Skip to main content

💼 5.18 Access rights

  • ID: /frameworks/iso-iec-27001-2022/05/18

Description

Access rights to information and other associated assets shall be provisioned, reviewed, modified and removed in accordance with the organization’s topic-specific policy on and rules for access control.

Similar

  • Internal
    • ID: dec-c-5909ec41

Sub Sections

SectionSub SectionsInternal RulesPoliciesFlagsCompliance

Policies (6)

PolicyLogic CountFlagsCompliance
🛡️ AWS EC2 Instance IAM role is not attached🟢1🟢 x6no data
🛡️ AWS IAM User has inline or directly attached policies🟢1🟠 x1, 🟢 x5no data
🛡️ Azure Non-RBAC Key Vault stores Keys without expiration date🟢1🟢 x6no data
🛡️ Azure Non-RBAC Key Vault stores Secrets without expiration date🟢1🟢 x6no data
🛡️ Azure RBAC Key Vault stores Keys without expiration date🟢1🟢 x6no data
🛡️ Azure RBAC Key Vault stores Secrets without expiration date🟢1🟢 x6no data

Internal Rules

RulePoliciesFlags
✉️ dec-x-0feec7902
✉️ dec-x-6c93750d1
✉️ dec-x-82ca41272
✉️ dec-x-4157c58a1