Access Control Policy
Defines access rules, approval, least privilege, and review cadence.
Controls for asset inventory, ownership, and protection.
Description
Defines how assets are identified, inventoried, classified, owned, and protected. Covers hardware/software inventory, data and information assets, asset custodianship, classification/labeling, acceptable use, handling requirements, lifecycle management, and disposal/sanitization.
Defines access rules, approval, least privilege, and review cadence.
Establishes governance structure, decision rights, and oversight.
Sets risk principles, controls expectations, and accountability for AI.
Defines approvals and safeguards for system/process change.
Backup requirements, testing cadence, and recovery expectations.
Rules for data ownership, quality, lifecycle, and stewardship.