Skip to main content
Joinly by KoppelHet

ISO 27001

ISO 27001 and access control: the controls that come up at your clients

Access control always comes up in an ISO 27001 audit. The standard asks for a policy, and it also asks you to show that the policy is carried out. If you are the MSP doing the management, that question lands with you.

The short answer

ISO 27001 covers access control in Annex A in, among others, controls 5.15 (Access control), 5.16 (Identity management), 5.17 (Authentication information) and 5.18 (Access rights), and in 6.5 on responsibilities after termination or change of employment. An auditor wants to see that access is granted as agreed, reviewed periodically and revoked when someone leaves. Joinly carries that out per client from HR and records every step in the audit log.

Which controls cover access

In the 2022 version, the controls for access sit mainly in section 5 of Annex A. Access control is about the rules: who gets access to what. Identity management covers the whole lifecycle of an identity. Authentication information is about how login details are issued and managed. Access rights covers granting, reviewing and revoking.

On top of that, control 6.5 asks that responsibilities and access are adjusted when someone leaves or changes role, and 8.15 asks you to record what happens.

What an auditor wants to see

A policy document is the start. After that, an auditor wants evidence that the policy is carried out: that a new employee got the access that fits their role, that someone who changed role lost their old access, that a leaver could no longer get in anywhere on their last day, and that access rights were reviewed periodically.

If that is spread across tickets and loose scripts, the evidence is hard to provide. Especially across several clients.

How Joinly records the work

With Joinly, your client's HR system is the source. Roles based on job title, department and location decide who gets what. Joiners, movers and leavers run automatically, the access review shows per person where their access differs from what fits their role, and every change goes into that client's audit log, with who, what, when and why.

De toegangsevaluatie in Joinly: feitelijke naast bedoelde toegang

For your clients, and for yourself

Joinly is ISO 27001 certified itself, and the data is stored in Amsterdam, within the EU. For your own certification or your client's, that makes Joinly a supplier you can account for in your supplier assessment. You will find the documents for it in the Trust Centre.

The controls and what Joinly does

The controls from Annex A of ISO 27001:2022 that cover access.

5.15 Access control
What it is about: Rules for who gets access to what
With Joinly: Roles based on job title, department and location
5.16 Identity management
What it is about: The whole lifecycle of an identity
With Joinly: Joiners, movers and leavers from HR
5.17 Authentication information
What it is about: Issuing and managing login details securely
With Joinly: A Temporary Access Pass for the first sign-in, resetting MFA
5.18 Access rights
What it is about: Granting, reviewing and revoking
With Joinly: Access review, revoking access when someone leaves
6.5 Responsibilities after termination or change of employment
What it is about: Adjusting access when someone leaves or changes role
With Joinly: Automatically, based on HR
8.15 Logging
What it is about: Recording what happens
With Joinly: Audit log with source and reason

ISO 27001

Frequently asked questions

  • Which ISO 27001 controls cover access control?

    In ISO 27001:2022 mainly 5.15 (Access control), 5.16 (Identity management), 5.17 (Authentication information) and 5.18 (Access rights), plus 6.5 on leavers and role changes and 8.15 on logging.

  • Does Joinly make an organisation ISO 27001 certified?

    No. Certification covers the whole management system. Joinly helps with carrying out the access controls and with the evidence for them.

  • What does an auditor want to see for access control?

    A policy, and evidence that it is carried out: access as agreed when someone joins, adjusted when they change role, revoked when they leave and reviewed periodically.

  • Is Joinly ISO 27001 certified itself?

    Yes. The data is stored in Amsterdam, within the EU. You will find the certificate and the other documents through the Trust Centre.

  • Does this also help with NEN 7510 and the BIO?

    NEN 7510 and the BIO are based on ISO 27001 and ISO 27002, so the access controls come back in them in a similar way.

Account management for your clients as a standard service?

In an introduction we walk through how Joinly would work for your clients: which HR systems, which environments and where you want to start. We agree the terms of a partnership in the same conversation.

Book an introduction