You're exploring a read-only demo — nothing you click is saved. Back to site →
Sample workspace
Sign in
← Policies
ISO 27001

Access Control Policy

Export DOCX / PDF

Access Control Policy

Northwind Logistics GmbH · ISO/IEC 27001

1. Principles

Access to information and systems is granted on a need-to-know and least-privilege basis, aligned to business and security requirements.

2. Identity and provisioning

Each user has a unique identity. Access is provisioned only on documented approval and removed promptly on change of role or termination.

3. Authentication

Strong authentication is enforced. Multi-factor authentication is required for remote access and all administrative and high-risk systems.

4. Privileged access

Privileged access rights are restricted, individually assigned, and logged. Privileged activity is reviewed regularly.

5. Access reviews

Access rights are reviewed at least quarterly and after major organisational changes.