| 1 | Start with Requirement | Take the requirement you are assessing. | ISO 27001 A.5.15 — Access Control |
| 2 | Understand the Requirement | Determine what the requirement is trying to achieve. | Prevent unauthorised access to information and systems. |
| 3 | Define Control Objective | Write the desired outcome the control must achieve. | Ensure access to LondonBuild’s systems and information is authorised, appropriate and limited according to business need. |
| 4 | Identify the Risk | Ask what could happen if the objective isn’t achieved. | Unauthorised users could access sensitive company or project information. |
| 5 | Determine Control Activity | Decide what activity/process should achieve the objective. | Access is approved based on job role and business need. |
| 6 | Identify Control Owner | Determine who is accountable for the control. | IT Manager |
| 7 | Define Control Frequency | Determine how often the control operates. | At onboarding/change of role + quarterly review |
| 8 | Define Expected Evidence | Determine what should prove the control is operating. | Access requests, manager approvals, user-access reports |
| 9 | Define Testing Approach | Decide how you will later test the control. | Sample 10 users and verify approval and appropriate access. |
| 10 | Document the Control | Put everything into the GRC system/control register. | Control ID, objective, activity, owner, frequency, evidence, test method. |