In this article I will show you what the access control policy is, how to write it and give you an ISO 27001 Access Control Policy template you can download and use right away.
I am Stuart Barker, the ISO 27001 Ninja and author of the Ultimate ISO 27001 Toolkit and this is everything you need to know about the ISO27001:2022 Access Control Policy.
Table of contents
- Key Takeaways
- ISO 27001 Access Control Policy
- Access Control Principles
- Access Control Methods
- Access Control Considerations
- Access Management Lifecycle
- ISO 27001 Access Control Policy Template
- ISO 27001 Access Control Policy Example
- How to write an ISO 27001 Access Control Policy
- Why is the ISO 27001 Access Control Policy Important?
- Access Control in Practice
- Benefits of implementing an ISO 27001 Access Control Policy
- ISO 27001 Access Control Policy FAQ
- Related ISO 27001 Controls
- About the author
Key Takeaways
- Access control is the most important control you will implement to protect the confidentiality of information
- Access control is based on legal, regulatory and contracutal requirements as well as the information classification policy
- Access control is a combination of technical controls and user education
ISO 27001 Access Control Policy
The ISO 27001 access control policy outlines how to manage and control access to organisational resources including data and systems. The policy covers the entire user access lifecycle and it ensures the correct access to the correct information and resources by the correct people. The objective is to limit access to information and systems based on need, the principle of least privilege and need to know.
In ISO 27001 this is a requirement of ISO27001:2022 Annex A 5.15 Access Control which is one of the 93 ISO 27001 Annex A controls.
Access Control Principles
Access control is based on 4 simple principles:
1. Need to Know
Users are only provided access to the information and systems they require to perform their tasks and role.
2. Least Privilege
The level of access provided to users is the minimum they need to be able to perform their tasks and role. This minimises the potential impact of a compromised account.
3. Segregation of Duty
Processes and functions should be separated to prevent any one person form having unchecked access and control. Segregation of duties involves dividing critical tasks among different individuals to prevent a single person from having too much control or the ability to compromise a process without detection. For example, the person who approves payments should not be the one who executes them.
4. Role Based Access (RBAC)
RBAC is a method of restricting system access based on the roles of individual users within an organisation. It’s important because it simplifies access management, improves security, and helps enforce the principle of least privilege.
Access Control Methods
There are 3 primary methods to control access. They are
1. Authentication
Allowing access based on something a person is, something a person knows or something a person. Or combination of these is called multi factor authentication (MFA). Examples include biometrics, passwords and security tokens.
2. Authorisation
The process of granting access based on a persons identity and role by the system or information owner.
3. Physical Access Control
The physical security controls, measures and barriers that restrict or prevent access to locations and systems. Examples include locks, gates, fences, walls.
ISO 27001 Starter Kit
Instant download of mandatory ISMS core policies and documentation. Verified by Lead Auditors and used by 5,000+ businesses worldwide to pass Stage 1 certification first time.
Access Control Considerations
When defining the policy and processes of access control the following considerations should be taken into account:
Business Requirements
Ensure that access control is in line with the requirements of the organisation and the information security obkectives.
Compliance
Ensure that access control fully meets the requirements of the law, regulation and customer contractual requirements.
Information Classification
Access control should be implemented based on the Information Classification Policy.
Remote Access
The policy should define secure methods for remote access, including the use of Virtual Private Networks (VPNs), strong authentication, and secure remote desktop protocols as well as specifying approved devices.
Cloud and Third Party Services
The policy should extend to cover access controls for third-party services, cloud platforms, and outsourced systems, ensuring that contractual agreements reflect the organisation’s security requirements.
Access Management Lifecycle
The lifecycle of user access is
1. Requesting Access
Someone requires access to systems or data and requests that access either for themselves or a member of their team.
2. Approving Access Requests
Access requests cannot be approved by the person requesting the access. This is known as segregation of duty. The person responsible for approving the access request is usually the system or data owner.
3. Implementing Access
Once approved the access will be granted and technically implemented. This is usually the responsibility of a trained IT professional. Great care should be taken if using the technique of copying or cloning access rights based on an existing user. This can introduce unintended consequences and result in unexpected unauthorised access. A better method is to base the access rights on role based access. Access that is defined by role and the role applied to the individual requiring access.
4. Managing Changes to Access
As a person changes role over time their access will be revisited and revised. To do this the process starts again at step 1 – requesting access.
