ISO/IEC 27000 Access Control, v2022

Specifies requirements in accordance with the security and privacy controls specified by ISO/IEC Publication 27001:2022, related to access control.

Assessment Step

1
Access Control (AccessControl)
Has the organization established and implemented rules to control physical and logical access to information and other associated assets based on business and information security requirements?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.

Conformance Criteria (1)

Access Control
Rules to control physical and logical access to information and other associated assets shall be established and implemented based on business and information security requirements.
Citations
27001
Annex A, Control 5.15
27002
Section 5.15