Skip to content
compliancebase
ISO 27001A.5 — Access control

A.5.15

Access control

ISO 27001 · ISO/IEC 27001:2022 · Last verified July 2026

Objective

Limit access to information and information processing facilities according to the business and security requirements defined by the organization.

Points of focus

  • Access control policy and rules defined
  • Access based on need-to-know / least privilege
  • Rules cover users, privileged roles, and service identities
  • Periodic review of access rights

Implementation notes

Centralize workforce and contractor identities in one IdP with SSO into production and admin surfaces. Encode least privilege in groups/roles, not tribal grants. Automate quarterly access-review packets from the IdP and retain dated remediations. Document emergency break-glass paths. Crosswalk to SOC 2 CC6 and HIPAA access controls when those programs run in parallel — one operating model, multiple evidence labels.

Audit tip: Sample access reviews that show population, reviewer, date, and outcomes — calendar invites alone fail.

Evidence auditors typically request:

  • Access control policy covering JML
  • IdP group/role model documentation
  • Quarterly access review packets with dated sign-off
  • Break-glass / privileged access procedure

Common gaps

  • Reviews without remediations recorded
  • Shared admin accounts outside the IdP
  • Contractors omitted from review populations

Cross-Framework Mapping

FrameworkRequirementImplementation note
ISO 27001A.5.15This control
SOC 2CC6.1, CC6.2, CC6.3Related Trust Services Criteria themes — map in your crosswalk; not identical requirements.
GDPRArticle 32Related GDPR articles for personal-data security or processor themes — not a compliance claim.
HIPAA164.312(a)(1)Related HIPAA Security Rule citations when PHI is in scope — SoA does not replace BAAs.

Primary sources

Frequently Asked Questions

No. A.5.15 is the access-control rule set. MFA and technical enforcement typically land under A.8.5 and related technological controls.

Commonly to CC6.1–CC6.3 themes. Use your crosswalk; do not claim identical wording between Annex A and Trust Services Criteria.

Yes. Non-human identities that can reach production data belong in inventory, ownership, and review processes.

In an approved access-control policy (A.5.15) implemented through identity, authentication, and rights processes (A.5.16–A.5.18 and A.8.x). Tool screenshots alone are not the policy.

When you change IdP, introduce new admin planes, or expand products that hold customer data — and at least during periodic risk/SoA review.

Framework versions referenced in this page:

  • ISO/IEC 27001ISO/IEC 27001:2022

Last verified: July 2026 · Primary sources linked above