ISO/IEC 27000 Access Rights, v2022

Specifies requirements in accordance with the security and privacy controls specified by ISO/IEC Publication 27001:2022, related to access rights.

Assessment Step

1
Access Rights (AccessRights)
Are access rights to information and other associated assets provisioned, reviewed, modified, and removed in accordance with the organization's topic-specific access control policies and rules?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.

Conformance Criteria (1)

Access Rights
Access rights to information and other associated assets shall be provisioned, reviewed, modified and removed in accordance with the organization's topic-specific policy on and rules for access control.
Citations
27001
Annex A, Control 5.18
27002
Section 5.18