Does ISO 27001 require Access Control?
Yes — 1 provision
Information Security Controls (Annex A)
"ISO 27001:2022 restructured Annex A controls into **4 themes** (organizational, people, physical, technological) with **93 controls** replacing the previous 114."
Requirements
| Requirement | Details |
|---|---|
| Access control policy | Define and enforce access control rules |
| User access management | Formal registration and de-registration |
Sources: ISO 27001:2022