Short answer
ISO 27001 Annex A control 5.15, Access control, requires rules to control physical and logical access to information and other associated assets, set according to business and information security requirements. In practice that means an approved access control policy, need-to-know and least-privilege principles, and records showing access is granted and reviewed against those rules.
Key takeaways
- A.5.15 sets the rules; A.5.16 to A.5.18 and A.8.2 to A.8.5 put them into practice.
- Rules should follow need-to-know and least privilege.
- Physical and logical access are both in scope.
- Auditors test the rules against real access, not just the policy.
What the control says
A.5.15 is an organisational control in ISO/IEC 27001:2022 Annex A. It combines the 2013 controls on access control policy and access to networks and network services into one requirement: define and implement rules for physical and logical access to information and associated assets, based on business and information security requirements. ISO/IEC 27002 adds guidance, such as considering the security requirements of each application, information classification, segregation of access roles, and legal or contractual obligations.
How it connects to other controls
A.5.15 is the policy layer. The detailed mechanics sit in related controls: , , , , and . Auditors often test them together.
How to implement it
- Write an access control policy covering principles (need-to-know, least privilege), roles, approval and review.
- Define access by role for each important system: which roles get which permissions.
- Set approval rules: who can approve access, and how privileged access differs.
- Apply the same thinking to physical access to offices and equipment.
- Review access regularly and remove what is no longer needed.
Evidence auditors sample
| Evidence | What it shows |
|---|---|
| Approved access control policy | Rules exist and are approved |
| Role-to-permission matrix for key systems | Rules are applied per system |
| Access request and approval tickets | Access is granted under the rules |
| Access review records | Rules are checked and access removed when not needed |
| Physical access lists and logs | Physical access follows the same principles |
Common findings
- A policy that says least privilege, while most users hold admin rights
- No defined roles, so every request is approved case by case
- Physical access left out of the policy
- Shared accounts with no owner
A.5.15Access controlSOC 2 CC6.1Logical access securityA.5.15Access controlNIST CSF PR.AA-05Access permissions managedA.5.15Access controlPCI DSS Req 7Restrict access by need to know
Put this into practice on QULDEX
Frequently asked questions
What replaced A.9.1.1 from ISO 27001:2013?
A.5.15 Access control in the 2022 edition combines the former access control policy (A.9.1.1) and access to networks and network services (A.9.1.2).
Is an access control policy mandatory?
If A.5.15 is in your Statement of Applicability, you need documented rules. ISO/IEC 27002 recommends a topic-specific access control policy.