ISO 27001

ISO 27001 A.5.15 Access control: what it requires and what auditors check

A.5.15 asks for rules on who can access what, based on business and security needs. Here is how to set them, and the evidence that proves they work.

Short answer

ISO 27001 Annex A control 5.15, Access control, requires rules to control physical and logical access to information and other associated assets, set according to business and information security requirements. In practice that means an approved access control policy, need-to-know and least-privilege principles, and records showing access is granted and reviewed against those rules.

Key takeaways

  • A.5.15 sets the rules; A.5.16 to A.5.18 and A.8.2 to A.8.5 put them into practice.
  • Rules should follow need-to-know and least privilege.
  • Physical and logical access are both in scope.
  • Auditors test the rules against real access, not just the policy.

What the control says

A.5.15 is an organisational control in ISO/IEC 27001:2022 Annex A. It combines the 2013 controls on access control policy and access to networks and network services into one requirement: define and implement rules for physical and logical access to information and associated assets, based on business and information security requirements. ISO/IEC 27002 adds guidance, such as considering the security requirements of each application, information classification, segregation of access roles, and legal or contractual obligations.

How it connects to other controls

A.5.15 is the policy layer. The detailed mechanics sit in related controls: , , , , and . Auditors often test them together.

How to implement it

  1. Write an access control policy covering principles (need-to-know, least privilege), roles, approval and review.
  2. Define access by role for each important system: which roles get which permissions.
  3. Set approval rules: who can approve access, and how privileged access differs.
  4. Apply the same thinking to physical access to offices and equipment.
  5. Review access regularly and remove what is no longer needed.

Evidence auditors sample

EvidenceWhat it shows
Approved access control policyRules exist and are approved
Role-to-permission matrix for key systemsRules are applied per system
Access request and approval ticketsAccess is granted under the rules
Access review recordsRules are checked and access removed when not needed
Physical access lists and logsPhysical access follows the same principles

Common findings

  • A policy that says least privilege, while most users hold admin rights
  • No defined roles, so every request is approved case by case
  • Physical access left out of the policy
  • Shared accounts with no owner
ISO 27001:2022Other frameworks
  1. A.5.15Access controlSOC 2 CC6.1Logical access security
  2. A.5.15Access controlNIST CSF PR.AA-05Access permissions managed
  3. A.5.15Access controlPCI DSS Req 7Restrict access by need to know
Full mappingPartial mappingIndicative mapping for planning.

Put this into practice on QULDEX

Frequently asked questions

What replaced A.9.1.1 from ISO 27001:2013?

A.5.15 Access control in the 2022 edition combines the former access control policy (A.9.1.1) and access to networks and network services (A.9.1.2).

Is an access control policy mandatory?

If A.5.15 is in your Statement of Applicability, you need documented rules. ISO/IEC 27002 recommends a topic-specific access control policy.

Sources

  1. ISO/IEC 27001:2022 Information security management systems: Requirements, ISO
  2. ISO/IEC 27002:2022 Information security controls, ISO
  3. NIST SP 800-53 Rev. 5 Security and Privacy Controls, NIST