Skip to main content

What are the ISO standards for access security?

The ISO standards applicable to access security primarily fall under the ISO 27000 series, with ISO 27001 and ISO 27002 being the most relevant standards. ISO 27001 sets requirements for an Information Security Management System (ISMS) and contains specific controls for access management, while ISO 27002 provides practical guidelines for their implementation. If you have questions about what this means for your organization, please feel free to contact with Sellox. In this article, we answer the most frequently asked questions about ISO standards and access security.

Which ISO standards specifically apply to access security?

The most relevant ISO standards for access security are ISO 27001 and ISO 27002. ISO 27001 is the certifiable standard that sets requirements for information security as a whole, including access control. ISO 27002 provides additional implementation guidelines. Additionally, ISO 27001 is relevant when access control overlaps with privacy protection and personal data.

In addition to the ISO 27000 series, there is also IEC 62443 a role in specific sectors, particularly in industrial environments and operational technology where physical and digital access security converge. Furthermore, for organizations working with certified access control systems, product-specific standards apply, such as EN 60839 for electronic access control systems.

It is important to understand that ISO standards for access security cover both logical access (digital systems, networks, applications) and physical access (buildings, server rooms, secure zones). Both dimensions are inextricably linked within a well-designed security system.

What does ISO 27001 prescribe regarding access control?

ISO 27001 stipulates that organizations must adopt a systematic policy for access control, based on the principle of minimum access rights. This means that employees and systems are granted access only to the information and resources they need for their function. The standard requires that access rights be granted, managed, monitored, and revoked based on documented procedures.

Within ISO 27001, access control falls under Annex A, which describes a series of security measures. The relevant controls relate to:

  • Establishing and documenting an access policy
  • Registration and management of user accounts and access rights
  • Use of strong authentication methods, including multi-factor authentication
  • Periodic check and review of access rights
  • Limitation of administrator rights and privileged access
  • Logging and monitoring of access attempts

ISO 27001 does not prescribe exactly how an organization should implement this technically, but it does state that the chosen measures must be demonstrably effective. This gives organizations the freedom to choose solutions that suit their specific situation, as long as they can demonstrate that risks are adequately managed.

What is the difference between ISO 27001 and ISO 27002 for access security?

The core difference is that ISO 27001 sets the requirements an organization must meet to become certified, whereas ISO 27002 provides practical implementation guidelines. For access security, this means that ISO 27001 stipulates that an access policy must exist, and ISO 27002 explains what that policy might look like in terms of content.

ISO 27001: the standard with requirements

ISO 27001 is the auditable and certifiable standard. An external certification body assesses whether the organization meets the set requirements, including the controls in Annex A relating to access management. The standard is binding for organizations wishing to obtain an ISO 27001 certificate.

ISO 27002: the standard with guidelines

ISO 27002 is not a certifiable standard, but a detailed manual. For each of the controls in ISO 27001, ISO 27002 provides explanations, examples, and recommendations for implementation. Regarding access security, ISO 27002 offers concrete guidance on matters such as password policies, role-based access control, and the management of external users. Organizations use ISO 27002 as a frame of reference when designing and improving their security measures.

How does physical access security relate to ISO standards?

Physical access security is an integral part of ISO 27001 and is explicitly addressed in the controls regarding physical and environmental security. The standard requires organizations to take measures to prevent unauthorized physical access to sensitive areas, equipment, and information. Examples include access control in server rooms, secure zones, and workstations containing confidential information.

Concrete measures that ISO 27001 expects regarding physical access include:

  • Defining secure zones with clear access restrictions
  • Use of access control systems such as cards, PIN codes, or biometrics
  • Visitor registration and guidance in secure areas
  • Protection of equipment against unauthorized access or theft
  • Procedures for the management of keys and access means

Physical and logical access security are considered complementary in ISO standards. A strong digital access policy is of little value if unauthorized persons can physically access servers or workstations. The standard therefore encourages organizations to assess and secure both aspects in conjunction.

How does an organization obtain ISO certification for access security?

An organization obtains ISO 27001 certification by establishing, implementing, and having a complete Information Security Management System (ISMS) audited by an accredited certification body. Access control is one of the mandatory areas of focus, but the certification covers the organization's entire information security.

