- Documentation
- Set up
Who can see and do what
The documented access control model for your Certaria ISMS site, how to maintain it, and how to review it so it can be evidenced at audit.
Purpose: the documented access control model for the Certaria ISMS site, how to maintain it, and
Where: nothing to do here. This is the map of how your SharePoint site and your Microsoft 365 groups fit together. how to review it so the implementation can be evidenced at audit.
Audience: ISMS Admin.
Why this matters: ISO/IEC 27001:2022 A.5.15 requires access control rules to be established and documented, and A.5.18 requires access rights to be provisioned, reviewed and removed according to those rules. A correctly configured site is not evidence on its own. The evidence is this document, plus the review record described in section 5.
1. The access model
Section titled “1. The access model”| Where | Everyone (staff) | ISMS administrators |
|---|---|---|
| Home, Policies, Report a concern pages | Read | Read |
| Published Policies (approved documents) | Read | Contribute |
| ISMS Policies (the document library) | Read | Contribute |
| Policy Acknowledgements | Add and see their own only | Full control |
| Concerns | Add and see their own only | Full control |
| ISMS Working (pending and draft material) | No access | Contribute |
| Audit Pack | No access | Contribute |
| Evidence | No access | Contribute |
Two points an auditor will ask about, so they are stated deliberately:
Staff cannot see working material. Documents that have not been approved for your organisation live in ISMS Working and are invisible to staff. This prevents anyone following a policy that has not been adopted.
Staff cannot see each other’s submissions. Acknowledgements and concerns use item level permissions, so each person sees only what they submitted. This matters most for concerns, where someone may be reporting a colleague.
2. The two group layers
Section titled “2. The two group layers”Access is granted through two layers, and it is important not to collapse them.
| Layer | What it is | What it does |
|---|---|---|
| Assignment | SharePoint groups ISMS Readers and ISMS Admins, on the site | Hold the permissions in section 1. Created by Certaria. Do not rename or delete these. |
| Membership | Microsoft Entra security groups placed inside the SharePoint groups | Decide who is in scope. Managed by you in the Entra admin centre |
Why two layers rather than adding people directly. Putting an Entra group inside the SharePoint group means membership is managed in one place, is enumerable, and can be exported for review. Adding individuals directly to the SharePoint group works, but it scatters the record and makes A.5.18 review harder than it needs to be.
3. Adding and removing people
Section titled “3. Adding and removing people”Add or remove them from the Entra security group that sits inside ISMS Readers. Nothing else is
required. Access takes effect at their next sign in.
Leavers: removing someone from the Entra group removes their access to the site. Their acknowledgement records remain in Certaria, which is correct: they are evidence of what happened while the person was employed.
ISMS administrators
Section titled “ISMS administrators”Add or remove them from the Entra security group that sits inside ISMS Admins.
Use ordinary working accounts, not administrative accounts. ISMS administration is routine business work. A.8.2 expects privileged accounts to be restricted to privileged purposes, and “the Global Admin account owns our policy library” is an awkward sentence in a Stage 2 audit.
4. Navigation and what people see
Section titled “4. Navigation and what people see”Navigation shows Home, Policies, Report a concern to everyone. An ISMS admin section appears only for members of the administrator Entra group, using SharePoint audience targeting.
Audience targeting hides links. It does not enforce access. The permissions in section 1 are what prevent access. Audience targeting only stops staff seeing links to places they cannot open. Never treat a hidden link as a control.
5. The review procedure (A.5.18)
Section titled “5. The review procedure (A.5.18)”Run this quarterly, or after any joiner or leaver.
- Open the Entra security group inside
ISMS Readers. Export or screenshot the membership. - Compare it against your current staff list. Remove anyone who has left or changed role.
- Repeat for the group inside
ISMS Admins. This list should be short and should contain only people who administer the ISMS. - Confirm no individual accounts have been added directly to either SharePoint group, bypassing the Entra layer.
- Record the date, who performed the review, and any changes made.
Evidence produced: the dated review record from step 5, plus the group membership export from steps 1 and 3. That combination is what demonstrates A.5.18, and it is worth keeping in the Audit Pack library.
6. Common failure modes
Section titled “6. Common failure modes”The staff group is empty, so nobody can see anything. This is the most likely failure and it is
silent. Administrators see a working site because they are administrators, while staff see nothing
at all, and no error appears anywhere. If staff report that the site is empty or inaccessible,
check the Entra group inside ISMS Readers first.
Someone has permissions but no licence. They land on the Microsoft 365 home page rather than the site, with nothing to indicate why. Permissions and licences are independent, so this looks identical to a working setup from every angle except the person’s own screen. See the caution in section 3. Check this before assuming a permissions fault, because the permissions will check out and you will spend the time twice.
Someone was added directly to the SharePoint group. It works, but it is now invisible to your Entra group review and will be missed at step 4. Move them into the Entra group instead.
A container lost its unique permissions. If ISMS Working, Audit Pack or Evidence ever becomes visible to staff, its permissions have been reset to inherit from the site. Re-apply unique permissions and investigate what changed.
An administrator account was used instead of a working account. Access still functions, but it weakens the privileged access separation in A.8.2 and creates an orphaning risk if that account is later disabled or rotated.
7. What this document is for
Section titled “7. What this document is for”Keep it current. If you change who has access to what, change section 1 to match. An access control model that no longer describes the system is worse than none, because it invites an auditor to verify a claim that has quietly stopped being true.