Does ISO/IEC 27001:2022 require Access Control?
Yes — 1 provision
Confidentiality and Access
"ISO/IEC 27001 frames confidentiality as ensuring that only the right people can access organizational information."
Requirements
| Requirement | Details |
|---|---|
| Confidential access | Ensure only the right people can access information |
| Risk management | Manage risks to information handled by the organization |
Sources: ISO/IEC 27001:2022