Defining access control policy

An access control policy documents and specifies the resources that employees, management, contractors, business partners and customers can access. It also states when and where such access can take place.

An access control policy points out the following high-level concerns:

  • Necessary resource access types.
  • Access scope
  • Regulatory compliance considerations for access
  • Coordination across the organisations' departments
  • Control types that enable access management and oversight


Developing an Access Control Policy -


A fundamental aspect of implementing a business's access control system is developing the access control policy.

An access control policy is the strategic foundation of all the best access control systems. Every company should decide the data and resources each employee should be able to access.


Determining everyone's proper place is the result of extensive thought and planning.

For example, company CEOs have ultimate control over all business decisions and need access to extensive data. Yet CEOs wouldn't have access to detailed accounts payable or receivable accounting systems as a measure to prevent internal fraud. CEOs might also not have free access to a factory floor because they lack the training and gear to move safely around.


Smart business practices require predictability, risk management, regulatory compliance and process controls. 

Access breaches can cause damage, such as the loss of computer systems, theft and injury. An access control policy enables a business to anticipate and lower potential risks.


Key elements to include in an access control policy:

  • Building access, including specific areas like warehousing, shipping docks, utility rooms for electrical panels, parking lots, etc.
  • Computer, communications and other digital infrastructures.
  • Data on databases, servers, individual workstations, laptops, etc.
  • Business processes.
  • Physical safety of personnel in case of an emergency, like a natural or man-made disaster.
  • Regulatory and legal compliance standards.


Models are the step between creating a policy and implementing it. They include detailed rule descriptions that don't depend on any given hardware, software or other mechanisms. 

Mechanisms can be software-based, such as an access control list or a physical item like a key or swipe card. Proper documentation will record which mechanisms will be used where.


