🛡️ Pentest from €539 · Compliance from €89. See All Services →
Optimum Web
ISO 27001NIS2SOC 2CR-ISO-05

Access Control Policy & Implementation

ISO 27001 access control policy + technical implementation. Covers A.5.15-5.18, NIS2, and SOC 2 in one engagement. Least-privilege enforced across all systems. €319.

Access Control Policy & Implementation by Optimum Web is a fixed-price compliance service covering ISO 27001 Annex A 5.15–5.18 — Access management. It costs €319 with 5–7 business days delivery by senior security engineers. Access Control Policy document (ISO 27001 aligned). 14-day warranty included.

€319
Fixed price, VAT excluded
5–7 business daysSenior only
Access Control Policy document (ISO 27001 aligned)
User provisioning and de-provisioning procedures
Quarterly access review process and template
Technical least-privilege implementation across key systems
🛡️
14-Day Warranty
If the delivered pack does not match your ISMS scope and Statement of Applicability, we rework it at no cost, or refund in full within 14 days of delivery.

Secured by PayPal · 256-bit SSL encryption

or order without payment
+373 22 843569
PayPal · SSL
👨‍💻 Senior only
14-day warranty
🆔 CR-ISO-05

This Service Covers

ISO 27001Annex A 5.15–5.18 — Information access, identity, authentication, access rights
NIS2Article 21(2)(j) — Multi-factor authentication and access control
SOC 2CC6.1 — Logical access security

What You Get

Comprehensive access control policy and technical implementation aligned to ISO 27001 Annex A 5.15-5.18. We create: Access Control Policy document (who can access what, based on business need-to-know), user provisioning and de-provisioning procedures, access review schedule and process, technical implementation of least-privilege across your systems. Includes gap assessment against ISO 27001, NIS2, and SOC 2 access control requirements.

Who Needs This

  • Companies preparing for ISO 27001 certification needing A.5.15-5.18 controls
  • Organizations with ad-hoc access management and no formal policy
  • Businesses with overly permissive access (everyone is admin) needing least-privilege
  • Companies that need access control documentation for SOC 2 or NIS2 compliance

How It Works

  1. 1
    Gap Assessment

    Audit current access management against ISO 27001 A.5.15-5.18

  2. 2
    Policy Draft

    Create Access Control Policy covering provisioning, review, and revocation

  3. 3
    Implement

    Configure least-privilege access, disable unnecessary admin accounts

  4. 4
    Review Process

    Set up quarterly access review template and schedule

SAVE 40–50%

Need Compliance Across Multiple Frameworks?

Our Multi-Framework Assessment (€639) covers GDPR + NIS2 + ISO 27001 + SOC 2 in one engagement — saving 40–50% compared to separate assessments.

Multi-Framework Assessment — €639

Ready to Start?

€319 · 5–7 business days · 14-day warranty

Secured by PayPal · 256-bit SSL encryption

or order without payment

Need a full compliance assessment? Multi-Framework Assessment — €639

Learn more

Frequently Asked Questions

Is this enough for ISO 27001 Annex A 5.15-5.18?+
Yes. The policy document and implementation evidence satisfy all four controls: A.5.15 (Access control), A.5.16 (Identity management), A.5.17 (Authentication information), A.5.18 (Access rights). Ready for Stage 2 audit.
Do you implement least-privilege or just write the policy?+
Both. We write the policy AND implement it by reconfiguring access across your key systems. No point having a policy that doesn't match reality.
What about database-level access controls?+
Yes. We configure database-level roles and permissions (PostgreSQL roles, MySQL grants) to enforce least-privilege at the data layer, not just the application layer.
How do quarterly access reviews work?+
We provide a template and process: every quarter, designated reviewers check their team's access rights, confirm or revoke as needed, and the review is documented. We can run the first review for you.
Does this satisfy NIS2 access control requirements?+
Yes. NIS2 Article 21(2)(j) requires access control and multi-factor authentication. The policy and implementation cover access control; combine with CR-NIS2-09 for MFA.

Service page last reviewed 15 August 2026 by the Optimum Web compliance team.

Secured by PayPal · 256-bit SSL encryption

or order without payment