ISO/IEC 27000 Access Rights, v2022
Specifies requirements in accordance with the security and privacy controls specified by ISO/IEC Publication 27001:2022, related to access rights.
Assessment Step
1
Access Rights (AccessRights)
Are access rights to information and other associated assets provisioned, reviewed, modified, and removed in accordance with the organization's topic-specific access control policies and rules?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.
|
Conformance Criteria (1)
Access Rights
Access rights to information and other associated assets shall be provisioned, reviewed, modified and removed in accordance with the organization's topic-specific policy on and rules for access control.
Citations
27001
Annex A, Control 5.18
27002
Section 5.18
|