Approval group
Access and systems
The system lines of the matrix: who grants privileged access, who signs off the access review, who approves a change to production and who may change the approval workflow itself.
The approval families
4| Family and a line that matches it | Marked | Clauses |
|---|---|---|
| Privileged system access grantsPrivileged system access grant: IT Manager | high-risk | ISO/IEC 27001 8.2 · ISO/IEC 27001 5.15 |
| User access review sign-offUser access review sign-off: IT Manager | ISO/IEC 27001 5.18 · ISO/IEC 27001 5.15 | |
| Changes to production systemsChanges to production: IT Manager | high-risk | ISO/IEC 27001 8.32 · COSO P11 |
| Changes to approval workflows and limits in the systemChanges to approval workflows in the ERP: IT Director | ISO/IEC 27001 8.32 · ISO/IEC 27001 5.37 |