ISO 27002:2022 8.3: Information access restriction
The organization is to limit who can reach information and associated assets, following its established access control policy. Purpose: permit authorized access and block unauthorized access to information and associated assets. Guidance: to support restriction, consider not allowing unknown or anonymous identities to reach sensitive information, granting public or anonymous access only to locations holding nothing sensitive; configuration settings that govern who reaches what inside systems, applications and services; control over which data each user can reach; control over which identities or groups hold which permissions, for example reading, writing, deleting or executing; and physical or logical isolation of sensitive applications, their data or systems. Consider dynamic access management for high-value sensitive information where the organization needs fine-grained control over who accesses it, when and how; wants to share it externally while keeping control; wants to manage its use and distribution in real time; wants to prevent unapproved alteration, copying, forwarding or printing; wants to monitor its use; or wants a record of changes for possible investigation. Such techniques should protect information throughout creation, processing, storage, transmission and disposal, with rules per use case that grant permissions by identity, device, location or application and use the classification scheme to decide what needs this protection, backed by operating, monitoring and reporting processes and technical infrastructure. Dynamic access systems protect information by requiring authentication, credentials or a certificate; limiting access to a time window; encrypting it; setting print permissions; recording who uses it and how; and alerting on attempted misuse. Other information: these techniques can protect documents, emails and files even after they leave the organization, where ordinary controls cannot reach, adapting over the life cycle; they supplement rather than replace classic controls such as access control lists by adding conditions, real-time evaluation and just-in-time data reduction; permissions can be changed or withdrawn at any time, which aids incident response; ISO/IEC 29146 provides a framework.
This control maps to 82 controls across 32 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
NIST-CSF-PR.DS-01 The confidentiality, integrity, and availability of data-at-rest are protected
NIST-CSF-PR.PS-05 Installation and execution of unauthorized software are prevented
You are reading one control. How much of ISO 27002:2022 have you already done?
ISO 27002:2022 8.3 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.