isms.coach
← All controls

A.5.15 · Organizational

Access control

Why it matters

This is the umbrella control auditors map most of your other access-related evidence back to.

How a self-led small team implements it

A written access control policy referencing least-privilege is enough — the depth comes from A.5.18 and A.8.x controls.

What auditors expect to see

Access control policy.

Track A.5.15 in your own Statement of Applicability — mark it applicable, log your justification, and link it to the risk that drove it.

Start your ISMS

More organizational controls