Skip to main content

πŸ’Ό 5.18 Access rights

  • Contextual name: πŸ’Ό 5.18 Access rights
  • ID: /frameworks/iso-iec-27001-2022/05/18
  • Located in: πŸ’Ό 5 Organizational controls

Description​

Access rights to information and other associated assets shall be provisioned, reviewed, modified and removed in accordance with the organization’s topic-specific policy on and rules for access control.

Similar​

  • Internal
    • ID: dec-c-5909ec41

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags

Policies (6)​

PolicyLogic CountFlags
πŸ“ AWS EC2 Instance IAM role is not attached 🟒1🟒 x6
πŸ“ AWS IAM User has inline or directly attached policies 🟒1🟠 x1, 🟒 x5
πŸ“ Azure Non-RBAC Key Vault stores Keys without expiration date 🟒1🟒 x6
πŸ“ Azure Non-RBAC Key Vault stores Secrets without expiration date 🟒1🟒 x6
πŸ“ Azure RBAC Key Vault stores Keys without expiration date 🟒1🟒 x6
πŸ“ Azure RBAC Key Vault stores Secrets without expiration date 🟒1🟒 x6

Internal Rules​

RulePoliciesFlags
βœ‰οΈ dec-x-0feec7902
βœ‰οΈ dec-x-6c93750d1
βœ‰οΈ dec-x-82ca41272
βœ‰οΈ dec-x-4157c58a1