ISO27001:2022 – A5.15

Access control

Introduction to ISO 27001 – A5.15

Do you allow anyone into your house? Would you let them roam freely, open your wardrobe, or read your personal diary? Probably not. In the same way, you must control access to your organisation’s information and other assets. That’s what ISO 27001 – A5.15 control is all about.

What does ISO 27001 – A5.15 require?

The standard states that:

“Rules to control physical and logical access to information and other associated assets shall be established and implemented based on business and information security requirements.” (A5.15 Access Control)

Why is this required?

You wouldn’t allow just anyone to enter your premises or log into your systems. This control ensures you consciously manage both physical and logical access to information and systems — especially those that may be targeted by criminals.

For example, your IT vendor might require access to infrastructure systems but not your HR platform. Likewise, your HR team should not have access to financial records unless necessary. Managing who has access to what helps protect your organisation from unauthorised access and misuse.

What the auditor is looking for

The auditor will expect to see a topic-specific Access Control Policy covering both physical locations and information systems.

You should also be able to demonstrate how access is:

  • Granted
  • Changed
  • Revoked
  • Reviewed

Even if you don’t have a formal process document, you must show that the process exists and is followed. Examples of evidence may include:

  • Induction checklists or onboarding procedures
  • Access request forms or IT helpdesk tickets
  • Role-Based Access Control (RBAC) records
  • Exit checklists for revoking access (linked to A6.5)

You should also be able to describe how physical access is controlled — such as locked rooms, PIN codes, or security passes — and who is allowed access to each area.

While the control doesn’t require a written process, documenting one can help standardise practices and support internal training (linked to A6.3 – Security Awareness Training).

Q & A

Do I need a written policy?

Yes. This control explicitly calls for “rules,” and A5.18 also references the need for a topic-specific Access Control Policy. The policy should focus on the who, why, and what — not necessarily the detailed “how.” The latter can be shown through support tickets, workflows, and audits.

Is it possible to get this wrong?

Yes. You must be able to:

  • Show that a policy exists
  • Provide evidence of how access is controlled and reviewed
  • Demonstrate physical and system access procedures (even if informal)

If you can’t provide this evidence, or if no one is managing access controls, your organisation is non-compliant.

Difficulty rating

We rate this control a 2 out of 5. It requires a moderate level of understanding, coordination with your IT and facilities teams, and the development of some supporting materials such as onboarding/offboarding checklists and RBAC forms.

More questions?

ISO27001 controls are interconnected. Check our FAQs or related controls for more insights. If you’re still unsure how to build your access control framework or implement RBAC, reach out — we’re happy to help.

 We are ISO 27001 Consultants who provide ‘Compliance without Complexity’® and we know we can help you… we even wrote a book about it. For more information on how to implement ISO 27001, written by ISO 27001 consultants like us, you should buy our book… “The Real Easy Guide to ISO27001”, available on Amazon.