Skip to main content

💼 7.2.1 An access control model is defined and includes granting appropriate access.

Description​

As follows:

  • Appropriate access depending on the entity's business and access needs.
  • Access to system components and data resources that is based on users' job classification and functions.
  • The least privileges required (for example, user, administrator) to perform a job function.

Similar​

  • Sections
    • /frameworks/pci-dss-v3.2.1/07/01/01
    • /frameworks/pci-dss-v4.0.1/07/02/01
  • Internal
    • ID: dec-c-8b362850

Similar Sections (Take Policies From)​

SectionSub SectionsInternal RulesPoliciesFlags
💼 PCI DSS v3.2.1 → 💼 7.1.1 Define access needs for each role.
💼 PCI DSS v4.0.1 → 💼 7.2.1 An access control model is defined and includes granting appropriate access.

Similar Sections (Give Policies To)​

SectionSub SectionsInternal RulesPoliciesFlags
💼 PCI DSS v3.2.1 → 💼 7.1.1 Define access needs for each role.
💼 PCI DSS v4.0.1 → 💼 7.2.1 An access control model is defined and includes granting appropriate access.

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags