All data is fictional

A.5.15 — Access Control

Implemented ISO 27001:2022 Organisational
Control Information
A.5.15
ISO 27001:2022
Organisational
Implemented
Access Control
Rules to control physical and logical access to information and other associated assets shall be established and implemented based on business and information security requirements.
RBAC implemented across all major systems. Quarterly access reviews conducted. Privileged access managed via PAM solution.
4 / 5 — Managed
15 Jan 2026
15 Jul 2026
Semi-Annual
IT Operations
Control Effectiveness
85% Effective
50% Maturity + 30% Evidence + 20% Test Recency

Maturity (50%)80%
Evidence (30%)93%
Test Recency (20%)83%