ISO 27001 8.3 Information Access Restriction Requirement:
"Access to information and other associated assets shall be restricted in accordance with the established topic-specific policy on access control."[1]
ISO 27001 8.3 Information Access Restriction Requirement Explanation:
When assigning access to information and system resources users should only be granted access to data they have a need to know for. This involves limiting access to resources such as SharePoint sites and file shares.
References:
Quick & Simple
Discover Our Cybersecurity Compliance Solutions:
Whether you need to meet and maintain your compliance requirements, help your clients meet them, or verify supplier compliance we have the expertise and solution for you