Access control deals with the means to ensure that access to assets is authorized and restricted based on business and security requirements (ISO/IEC 27000). In ISO/IEC 27002 topics like user access management (access to information systems) as well as password, clean desk and clear screen policies are covered by access control.