Access control policy
**Document control**
| Field | Value | |---|---| | Organization | [COMPANY NAME] | | Policy owner | [OWNER NAME / ROLE] | | Approver | [APPROVER NAME / ROLE] | | Version | [VERSION] | | Effective date | [YYYY-MM-DD] | | Next review | [YYYY-MM-DD] |
**Mapped themes:** SOC 2 CC6.1–CC6.3; ISO/IEC 27001:2022 Annex A.5.15, A.5.16, A.5.18, A.8.2, A.8.5 (educational mapping).
1. Purpose
This policy defines how [COMPANY NAME] restricts logical access to information assets so that only authorized users and services can access systems and data.
2. Scope
Applies to workforce and contractor identities, service accounts, and production, staging, and administrative systems in the security program scope.
3. Policy statements
- Access is provisioned based on role and least privilege using the corporate identity provider where feasible.
- Human access to production and administrative consoles requires multi-factor authentication.
- Joiner, mover, and leaver processes provision, modify, and revoke access within defined SLAs.
- Privileged access is minimized, logged, and reviewed more frequently than standard access.
- Access reviews occur at least quarterly for in-scope systems and produce dated artifacts naming reviewer, population, and remediations.
- Shared credentials for production systems are prohibited except documented break-glass accounts with monitoring.
- Service accounts have named human owners and are included in reviews.
- Remote access uses approved secure channels (SSO, VPN/ZTNA) consistent with network standards.
4. Roles
- **Identity owner:** [ROLE]
- **System owners:** Approve access to their systems
- **Reviewers:** Complete scheduled access reviews
5. Exceptions
Temporary elevated access requires a ticket, time bound, and MFA. Standing exceptions need risk acceptance by [ROLE].
6. Related documents
Information security policy; Change management policy; Incident response policy.
---
**Disclaimer:** Educational template only — not legal advice. Adapt with counsel and your auditor. ComplianceBase is vendor-neutral and independent.