ISO/IEC 27001:2022: what it asks of an approval matrix
The Annex A controls that bear on an approval matrix: segregation of duties, roles and responsibilities, access rights, privileged access and change management.
Quoted for every matrix.
Approval families anchored here
35ISO/IEC 27001:2022: every clause cited, quoted
7 of the 93 heldThe requirement text is our statement of each clause, read against the copy we hold and cited to it; it is not the instrument verbatim.
ISO/IEC 27001 5.2 Information security roles and responsibilitiesName who owns what in security and make the allocation explicit and traceable.
Where matrices usually fall short: Roles not updated after staff changes; No documented acceptance of responsibilities; Unclear separation between ownership and operational duties; Delegated authority not reflected in policy documents
Source: ISO/IEC 27001:2022
ISO/IEC 27001 5.3 Segregation of dutiesSplit conflicting duties so no single person can run a sensitive process end to end unchecked.
Where matrices usually fall short: Combining conflicting roles in small teams; Lack of documented exceptions; Infrequent access rights reviews; Reliance on informal approvals
Source: ISO/IEC 27001:2022
ISO/IEC 27001 5.15 Access controlSet rules for physical and logical access based on business and security requirements.
Where matrices usually fall short: Infrequent review of access rights; Missing documentation for temporary access; Overly broad role definitions; Inadequate segregation of duties enforcement
Source: ISO/IEC 27001:2022
ISO/IEC 27001 5.18 Access rightsProvision, review, modify and remove access rights in line with the access control policy.
Where matrices usually fall short: Reviews lack documented corrective actions; Access changes not tied to approved request workflow; Legacy accounts remain active after employee departure; Role definitions not updated to reflect current business processes
Source: ISO/IEC 27001:2022
ISO/IEC 27001 5.37 Documented operating proceduresDocument operating procedures for information processing facilities and make them available to those who need them.
Where matrices usually fall short: Outdated procedures still in use; No evidence of distribution to staff; Missing version control for revisions; Procedures not aligned with actual practice
Source: ISO/IEC 27001:2022
ISO/IEC 27001 8.2 Privileged access rightsRestrict and manage the allocation and use of privileged access.
Where matrices usually fall short: Outdated privileged account inventory; Missing or informal approval documentation; Infrequent or superficial access reviews; Privileged activity logs not retained or insufficiently protected
Source: ISO/IEC 27001:2022
ISO/IEC 27001 8.32 Change managementPut changes to facilities and systems through change management procedures.
Where matrices usually fall short: Missing formal approval; No rollback plan documented; Testing performed after production deployment; Change records not linked to assets
Source: ISO/IEC 27001:2022