5. Review Access
Access is reviewed on a regular basis. The main requirement is to conduct and evidence access reviews. Access reviews are usually performed by the system or data owner to ensure that the people with access are still required and relevant. Common practice is to conduct this on a monthly basis. It is a great way to catch when a person has left and their access has not been removed or to catch when a person has changed role and their access needs to be modified.
6. Access is Logged
Logging and monitoring access attempts (both successful and failed) are vital for detecting unauthorised activity, investigating security incidents, and providing an audit trail. Logs should be kept and reviewed at least monthly with incidents passed to the incident management team and managed via the incident management process.
7. Revoking Access
Revoking access can take place during a change in role or when a person leaves the organisation. It is best practice to revoke that access at the earliest opportunity. For audit trail the process of requesting the access be revoked, that request being approved and then actioned would be followed.
ISO 27001 Access Control Policy Template
The ISO 27001 Access Control Policy template is pre written and ready to go. It is one of the required ISO 27001 policies that sets out the organisations approach to access control.

ISO 27001 Access Control Policy Example
This is an example ISO 27001 Access Control Policy:
How to write an ISO 27001 Access Control Policy
The ISO 27001 Access Control Policy is required to be presented in a certain way. What we mean by that is that the policy is expected to have certain document markup. Document mark up is just a fancy words for having certain information on the policy. It will need version control, a version number, an owner, an information security classification.
- Write the ISO 27001 Access Control Policy contentsAn example ISO 27001 Access Control Policy table of contents
- Write the ISO 27001 Access Control Policy purpose
- Write the ISO 27001 Access Control Policy principle
- Write the ISO 27001 Access Control Policy scope
- Describe your use of confidentiality agreements
- Explain role based access
- Define the use of unique identifiers
- Define the use of access authentication
- Explain the approach to access rights reviews
- Describe the use of privilege accounts and administrator accounts
- Define the policy for passwords
- Explain user account provisioning
- Document how you treat leavers
- Set the rules for the authentication system
- Explain your approach to remote access
- Explain your approach to third party remote access
- Describe monitoring and reporting
- Document data masking
Why is the ISO 27001 Access Control Policy Important?
A cornerstone of information security is confidentiality and providing the right access to the right people at the right time. We want to ensure that people have access to do their job but no more. We want to protect the information and data that we have.
People will talk about preventing unauthorised access which is a fancy way of saying getting access to data they should not have. By protecting the access to the data we can reduce the risk of information security incidents and data breaches.
The ISO 27001 Access Control Policy is important as it sets out clearly and in written form what you expect to happen. If you don’t tell people what you expect of them then how can you expect them to do it? Communicating what is expected is a key step in any HR disciplinary process with many not being enforceable or actionable if you have not told people what to do and got them to accept that they understand what is being asked.
The ISO 27001 standard wants you to have the access control policy in place, communicated, and accepted by staff as part of your ISO 27001 certification. It actually forms part of a wider set of required information security policies that are all included in the ISO 27001 toolkit.
Access Control in Practice
The ISO 27001 Access Control Policy is all about access to systems and data. When looking at access we are looking at the different types of access. We differentiate between normal users and administrators.
First things first we want to ensure that we have confidentiality agreements in place and being required to access systems. This may form part of employment contracts. It makes sense to grant access to systems based on roles where the role defines the level of access that is allowed. We want to ensure that we can track actions back to individuals so the concept of one user and one ID is introduced. If we have shared accounts it can be nearly impossible to track back who exactly did what. This can become critical if incidents occur and we need to conduct investigations. Users of systems are responsible for their actions.
System access is not a one time deal. We will have a start, leaver, mover process that covers the provision of access, the changes to access as roles change and the removal of access when someone leaves. To ensure that all is working as planned we are going to conduct regular access reviews. An access review is as simple as seeing who has access to systems, what level of access they have and confirming that they still need it. If they don’t, or they have changed role, or they have left and the normal processes hasn’t caught it then we handle it at that point.
Our most powerful users are administrators. They hold the keys to the kingdom. There are special considerations when it comes these administrative accounts. How they are allocated, when they are allocated, how they are used, how they are monitored is addressed.
We all use passwords and the rules for passwords are set. How passwords are created, how complex do they need to be, how often if at all are they changed, how are they communicated to users. Passwords are the keys to the doors of our systems and data so we are clear on their management and use.
