Skip to content

Access Control

What is Access Control?

Security measures that regulate who can view or use resources in a computing environment. Access controls include authentication, authorisation, and audit mechanisms.

Information Security

What the standards actually require on access control

Requirements naming access control across 6 standards, quoted from the control text.

Security Dimension 1 Access Control per X.805 Clause 6.1: Access Control protects against unauthorized use of network resources. Access Control ensures that only authorized personnel or devices are allowed access to network elements + stored information + info...

X805-Dim1-Access-Control-RBAC-Authorization-Resources-Network-Elements-Services-Applications · ITU-T X.805 Security Dimension 1 - Access Control + Role-Based Access Control (RBAC) + Authorization + Resources + Network Elements + Services + Applications + Access Limitations + Authorized Personnel + Discretionary + Mandatory Access Control

Certificates are protected by logical and physical access controls, encryption, and user authentication.

ISM-1327 · Certificates are protected by logical and physical access controls, encryption, and user a

Access Control Decisions. [organization-defined] to ensure [organization-defined] are applied to each access request prior to access enforcement

NIST800-AC-24 · Access Control Decisions. [organization-defined] to ensure [organization-defined] are applied to each access request prior to access enforcement
PCI DSS 4.07 controls

Pre-production environments are separated from production environments and the separation is enforced with access controls

pci-dss-4-0::6.5.3 · Pre-production environments are separated from production environments and the separation is enforced with access controls

Remote access controls. Control from BSI IT-Grundschutz framework, domain: BSI IT-Grundschutz: Access Control & Identity.

BSI-04 · Remote access controls
FedRAMP High6 controls

Route remote accesses through FedRAMP-defined number of managed network access control points.

AC-17(3) · Managed Access Control Points

Questions people ask about access control

What is Access Control?
Security measures that regulate who can view or use resources in a computing environment. Access controls include authentication, authorisation, and audit mechanisms.
Why is Access Control important for compliance?
Access Control is a key concept in Information Security. Understanding access control helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
What concepts are related to Access Control?
Key concepts related to Access Control include Authentication, Authorisation, RBAC (Role-Based Access Control). Understanding these interconnected concepts provides a more comprehensive view of Information Security requirements and helps organizations build holistic compliance programs.
Which compliance frameworks address Access Control?
Access Control appears in the requirement text of ITU-T X.805 - Security Architecture for End-to-End Communications, Australian Information Security Manual, NIST SP 800-53 Rev 5, PCI DSS 4.0, BSI IT-Grundschutz. Across these standards we have identified 46 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Access Control?
Explore our compliance framework pages to see how access control applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Access Control applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.