ISO 27001
ISO 27001 and access control: the controls that come up at your clients
Access control always comes up in an ISO 27001 audit. The standard asks for a policy, and it also asks you to show that the policy is carried out. If you are the MSP doing the management, that question lands with you.
The short answer
ISO 27001 covers access control in Annex A in, among others, controls 5.15 (Access control), 5.16 (Identity management), 5.17 (Authentication information) and 5.18 (Access rights), and in 6.5 on responsibilities after termination or change of employment. An auditor wants to see that access is granted as agreed, reviewed periodically and revoked when someone leaves. Joinly carries that out per client from HR and records every step in the audit log.
Which controls cover access
In the 2022 version, the controls for access sit mainly in section 5 of Annex A. Access control is about the rules: who gets access to what. Identity management covers the whole lifecycle of an identity. Authentication information is about how login details are issued and managed. Access rights covers granting, reviewing and revoking.
On top of that, control 6.5 asks that responsibilities and access are adjusted when someone leaves or changes role, and 8.15 asks you to record what happens.
What an auditor wants to see
A policy document is the start. After that, an auditor wants evidence that the policy is carried out: that a new employee got the access that fits their role, that someone who changed role lost their old access, that a leaver could no longer get in anywhere on their last day, and that access rights were reviewed periodically.
If that is spread across tickets and loose scripts, the evidence is hard to provide. Especially across several clients.
How Joinly records the work
With Joinly, your client's HR system is the source. Roles based on job title, department and location decide who gets what. Joiners, movers and leavers run automatically, the access review shows per person where their access differs from what fits their role, and every change goes into that client's audit log, with who, what, when and why.

For your clients, and for yourself
Joinly is ISO 27001 certified itself, and the data is stored in Amsterdam, within the EU. For your own certification or your client's, that makes Joinly a supplier you can account for in your supplier assessment. You will find the documents for it in the Trust Centre.
The controls and what Joinly does
The controls from Annex A of ISO 27001:2022 that cover access.
Control
What it is about
With Joinly
- 5.15 Access control
- What it is about: Rules for who gets access to what
- With Joinly: Roles based on job title, department and location
- 5.16 Identity management
- What it is about: The whole lifecycle of an identity
- With Joinly: Joiners, movers and leavers from HR
- 5.17 Authentication information
- What it is about: Issuing and managing login details securely
- With Joinly: A Temporary Access Pass for the first sign-in, resetting MFA
- 5.18 Access rights
- What it is about: Granting, reviewing and revoking
- With Joinly: Access review, revoking access when someone leaves
- 6.5 Responsibilities after termination or change of employment
- What it is about: Adjusting access when someone leaves or changes role
- With Joinly: Automatically, based on HR
- 8.15 Logging
- What it is about: Recording what happens
- With Joinly: Audit log with source and reason
ISO 27001
Frequently asked questions
Which ISO 27001 controls cover access control?
In ISO 27001:2022 mainly 5.15 (Access control), 5.16 (Identity management), 5.17 (Authentication information) and 5.18 (Access rights), plus 6.5 on leavers and role changes and 8.15 on logging.
Does Joinly make an organisation ISO 27001 certified?
No. Certification covers the whole management system. Joinly helps with carrying out the access controls and with the evidence for them.
What does an auditor want to see for access control?
A policy, and evidence that it is carried out: access as agreed when someone joins, adjusted when they change role, revoked when they leave and reviewed periodically.
Is Joinly ISO 27001 certified itself?
Yes. The data is stored in Amsterdam, within the EU. You will find the certificate and the other documents through the Trust Centre.
Does this also help with NEN 7510 and the BIO?
NEN 7510 and the BIO are based on ISO 27001 and ISO 27002, so the access controls come back in them in a similar way.
- Joinly for MSPsFor an MSP, every joiner and leaver at a client is a ticket, a checklist and work that is hard to bill for. Joinly picks up those changes from your client's HR system and handles accounts, groups, licences and access automatically. For all your clients, from one login, with each client in its own environment.
- NIS2 for MSPsWith the Cyberbeveiligingswet, the Dutch implementation of NIS2, the directive reaches an MSP in two ways: as an obligation of your own, and through your clients' questionnaires. Access management is in both. This is how you deliver the answer per client, without piecing it together again every time.
- User access review per clientThe classic access review is an export sent round to managers who do not recognise the group names. What comes back is a column of ticks. With Joinly you review per client what is actually set up, next to what was intended, and for every difference you see where it comes from.
- Access control matrix per clientAlmost every organisation has an access control matrix somewhere: a spreadsheet with job roles in the rows and systems in the columns. And almost everywhere it lags behind what is actually set up. With Joinly the matrix becomes the place access comes from, so it never lags behind again.
Account management for your clients as a standard service?
In an introduction we walk through how Joinly would work for your clients: which HR systems, which environments and where you want to start. We agree the terms of a partnership in the same conversation.
Book an introduction