This template was created by the people of ICT Institute
You can find the latest version and other templates here:
https://ictinstitute.nl/free-templates/
You can use this template freely under the Create Commons Attribution license
https://creativecommons.org/licenses/by/4.0/
You can do the following with the templates:
Share. You can share the templates and any documents made with these templates freely, with any on
Adapt. You can make new documents based on the templates, make changes, add elements or delete
If you are a customer, you do not have to mention ICT Institute anywhere
If you are not a customer, you must keep the text "create by the people of ICT Institute" somewhere
Note that the use of these templates is of course at your own risk.
Note also that the ISO standards are copyrighted. You must buy the standard from NEN or ISO before u
Read also:
https://ictinstitute.nl/iso-27001-and-nen7510-support/
https://ictinstitute.nl/iso27002-explained-part-1/
https://ictinstitute.nl/iso27002-2022-explained-1/
tion license
hese templates freely, with any one that you want to share it with.
 changes, add elements or delete elements as much as you want. You can even do this in commercial organisations of for comm
ple of ICT Institute" somewhere
 tandard from NEN or ISO before using it
mercial organisations of for commercial purposes.
Authorisation Matrix
Version                              1
Classification           Internal use
owner of this register   CISO
Policy for access by role type
This is a descrpition of access rights per role. Extra access rights may only be give by the CEO based on business nee
A VOG is a formal Certificate of Conduct, provided by the Dutch government
Role                            Description                        Examples
                                CEO, accountable for the entire
Managing director               organization                    Sieuwert
                                Information Security Executive,
CISO                            accountable for InfoSeC            Joost
                                Maintains internal systems and
IT-admin                        networks                           Mitchell
Sales employee                  Sales department, non-managers John
Head of Sales                   Sales Director                 Frank
…
Role n.
ve by the CEO based on business need
         office key          Tag           Telephone Laptop   System 1 role System 2 role
                   x                   x       x          x   User          User
                   x                   x       x          x   Security admin Security admin
                                       x       x          x   Global admin Global admin
                                       x       x          x   User          User
                                       x       x          x   User          User
Website CRM role Social media   May sign          Column1
User             n/a            Everything
Security admin   n/a            Contracts <250k
Global admin     n/a            n/a
n/a              User           n/a
User             n/a            Contracts <1mln
Employee ID Name                    Role
0001        Sieuwert van Otterloo   Director en consultant
            …
            …
Employed since          Last active
                 2015                 2023
                              VOG
No Person        Role         screening    categories         screening Required to sign
                                                              completed inforsec rules?
                              required
                 Director and
1 Sieuwert       consultant yes            11,12,13,21,22,71 yes           yes
2
3
…
    Note: VOG (Verklaring Omstrent Gedrag) is the best way to do employee screening in the Netherlands
    For non-Dutch organisations, check what type of employee screening (calling references, diploma validation, …)
           Rules signed
           yes
 in the Netherlands
ences, diploma validation, …) works for you
Date   Change   Author
Approval