Policy templates/Identity & Access/Version 1.0

Access Management Policy Template

Summary

Defines requirements for granting, changing, reviewing, and removing access to information systems and data. Covers identity controls, MFA, password practices, privileged accounts, service accounts, third-party access, monitoring, and lifecycle controls based on least privilege.

Purpose

To define the principles and requirements for managing access to information systems and resources, ensuring only authorized individuals have access appropriate to their role, and preventing unauthorized use or disclosure.

Scope

This policy applies to all employees, contractors, and third parties who access organizational information systems, applications, networks, and data. It covers user accounts, administrative privileges, shared credentials, and programmatic access.

Framework Mapping

Appendix A includes mappings to common security and compliance frameworks for this template.
ISO/IEC 27002:2022
5.15 Access control5.16 Identity Management5.17 Authentication Information
SOC 2 TSC
CC6.1: Logical accessCC6.2: Identity verificationCC6.3: Authentication
NIST CSF v2.0
PR.AC-1: Identities and credentials managedPR.AC-4: Access permissions enforcedPR.AC-6: Least privilege
NIST SP 800-53 Rev. 5
AC-1: Access Control PolicyAC-2: Account ManagementAC-6: Least Privilege

Complete table of contents

This preview shows the full structure of the template. Create an account or sign in to download the complete editable policy.
  1. 1. Purpose
  2. 2. Scope
  3. 3. Policy Statement
  4. 3.1 Identity and Access Controls
  5. 3.2 Password Management
  6. 3.3 Access Lifecycle Management
  7. 3.3.1 Provisioning and Modifications
  8. 3.3.2 Termination and Role Changes
  9. 3.3.3 Access Reviews
  10. 3.4 Non-Standard Access Scenarios
  11. 3.5 Third-Party and External Access
  12. 3.6 Access Monitoring and Alerting
  13. 4. Roles and Responsibilities
  14. 5. References and Related Policies
  15. 6. Definitions
  16. 7. Policy Exceptions
  17. 8. Compliance and Monitoring
  18. 9. Policy Review
  19. Appendix A: Framework Control Mapping
  20. Appendix B: Revision History
  21. Appendix C: Approvals

Download the complete access management policy template

Use the full editable template as a starting point, then adapt it to your organization.