Skip to content

Access Policy

What is Access Policy?

A documented set of rules defining who is authorized to access specific resources, under what conditions, and with what level of permission.

Information Security

Each of these is named in at least one of the same controls as access policy. The number is how many controls name both.

What the standards actually require on access policy

Requirements naming access policy across 4 standards, quoted from the control text.

Maintain a written policy addressing how the organisation manages security and access to the My Health Record system, covering the matters required by the My Health Records Rule.

MYHR-SEC-1 · Written security and access policy

Automate application access policy, testing, and deployment workflows across the applications pillar.

ZTMM-APP-AO · Applications Pillar: Automation and Orchestration

Security Layer 2 Services per X.805 Clause 7.2: The Services Security Layer is concerned with security of network services that service providers offer to their customers - encompasses the protection of the basic network connectivity services + supplementary v...

X805-Layer2-Services-Security-Frame-Relay-ATM-IP-VoIP-QoS-Toll-Free-IM-VPN-AAA-DNS · ITU-T X.805 Security Layer 2 - Services Security + Frame Relay + ATM + IP + VoIP + QoS + Toll-Free + Instant Messaging + VPN + AAA Authentication-Authorization-Accounting + DNS + IMS + 5G + Cellular Mobile Voice + SMS

Design and operate OT network architecture per NIST SP 800-82 Rev 3 Chapter 6 (OT Security Architecture). Apply the Purdue Enterprise Reference Architecture as the foundational structure: Level 0 Physical Process + Level 1 Basic Control + Level 2 Area Supervis...

NISTSP82-3 · OT Network Architecture: Zoned Architecture, Conduits, Segmentation, and Defence-in-Depth

Questions people ask about access policy

What is Access Policy?
A documented set of rules defining who is authorized to access specific resources, under what conditions, and with what level of permission.
Why is Access Policy important for compliance?
Access Policy is a key concept in Information Security. Understanding access policy helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Access Policy?
Access Policy appears in the requirement text of Australia My Health Records Act 2012, CISA Zero Trust Maturity Model, ITU-T X.805 - Security Architecture for End-to-End Communications, NIST SP 800-82 Revision 3: Guide to Industrial Control Systems (ICS) Security. Across these standards we have identified 4 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Access Policy?
Explore our compliance framework pages to see how access policy applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Access Policy applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.