHR-SEC-7 Consumer access controls and consent

C5 (Germany) · 2 controls

  • 16.1.24.C.01 16.1.24.C.01 Identity, authentication and authorisation policies communicated to users
  • 16.2.4.C.01/CID1930 16.2.4.C.01 Defined eight-stage process for building access control lists
  • AUCDR-IS-1 Limit risk of unauthorised access to the CDR data environment
  • AEO-3 Satisfactory System for Management of Commercial Records

DORA · 1 control

ISO 27001:2022 · 1 control

MTCS (Singapore) · 1 control

  • A.19 Disclosure: User management

NIS2 Directive · 1 control

  • Art.21.2.i Human resources security, access control policies and asset management

NIST SP 800-172 · 1 control

  • 3.1.2e Restrict Access to Organization-Owned, Provisioned, or Issued Information Resources
  • NRC7354-5 Access Control, Authentication, Removable Media, and Portable Devices
  • TSA-SD-06 Access control to Critical Cyber Systems

UK Cyber Essentials · 1 control

  • CE-AC.1 User Account Approval Process

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Organizational controls – ISO 27002:2022

You are reading one control. How much of ISO 27002:2022 have you already done?

ISO 27002:2022 5.15 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 102 it maps to, and the evidence behind each claim, over MCP and REST.