Policy Register

Access and identity

Who may reach what, how they prove who they are, and how the privileged few are kept few. The clauses here are the ones an auditor tests first because the evidence is in the systems.

Policy types in this family

5

What reaches this family

ISO 27001Expects: access control policy. Requires, by clause: ISO 27001 5.15, ISO 27001 5.18, ISO 27001 5.16, ISO 27001 5.17, ISO 27001 8.5, ISO 27001 8.2.
ISO 27701Expects: no document of this family on its gap list. Requires, by clause: ISO 27701 A.3.9, ISO 27701 A.3.8, ISO 27701 A.3.23.
DORAExpects: access control policy. Requires, by clause: DORA Art. 9.
NIS2Expects: access control policy, password and authentication standard. Requires, by clause: NIS2 Art. 21(2)(i), NIS2 Art. 21(2)(j).

Register the documents in this family

Paste the list; every document in this family is placed in its type, given its owner and cadence against the clauses, and the ones the regimes expect and the list does not carry are named. Eight documents free, no account.

Build a register