The certification process proceeds broadly in the following steps:

  1. Define scope: The organization determines which systems, processes, and locations fall under the ISMS.
  2. Conduct a risk analysis: Risks related to information security, including access risks, are identified and assessed.
  3. Implement measures: Based on the risk analysis, appropriate controls are implemented, such as access policies, authentication systems, and log management.
  4. Internal audit: The organization itself verifies whether the ISMS functions correctly and is documented.
  5. External audit (phase 1): A certifying body assesses the documentation and the policy.
  6. External audit (phase 2): The actual implementation and functioning of the measures are tested in practice.
  7. Certificate issuance: Upon a positive assessment, the organization receives the ISO 27001 certificate, valid for three years with annual surveillance audits.

Proper preparation requires time and effort from the entire organization. Access control plays a central role in this, as it intersects with virtually every other aspect of information security. Would you like to know how Sellox can support your organization in establishing solid access security? Contact us and we are happy to think along with you.

Frequently Asked Questions

Does every organization need to be ISO 27001 certified to comply with legal requirements regarding access security?

No, ISO 27001 certification is not legally mandatory in most cases, but it may be indirectly required by customers, partners, or sector-specific regulations such as NIS2 or GDPR. Organizations can also meet legal requirements without a certificate by using the guidelines of ISO 27001 and ISO 27002 as a frame of reference. However, certification offers a demonstrable advantage: it gives external parties confidence that information security, including access control, is set up at a professional level.

How long does it take on average for a medium-sized organization to obtain ISO 27001 certification?

For a medium-sized organization, the certification process typically takes between six months and two years, depending on the current maturity of information security, the size of the scope, and the available internal capacity. Organizations that already have a robust access policy and associated procedures can significantly shorten this process. A phased approach, in which the most critical controls, such as access management, are established first, helps keep the process manageable.

What are the most common mistakes organizations make when setting up access control according to ISO 27001?

A common mistake is the inconsistent application of the principle of minimum access rights: employees are granted more rights than they need, often out of convenience or because rights are never reviewed following a job change. Other common errors include the lack of periodic access reviews, insufficient logging of access attempts, and the failure to revoke access rights in a timely manner upon termination of employment. A structured and documented process for granting, reviewing, and revoking access rights is essential to avoid these pitfalls.

How do we handle access rights for external employees, suppliers, or freelancers within an ISO 27001 framework?

ISO 27001 requires that access rights for external parties be managed with the same care as those of internal employees, but with extra attention to the temporality and limitation of that access. In practice, this means creating separate accounts for external users, restricting access to only the systems and data necessary for the assignment, and linking a clear end date or deactivation moment to that access. Contractual agreements regarding information security, such as a data processing agreement or confidentiality clause, constitute an additional requirement within the ISMS.

Is biometric access control fully compliant with ISO standards and the GDPR?

Technically, biometric access control is fully applicable within an ISO 27001 framework and is even considered a strong authentication method. However, because biometric data is classified as special personal data under the GDPR, additional legal requirements apply to its processing, such as an explicit legal basis and a Data Protection Impact Assessment (DPIA). Organizations deploying biometrics would be wise to also consult ISO 27701, which focuses specifically on privacy management as an extension to ISO 27001.

What happens if an external audit reveals that our access management is not in order?

If an auditor identifies shortcomings in access control, these are classified as a 'non-conformity', which can range from a minor deviation to a major finding. In the case of a minor non-conformity, the organization is given the opportunity to implement improvements within an agreed timeframe without the certification being immediately jeopardized. A major non-conformity, such as the complete absence of an access policy or access reviews, may lead to the certification being postponed or revoked until the problem is demonstrably resolved.

How do we keep our access policy up to date after obtaining ISO 27001 certification?

Following certification, annual surveillance audits are mandatory, which means that the access policy must remain continuously up-to-date and demonstrably effective. In practice, this entails conducting periodic access reviews (at least annually or with every change of role), adjusting the policy in response to organizational changes or new technologies, and always documenting changes. Embedding access management into regular HR and IT processes, such as onboarding and offboarding, ensures that the policy is alive within the organization and does not merely exist on paper.