Skip to main content

πŸ’Ό 8.3 Information access restriction

  • Contextual name: πŸ’Ό 8.3 Information access restriction
  • ID: /frameworks/iso-iec-27001-2022/08/03
  • Located in: πŸ’Ό 8 Technological controls

Description​

Access to information and other associated assets shall be restricted in accordance with the established topic-specific policy on access control.

Similar​

  • Internal
    • ID: dec-c-07571b43

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags

Policies (11)​

PolicyLogic CountFlags
πŸ“ AWS Account Root User has active access keys 🟒1🟒 x6
πŸ“ AWS EC2 Instance IAM role is not attached 🟒1🟒 x6
πŸ“ AWS IAM User has inline or directly attached policies 🟒1🟠 x1, 🟒 x5
πŸ“ AWS IAM User with console and programmatic access set during the initial creation 🟒🟒 x3
πŸ“ AWS RDS Instance is publicly accessible and in an unrestricted public subnet 🟒1🟒 x6
πŸ“ AWS S3 Bucket is not configured to block public access 🟒1🟒 x6
πŸ“ AWS S3 Bucket MFA Delete is not enabled 🟠🟒1🟠 x1, 🟒 x6
πŸ“ Azure App Service Authentication is disabled and Basic Authentication is enabled 🟒1🟒 x6
πŸ“ Azure App Service Basic Authentication is enabled 🟒🟒 x3
πŸ“ Azure SQL Database allows ingress from 0.0.0.0/0 (ANY IP) 🟒1🟒 x6
πŸ“ Azure Storage Account Trusted Azure Services are not enabled as networking exceptions 🟒1🟒 x6

Internal Rules​

RulePoliciesFlags
βœ‰οΈ dec-x-0a7801fb1
βœ‰οΈ dec-x-6c93750d1
βœ‰οΈ dec-x-0289e9c91
βœ‰οΈ dec-x-3179d53c1
βœ‰οΈ dec-x-4157c58a1
βœ‰οΈ dec-x-b10e98af1
βœ‰οΈ dec-x-ca52f63a2
βœ‰οΈ dec-x-ec547a7c1
βœ‰οΈ dec-x-f937c35f1
βœ‰οΈ dec-z-bb7312921