Castleforce IT Security Team

A.11.6 Application and information access control

Objective: To prevent unauthorized access to information held in application systems.

A.11.6.1 Information access restriction

Control

Access to information and application system functions by users and support personnel
shall be restricted in accordance with the defined access control policy.

A.11.6.2 Sensitive system isolation

Control

Sensitive systems shall have a dedicated (isolated) computing environment.

Contact Castleforce for help with ISO27001