ISO 27001 Annex : A.9.4 System and Application Access Control
ISO 27001 Annex : A.9.4 System and Application Access Control Its objective is to put a stop to unauthorized access to systems and applications. A.9.4.1 Information Access Restriction Control- Access to information and application system functions should be limited in compliance with the policy on access control. Implementation Guidance- Access controls should be based on individual requirements for business applications and in compliance with a specified access control policy. In order to meet access restriction criteria, the following should be considered:- Provide menus for controlling access to application system functions; Controlling which data a particular user can access; Control user access permission, e.g. read, write, delete, and execute; Control of the access permission to other applications; Restrict the information contained in the outputs; Physical or logical access controls for sensitive applications, applicat...