Skip to content

Authorisation

What is Authorisation?

The process of determining what actions an authenticated user or system is permitted to perform. Typically enforced through access control lists or role-based access control.

Information Security

What the standards actually require on authorisation

Requirements naming authorisation across 6 standards, quoted from the control text.

Authentication and authorisation is used for all actions on a video conferencing network, including call setup and changing settings.

ISM-0553 · Authentication and authorisation is used for all actions on a video conferencing network,

Article 5(3) requires PSD2 authorisation applications to include a description of the PI's internal-control mechanisms for AML/CFT in accordance with the 4th + now 5th + 6th Anti-Money-Laundering Directives and Regulation (EU) 2015/847 on information accompany...

PSD2-Art.5_19_22 · Money-laundering / CFT and AML controls in payment institution authorisation + agents

Article 16 requires authorisation by the home Member State competent authority before any offer to the public or admission to trading of an ART (or before the issuer is established in the Union).

MiCA-Art.16_17_18_19_20_21 · ART authorisation - application + assessment + grant/refusal (Articles 16-21)

Economic operators may apply for AEO Customs Simplifications, AEO Security and Safety, or combined status, demonstrating compliance with customs legislation, satisfactory records management, financial solvency and appropriate security standards.

EU-UCC-02 · Authorised Economic Operator (AEO) Authorisation

Processing operations must be notified to the Data Protection Agency (APD); certain categories require prior authorisation.

AO-PDPL-5 · APD Notification and Authorisation
C5 (Germany)5 controls

Restrict service functions behind authorisation checks confirming that a user, IT component or application may perform the action, validate those checks before releasing new functions or changing existing ones, rate defects against an industry metric, remediat...

C5-PSS-09 · Authorisation Mechanisms

Questions people ask about authorisation

What is Authorisation?
The process of determining what actions an authenticated user or system is permitted to perform. Typically enforced through access control lists or role-based access control.
Why is Authorisation important for compliance?
Authorisation is a key concept in Information Security. Understanding authorisation helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
What concepts are related to Authorisation?
Key concepts related to Authorisation include Authentication, RBAC (Role-Based Access Control), Least Privilege. Understanding these interconnected concepts provides a more comprehensive view of Information Security requirements and helps organizations build holistic compliance programs.
Which compliance frameworks address Authorisation?
Authorisation appears in the requirement text of Australian Information Security Manual, EU Payment Services Directive (PSD2), EU Markets in Crypto-Assets Regulation (MiCA), Union Customs Code (UCC) - Regulation (EU) No 952/2013, Angola Personal Data Protection Law (Law No. 22/11). Across these standards we have identified 39 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Authorisation?
Explore our compliance framework pages to see how authorisation applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Authorisation applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.