A.8.3Information access restriction
Restrict access to information and application functions according to your access control policy, so people only reach what their role requires.
A.8.3 is covered by 3 Sekit CSF controls. Open in the full graph →
Mapped from the Sekit CSF
The Sekit controls that cover this requirement, lens by lens.
NIST CSF 2.0 counterparts
Reached through the Sekit CSF controls both map to — a mapping, not a formal equivalence.
Cyber Essentials counterparts
In practice
Restricting access to information usually means role-based permissions enforced by the system itself, not a spreadsheet describing who should have what. Auditors check whether a new hire's access is granted from a defined role rather than copied from whichever colleague sits nearby, since copied access is how permissions creep accumulates unnoticed over years. For multi-tenant applications, the same principle extends to customer data: every query is scoped to the requesting tenant at the platform layer, so a bug in application code cannot expose one customer's records to another. The common failure mode is an admin panel or reporting tool that bypasses the role model entirely because it predates the access control policy.
Common gaps
Questions your auditor will ask
Where regulation demands it
Related controls
Via the shared Sekit CSF topic, not the framework's own index.
Connect your AI · free MCP
https://sekit.ai/api/mcp/crosswalk- In Claude or ChatGPT, add a custom connector and paste this URL.
- Sign in with your email to finish. Free, read-only, no organization required.