Skip to main content

๐Ÿ’ผ A.9 Access control

  • Contextual name: ๐Ÿ’ผ A.9 Access control
  • ID: /frameworks/iso-iec-27001-2013/09
  • Located in: ๐Ÿ’ผ ISO/IEC 27001:2013

Descriptionโ€‹

Empty...

Similarโ€‹

  • Internal
    • ID: dec-b-715f53af

Sub Sectionsโ€‹

SectionSub SectionsInternal RulesPoliciesFlags
๐Ÿ’ผ A.9.1 Business requirements of access control2
ย ย ย ย ๐Ÿ’ผ A.9.1.1 Access control policy
ย ย ย ย ๐Ÿ’ผ A.9.1.2 Access to networks and network services1718
๐Ÿ’ผ A.9.2 User access management6
ย ย ย ย ๐Ÿ’ผ A.9.2.1 User registration and de-registration11
ย ย ย ย ๐Ÿ’ผ A.9.2.2 User access provisioning44
ย ย ย ย ๐Ÿ’ผ A.9.2.3 Management of privileged access rights34
ย ย ย ย ๐Ÿ’ผ A.9.2.4 Management of secret authentication information of users810
ย ย ย ย ๐Ÿ’ผ A.9.2.5 Review of user access rights11
ย ย ย ย ๐Ÿ’ผ A.9.2.6 Removal or adjustment of access rights
๐Ÿ’ผ A.9.3 User responsibilities1
ย ย ย ย ๐Ÿ’ผ A.9.3.1 Use of secret authentication information33
๐Ÿ’ผ A.9.4 System and application access control5
ย ย ย ย ๐Ÿ’ผ A.9.4.1 Information access restriction1920
ย ย ย ย ๐Ÿ’ผ A.9.4.2 Secure log-on procedures
ย ย ย ย ๐Ÿ’ผ A.9.4.3 Password management system11
ย ย ย ย ๐Ÿ’ผ A.9.4.4 Use of privileged utility programs
ย ย ย ย ๐Ÿ’ผ A.9.4.5 Access control to program source code