A.5.15 A.5 · Organisational Controls

A.5.15 — Access control

Define and implement rules to control physical and logical access to information and information assets based on business and security requirements.

Also written as A5.15, Annex A 5.15, ISO 27001:2022 A.5.15, ISO27001 A.5.15.

What ISO 27001 A.5.15 requires

Access control is one of 37 Organisational Controls in ISO/IEC 27001:2022 Annex A. Define and implement rules to control physical and logical access to information and information assets based on business and security requirements. Organisational controls are judged on governance rather than tooling: an auditor wants a named owner, an approval trail, and evidence the control is exercised on a defined cadence rather than written once and filed.

Audit evidence assessors look for

When preparing your Statement of Applicability (SoA) for A.5.15, gather artefacts such as:

  • Access control policy document
  • Business justification records for access control decisions
  • Evidence of need-to-know principle enforcement
  • Access review records (periodic)

How to implement A.5.15

  1. Write the rules down before configuring anythingA.5.15 is the policy-level control; the technical enforcement lives in the A.8 series. What is tested here is whether documented rules exist that say who may access what, on what basis, and who decides. Access that is correct in the system but undocumented in principle still fails this control.
  2. Choose and state your access modelRole-based, attribute-based or a hybrid — say which, and define the roles. The common failure is an access matrix that describes the current state of Active Directory rather than an intended model, which means it can never be used to detect drift.
  3. Make need-to-know provable, not aspirationalLeast privilege is easy to assert and hard to evidence. The practical approach is to define default access for each role, require justification for anything beyond it, and keep those justifications. That turns need-to-know into a record rather than a claim.
  4. Cover physical access in the same policyA.5.15 explicitly spans physical and logical access. Organisations routinely write a logical access policy and leave physical access to facilities management, which leaves a visible gap between this control and the A.7 series.
  5. Schedule reviews with a named reviewerPeriodic access review is where this control is most often tested. Define the cadence per system criticality, name who reviews rather than saying "the system owner", and keep the sign-off including the cases where access was removed.

Common audit findings for A.5.15

What actually gets raised against A.5.15, in rough order of how often it comes up:

Scoping A.5.15

A.5.15 applies wherever there is information to protect, which is universally. It is closely coupled to A.5.16, A.5.17 and A.5.18 — auditors frequently test all four together by tracing a single joiner and a single leaver end to end, so build the evidence as one story rather than four.

How A.5.15 maps to SOC 2 and NIST CSF

If you run more than one framework, the same evidence usually satisfies all of them. A.5.15 aligns with:

SOC 2: CC6.1 Logical access security architecture, CC6.3 Role-based access and least privilege

NIST CSF 2.0: PR.AA-05 Access authorization and least privilege

ISO 27001:2013 mapping

A.5.15 consolidates the following ISO 27001:2013 control(s): A.9.1.1, A.9.1.2. If you are transitioning an existing ISMS, map your prior evidence for these to A.5.15 in your updated SoA.

Map A.5.15 to NIST CSF & SOC 2 →
Crosswalk this control in the Control Mapper & Gap Assessment.
Document the risk →
Record treatment for gaps against A.5.15 in the Risk Register.

Related Annex A controls

A.8.2 Privileged access rights A.8.3 Information access restriction A.8.4 Access to source code A.8.18 Use of privileged utility programs A.5.3 Segregation of duties A.5.18 Access rights

See all 37 Organisational Controls →

Frequently asked questions

Is ISO 27001 A.5.15 mandatory?

Annex A controls are not mandatory in the abstract. Clause 6.1.3 requires you to compare your risk treatment plan against Annex A and justify, in the Statement of Applicability, any control you exclude. If your risk assessment surfaces a risk that A.5.15 addresses, excluding it needs a documented, risk-based rationale that an auditor will test.

How do auditors test ISO 27001 A.5.15?

In two passes. First design: does a documented control exist, is it owned, and does it address the risk? Then operating effectiveness: the auditor samples records from across the audit period to confirm the control actually ran. A Stage 2 audit will typically pull several samples, so evidence that only exists for the month before the audit is a common finding.

How often should A.5.15 be reviewed?

ISO 27001 sets no fixed interval — it requires review at "planned intervals" and after significant change. Annual review is the norm most certification bodies expect, with an out-of-cycle review triggered by incidents, major system changes, restructures, or new regulatory obligations. Record the review date and outcome either way; an undated control is treated as unreviewed.

What does ISO 27001 A.5.15 map to in SOC 2 and NIST CSF?

A.5.15 aligns with SOC 2 CC6.1, CC6.3 and NIST CSF PR.AA-05. Evidence gathered for one framework will usually satisfy the others, which is the basis for a test-once, satisfy-many control library.

What was A.5.15 in ISO 27001:2013?

A.5.15 consolidates 2 control(s) from the 2013 edition: A.9.1.1, A.9.1.2. When transitioning, re-point the existing evidence rather than rebuilding it — the underlying requirement has not changed materially.

What are the most common audit findings for A.5.15?

An access control policy that documents current state rather than intended rules, so nothing can ever be found non-compliant against it. Access reviews performed but with no evidence of anything being revoked, which suggests a rubber-stamp exercise.