Skip to main content

Proof of competence

ISO/IEC 27001:2022 Annex A · Control 5.15

Access Control: A Practical Implementation Guide

Establish consistent business rules for granting, using, reviewing and removing access.

Access control policy sets the principles and lifecycle requirements used by identity, application, physical and privileged-access processes.

Practical interpretation: Access control is a governance system, not only a technical setting. Business owners must decide need, systems must enforce decisions and evidence must show timely lifecycle control.

What should the control achieve?

  • Access is based on business need and least privilege.
  • Authorization is separated from provisioning.
  • Access is reviewed and removed promptly.
  • Special risks such as privilege and remote access receive stronger control.

Step-by-step implementation

1

Define policy principles

Cover need-to-know, least privilege, unique identity, segregation, default denial and accountability.

2

Establish access models

Use role, attribute or individually approved access according to system needs.

3

Design the lifecycle

Document request, approval, provisioning, review, change, suspension and removal.

4

Set stronger controls

Apply MFA, time limitation, monitoring and separate accounts for privileged or remote access.

5

Assign owners

Asset owners approve access; administrators implement; Security oversees rules.

6

Review effectiveness

Test samples, orphan accounts, excessive rights and overdue removals.

What this could look like in practice

A SaaS company uses role-based profiles for standard access. Managers request access, application owners approve sensitive roles and IT provisions through the identity platform. Privileged access is time-limited and reviewed quarterly.

ActivityPractical implementationEvidence
JoinerApproved role profile is assigned after manager request.Workflow record
Role changeOld access is removed before new privileges are added.Mover ticket
Periodic reviewOwner confirms, removes or justifies each entitlement.Signed review
Emergency accessTime-limited elevation with alert and retrospective review.Session and approval log

Implementation evidence

  • Access control policy
  • Role catalogue
  • Approval matrix
  • Provisioning workflows
  • Access reviews
  • Privileged-access logs
  • Orphan-account reports
  • Removal records

Useful metrics

  • Access removed within target
  • Overdue access reviews
  • Orphan or dormant accounts
  • Privileged grants outside standard workflow

Common mistakes

  • Managers approving access they do not understand.
  • Accumulating rights after role changes.
  • Using shared accounts without accountability.
  • Reviewing account existence but not entitlements.
  • Treating physical and cloud access separately from policy.

Questions an auditor may ask

  • How is business need demonstrated?
  • Who approves sensitive access?
  • Show a joiner, mover and leaver.
  • How are privileged and emergency rights controlled?
Implementation test: Sample ten users across departments and trace each entitlement to current role need, approval and review.

Continue through Annex A

Explore the growing library of practical guides for all 93 Annex A controls.

Open the ISO 27001 Annex A Control Library

This independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.