Rules that govern both physical entry and logical access to information and associated assets are to be set and applied on the basis of business and information security requirements. Purpose: allow access that is authorized and block access that is not. Guidance: asset owners work out the business and security requirements for access, and a topic-specific access control policy reflecting them is defined and communicated. Requirements and policy consider: which entities need which kinds of access; application security (8.26); physical access backed by entry controls (7.2 to 7.4); dissemination and authorization including need-to-know, and classification levels (5.10, 5.12, 5.13); limits on privileged access (8.2); segregation of duties (5.3); laws, regulations and contracts restricting access to data or services (5.31 to 5.34, 8.3); separation of the access control functions of requesting, authorizing and administering; formal approval of access requests (5.16, 5.18); managing access rights (5.18); and logging (8.15). Rules are put into effect by defining access rights and restrictions and mapping them to entities, which may be people or technical items such as machines, devices or services, and roles for groups of entities simplify management. When defining the rules, keep access rights consistent with classification and with physical perimeter needs, account for every type of connection in distributed environments so entities reach only authorized networks, services and information, and consider how dynamic factors can be reflected. Other information: need-to-know and need-to-use are the usual guiding principles; rules should default to deny (least privilege) rather than default to allow; care is needed over automatic versus user-initiated label changes and system versus administrator permission changes, and over when approvals are set and reviewed. Rules are backed by documented procedures and defined responsibilities, can be implemented as MAC, DAC, RBAC or ABAC, may include dynamic elements such as past access or location and connection type, and can range from whole networks to single data fields, with finer granularity costing more, so business need and risk decide the level.
This control maps to 102 controls across 34 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization
NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
NIST-CSF-PR.AA-06 Physical access to assets is managed, monitored, and enforced commensurate with risk
NIST-CSF-PR.IR-01 Networks and environments are protected from unauthorized logical access and usage
You are reading one control. How much of ISO 27002:2022 have you already done?
ISO 27002:2022 5.15 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.