Policy Statement
The Company is committed to ensuring that access to its information systems, applications, and data is granted only to authorized individuals in accordance with defined business and security requirements. This Access Control Policy defines the framework for managing user access rights to maintain the confidentiality, integrity, and availability of information assets.
Objectives
- Define the principles and procedures for granting, reviewing, and revoking access to information systems.
- Prevent unauthorized access, misuse, or disclosure of sensitive information.
- Establish accountability and auditability of all access-related activities.
- Ensure compliance with ISO/IEC 27001, GDPR, and DPDP Act requirements.
Scope and Applicability
This policy applies to all employees, contractors, vendors, and third parties who require access to the Company's systems, applications, or data. It covers physical, logical, and remote access across all technology platforms managed by the Company.
Turn this template into a living policy
Book a 20-minute demo to see how PolicyCentral.ai distributes, translates, and tracks acknowledgement of policies like this across your entire workforce.
Book a DemoAccess Control Principles
- Need-to-Know: Access shall be granted only when required for legitimate business purposes.
- Least Privilege: Users shall be provided with the minimum level of access necessary to perform their duties.
- Segregation of Duties: Conflicting responsibilities shall be separated to prevent unauthorized or fraudulent activities.
- Accountability: Each user is responsible for activities performed under their credentials.
- Timely Revocation: Access rights shall be promptly removed when no longer required.
User Account Management
The creation, modification, and deletion of user accounts shall follow a controlled approval process.
- New user access must be requested and approved by the relevant Department Head and IT Security Team.
- Access privileges shall be documented and reviewed periodically.
- User accounts must be unique and not shared between individuals.
- Dormant or inactive accounts shall be disabled after 90 days of inactivity.
- Access for employees leaving the organization must be revoked within 24 hours of separation.
Authentication Controls
- All systems must use strong passwords or passphrases that meet the Company's password policy requirements.
- Multi-Factor Authentication (MFA) shall be enabled for access to critical systems and cloud services.
- Default vendor or system passwords must be changed immediately upon installation.
- Passwords must not be shared, written down, or stored in unsecured formats.
Privileged Access Management
Access to administrative or privileged accounts must be strictly controlled and monitored to prevent misuse.
- Privileged accounts shall be used only for administrative purposes.
- Use of shared or generic administrator accounts is prohibited.
- All privileged account activities must be logged and regularly reviewed.
- Privileged accounts shall undergo quarterly access reviews by the IT Security Team.
Physical Access Control
- Access to offices, server rooms, and data centers must be restricted to authorized personnel only.
- Identification badges or biometric verification shall be used for entry control.
- Visitors must be registered, accompanied, and monitored at all times.
- Physical access logs shall be maintained for audit purposes.
Remote Access Control
- Remote connections must be established only through secure VPNs with encryption enabled.
- Personal or unapproved devices shall not be used to access Company systems.
- Remote sessions must be automatically disconnected after a period of inactivity.
- Access to critical systems remotely must require MFA and compliance with device security standards.
Access Review and Audit
Regular access reviews shall be conducted to ensure compliance with this policy. Department Heads and the IT Security Team must jointly review user access rights at least quarterly.
All access-related activities shall be logged, monitored, and retained for a minimum of one year for audit and investigation purposes.
Third-Party and Vendor Access
Third-party vendors requiring access to Company systems must sign confidentiality and data protection agreements. Their access shall be restricted to specific systems, time-bound, and monitored for compliance.
Policy Enforcement and Violations
Failure to comply with this policy may result in disciplinary action, suspension of system access, or termination of employment. Severe violations may also lead to legal or regulatory penalties.
Policy Review
This policy shall be reviewed annually or whenever there is a significant change in the Company's IT infrastructure, regulatory obligations, or security risks. All updates must be approved by the Board of Directors and communicated to employees.
Employee Acknowledgment
I acknowledge that I have read and understood the Access Control Policy of the Company I agree to comply with the principles and responsibilities outlined in this policy to ensure secure management of Company systems and data.
Employee Name: __________________________
Signature: ______________________________
Date: _________________________________
Browse all policy categories
Frequently asked questions
Who does this policy apply to?
This policy applies to all employees, contractors, vendors, and third parties who require access to the Company's systems, applications, or data. It covers physical, logical, and remote access across all technology platforms managed by the Company.
How often is this policy reviewed?
Regular access reviews shall be conducted to ensure compliance with this policy. Department Heads and the IT Security Team must jointly review user access rights at least quarterly. All access-related activities shall be logged, monitored, and retained for a minimum of one year for audit and investigation purposes.