Often times we rely on third parties or suppliers to help support and run our systems. We want to grant them the access that they need, when they need it to help us. We set out the policy and rules for their access. We also address remote access of all users.
Benefits of implementing an ISO 27001 Access Control Policy
The main benefit is that it allows you to mitigate the risk of access to systems and data. Access poses unique challenges as it is the primary way people gain entry to systems and data to perform their role so the risks need to be assessed and appropriate controls implemented. The benefits of implementing an ISO 27001 Access Control Policy include:
- Access to data will be granted only to those that require it and have been approved reducing the risk of unauthorised access and data breaches.
- Improved compliance and meet the needs of laws and regulations that require access controls to be place
- Protection of confidential information
- Building trust with employees and third parties
- Reputation Protection because in the event of a breach having effective remote working controls in place will reduce the potential for fines and reduce the PR impact of an event.
ISO 27001 Access Control Policy FAQ
The ISO 27001 Access Control Policy can be downloaded at High Table: The ISO 27001 Company.
The purpose of the ISO 27001 Access Control Policy is to ensure the correct access to the correct information and resources by the correct people.
Access control is granted on the principle of least privilege. Users are only provided access to the information they require to perform their tasks and role.
1. Requesting Access
2. Approving Access Requests
3. Implementing Access
4. Managing Changes to Access
5. Monitoring Access
6. Revoking Access
Access is the responsibility of the data and system owners. The ISO 27001 Access Control Policy is the responsibility of the senior leadership team. This can also be the senior operational leadership team.
ISO 27001 Clause 5 Leadership
ISO 27001 Clause 5.1 Leadership and commitment
ISO 27001 Clause 5.2 Policy
ISO 27001 Clause 6.2 Information security objectives and planning to achieve them
ISO 27001 Clause 7.5.3 Control of documented information
ISO 27001 Clause 7.3 Awareness
ISO27001 Annex A 5.15 Access Control
ISO 27001 Annex A 5.16 Identity Management
ISO 27001 Annex A 5.17 Authentication Information
ISO 27001 Annex A 5.18 Access Rights
Unauthorised access: accessing data without authorisation or approval.
Unauthorised disclosure of data: sharing data or information with people that are not authorised to access it.
Sharing passwords: allowing others to use your password to access data to which they are not authorised.
Unauthorised destruction or modification of data: Changing or modifying data you have access to but are not granted to permission to delete or modify.
Not managing access to systems can have severe consequences. This is a simple, effective protection against cyber attack and data breach. Like giving a key to your door to everyone and anyone that asks, you are inviting attackers into your systems. The consequences could be legal and regulatory fines and / or enforcement, loss of data, loss of revenue and in the most extreme cases risk to life and closure of your organisation.
The approaches to monitoring the effectives of access control include:
Monthly access reviews by the system and data owners
Internal audit of the access control process
External audit of the access control process
Review of system logs and alerts for anomalies in operation
Access control is primarily addressed in Annex A.9 (Access Control) of ISO 27001. This section contains a set of specific controls related to managing access to information and information processing facilities.
Yes, it is essential. ISO 27001 requires organizations to establish and implement an Access Control Policy as part of their Information Security Management System (ISMS) to meet the requirements of ISO27001:2022 Annex A 5.15 Access Control
It should include principles for access control, user access management, system and application access control, mobile device access, remote access, privileged access management, and segregation of duties.
Strong authentication, such as multi-factor authentication (MFA), is crucial for verifying user identities and is often a key requirement of an ISO 27001 Access Control Policy.
Logging and monitoring access attempts (both successful and failed) are vital for detecting unauthorised activity, investigating security incidents, and providing an audit trail.
A robust Access Control Policy contributes to effective incident response by ensuring that unauthorised access is minimised, and in the event of a breach, access logs provide crucial information for investigation and containment.
Related ISO 27001 Controls
The ISO 27001 Access Control Policy satisfies the following clauses in ISO 27001:2022
- ISO 27001 Annex A 5.15 Access Control
- ISO 27001 Annex A 5.16 Identity Management
- ISO 27001 Annex A 5.17 Authentication Information
- ISO 27001 Annex A 5.18 Access Rights
- ISO 27001 Annex A 8.4 Access to source code
- ISO 27001 Annex A 8.5 Secure authentication
- ISO 27001 Annex A 8.11 Data Masking








