ISO/IEC 27001:2022 Annex A · Control 5.15
Access Control: A Practical Implementation Guide
Establish consistent business rules for granting, using, reviewing and removing access.
Access control policy sets the principles and lifecycle requirements used by identity, application, physical and privileged-access processes.
What should the control achieve?
- Access is based on business need and least privilege.
- Authorization is separated from provisioning.
- Access is reviewed and removed promptly.
- Special risks such as privilege and remote access receive stronger control.
Step-by-step implementation
Define policy principles
Cover need-to-know, least privilege, unique identity, segregation, default denial and accountability.
Establish access models
Use role, attribute or individually approved access according to system needs.
Design the lifecycle
Document request, approval, provisioning, review, change, suspension and removal.
Set stronger controls
Apply MFA, time limitation, monitoring and separate accounts for privileged or remote access.
Assign owners
Asset owners approve access; administrators implement; Security oversees rules.
Review effectiveness
Test samples, orphan accounts, excessive rights and overdue removals.
What this could look like in practice
A SaaS company uses role-based profiles for standard access. Managers request access, application owners approve sensitive roles and IT provisions through the identity platform. Privileged access is time-limited and reviewed quarterly.
| Activity | Practical implementation | Evidence |
|---|---|---|
| Joiner | Approved role profile is assigned after manager request. | Workflow record |
| Role change | Old access is removed before new privileges are added. | Mover ticket |
| Periodic review | Owner confirms, removes or justifies each entitlement. | Signed review |
| Emergency access | Time-limited elevation with alert and retrospective review. | Session and approval log |
Implementation evidence
- Access control policy
- Role catalogue
- Approval matrix
- Provisioning workflows
- Access reviews
- Privileged-access logs
- Orphan-account reports
- Removal records
Useful metrics
- Access removed within target
- Overdue access reviews
- Orphan or dormant accounts
- Privileged grants outside standard workflow
Common mistakes
- Managers approving access they do not understand.
- Accumulating rights after role changes.
- Using shared accounts without accountability.
- Reviewing account existence but not entitlements.
- Treating physical and cloud access separately from policy.
Questions an auditor may ask
- How is business need demonstrated?
- Who approves sensitive access?
- Show a joiner, mover and leaver.
- How are privileged and emergency rights controlled?
Continue through Annex A
Explore the growing library of practical guides for all 93 Annex A controls.
Open the ISO 27001 Annex A Control LibraryThis independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.