ISO/IEC 27000 Information Access Restriction, v2022

Specifies requirements in accordance with the security and privacy controls specified by ISO/IEC Publication 27001:2022, related to information access restriction.

Assessment Step

1
Information Access Restriction (InformationAccessRestriction)
Is access to information and other associated assets restricted in accordance with the established topic-specific policy on access control?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.

Conformance Criteria (1)

Information Access Restriction
Access to information and other associated assets shall be restricted in accordance with the established topic-specific policy on access control.
Citations
27001
Annex A, Control 8.3
27002
Section 8.3