HLD Group
Access control policy
Granting, reviewing, and revoking access to systems and data.
Last updated: 24 July 2026
Version 2.0 · Review cycle: 180 days · View all frameworks
1. Purpose
This policy establishes the requirements for granting, managing, reviewing, and revoking access to HLD Group information systems and data. Access control is the primary safeguard by which we enforce confidentiality and integrity, and it is the control most frequently examined by auditors, customers, and regulators.
Its purpose is to ensure that access is granted only to authenticated, authorised individuals and services, only to the extent needed, only for as long as needed, and always in a manner that can be evidenced.
2. Scope
This policy applies to all personnel, contractors, and service accounts, and to all systems, applications, data stores, networks, and physical and cloud environments owned or operated by HLD Group, including customer environments under our management subject to any stricter customer requirement.
3. Definitions
- Identity — the unique representation of a person or service that access is granted to
- Authentication — verifying that an identity is who or what it claims to be
- Authorisation — determining what an authenticated identity is permitted to do
- Least privilege — granting only the access required to perform a role or function
- Privileged access — elevated rights that can alter security configuration or reach unrelated data
- Joiner-mover-leaver (JML) — the lifecycle of access as people join, change role, and leave
- Segregation of duties — the division of tasks so that no single person can complete a sensitive process alone
4. Access control principles
- Least privilege — access is limited to what the role or function requires
- Need to know — access to information is limited to those who require it for a legitimate purpose
- Default deny — access is denied unless explicitly granted
- Segregation of duties — sensitive processes require more than one person
- Accountability — every action is attributable to an individual identity, not a shared account
- Just-in-time and just-enough — privileged access is elevated only when needed and for the minimum scope and time
5. Identity lifecycle (joiner, mover, leaver)
Provisioning
Access is provisioned on the basis of an approved role, initiated by a documented request and authorised by the resource owner or line manager. New access follows role-based templates so that grants are consistent and reviewable.
Change of role
When a person changes role, access is re-evaluated and rights no longer required are removed. Accumulated access from prior roles — privilege creep — is a common audit finding and is actively prevented through review.
Deprovisioning
Access is revoked promptly on termination or end of engagement. Access to critical systems is disabled on the effective date, and all access is fully removed within one business day. Offboarding is coordinated between People and Culture, IT, and the resource owner.
6. Authentication requirements
- Multi-factor authentication is mandatory for all remote access, all administrative access, and all access to systems processing sensitive or customer data
- Phishing-resistant authenticators (such as FIDO2/WebAuthn security keys or platform passkeys) are required for privileged and high-risk access
- Single sign-on through the central identity provider is used wherever a system supports it, to centralise enforcement and revocation
- Passwords and secrets follow the Password and Authentication Policy
- Service-to-service authentication uses short-lived credentials or workload identity, not long-lived shared secrets
7. Authorisation and privileged access
- Role-based access control is the default model; attribute-based controls are used where finer granularity is required
- Privileged access is granted just-in-time, is time-bound, and is logged and reviewed
- Administrative activity uses dedicated privileged accounts, never day-to-day user accounts
- Break-glass accounts are tightly controlled, monitored, and reviewed after every use
- Standing privileged access is minimised and justified in writing where it cannot be eliminated
8. Access reviews and recertification
Access is recertified on a defined cadence so that grants remain justified over time. Reviews are performed by resource owners, who confirm that each grant is still required.
- Privileged access reviewed at least quarterly
- General access reviewed at least every six months
- Service accounts reviewed for necessity, ownership, and credential rotation
- Findings remediated within a defined period, and evidence retained for audit
9. Shared, service, and non-human accounts
- Interactive shared accounts are prohibited unless a documented exception with compensating controls is approved
- Service accounts have a named human owner, a defined purpose, and rotated or workload-based credentials
- Secrets are stored in a managed secrets vault, never in code, configuration, or tickets
- Non-human identities are inventoried and reviewed like human identities
10. Remote and third-party access
- Remote access requires MFA and flows through controlled, monitored channels
- Third-party and vendor access is time-bound, least-privilege, individually attributable, and logged
- Vendor access is governed by the Vendor Management Policy and removed at engagement end
11. Framework alignment
- ISO/IEC 27001:2022 Annex A controls 5.15 (access control), 5.16 (identity management), 5.17 (authentication information), 5.18 (access rights), and 8.2 (privileged access rights)
- NIST SP 800-53 Rev. 5 control family AC (Access Control) and IA (Identification and Authentication)
- SOC 2 Trust Services Criteria CC6.1, CC6.2, and CC6.3
- PCI DSS v4.0 Requirements 7 and 8 where cardholder data is in scope
12. Roles, exceptions, enforcement, and review
Resource owners approve and recertify access; IT provisions and deprovisions; the CISO owns this policy. Exceptions require documented CISO approval with compensating controls and an expiry date. Violations may result in access suspension and disciplinary action. This policy is reviewed at least annually and after any access-related incident.
Related frameworks
For contractual attestations or audit packs, contact [email protected].