Access control policy

Published: 02 September 2026
Freedom of information class: How we manage our resources

This policy relates to access to RoS digital information assets.


1. Purpose and scope

The purpose of the Access Control Policy is to detail the requirements and recommendations in order to ensure that access to RoS systems is granted only for authorised business purposes, that staff have the relevant security clearances and authorisations before access is granted and thereby reduce the risk of malicious actions such as theft, fraud and misuse of facilities.

Access to any RoS Information systems (including systems that are capable of processing and/or storing information, although this may not be its primary function) and any other systems employed by RoS that are used to create, process, store, receive and/or transmit RoS information are governed by this policy.

2. Applicability

This Policy is applicable to all RoS employees and third-party staff (e.g. contingent workers, consultants, resource company employees, temporary employees) hereinafter referred to as “users” that use or have access to RoS systems and/or information.

3. Terminology

TermMeaning/application
ShallThis term is used to state a mandatory requirement of this policy
ShouldThis term is used to state a recommended requirement of this policy
MayThis term is used to state an optional requirement

4. Roles and responsibilities

4.1 General

  • Access shall be granted using the principle of ‘least privilege’. This means that every programme and every user of the system should operate using the least set of privileges necessary to complete their job or role.
  • Each user shall be identified by a unique user identity so that users can be linked to and made responsible for their actions.
  • The use of group identities shall only be permitted where they are suitable for the work carried out (e.g. training accounts or service accounts).
  • During their induction to the system each user shall be provided with guidelines on use of the system and their user login details.
  • All user access events shall be securely logged to support incident investigations.

4.2 Physical access

  • Physical access shall only to be granted on the authority of the data/system owner and shall be applied on a strict ‘need to know’ basis.
  • All RoS data/systems shall be physically protected in accordance with their value and security classification.
  • Data/system owners shall implement physical security measures in line with the RoS Physical Security policy to control physical access to their data/systems.
  • For outsourced hosting (managed service providers/cloud), information asset owners shall ensure that the appropriate clauses are in place for controlled physical access.
  • The data/system owner should, where applicable retain a log ‘date/time/name/reason’ for access to their data/system.
  • Any unauthorised access shall be reported as a security incident.

4.3 Network access

  • All users shall be given network access in accordance with business access control procedures and requirements for access defined by their roles.
  • All users who access RoS networks remotely shall only be authenticated using the approved authentication mechanisms.
  • Network connected infrastructure devices should identify themselves automatically to each other.
  • The data/system owner should, where applicable retain a log ‘date/time/name’ for access to their data/system.
  • Diagnostic and configuration ports shall only be enabled for specified business reasons. All other ports shall be disabled or removed.
  • Network routing controls shall be implemented to support the access control policy.

4.4 Operating system access

4.4.1 User responsibilities

  • Only authorised RoS users with valid log-on information shall attempt to log-on to RoS systems.
  • All RoS users shall be expected to confirm they are an authorised user at log-on.
  • All RoS users shall have a unique identifier which shall not be shared with other users.
  • All RoS users shall be required to change their passwords in accordance with RoS password guidance.

4.4.2 System configuration

  • Only authorised RoS users shall have access to system utilities and access shall be revoked when there is no longer a business reason for access.
  • Where there is a business requirement for the use of identifiers that are not associated with a single individual (for example, service accounts), these shall only be created following consultation with the RoS IT security team and following a formal risk assessment.
  • All workstations shall be configured to lock automatically after a period of inactivity in order to reduce the risk of unauthorised access.
  • Restrictions on connection times to sensitive systems should be considered to reduce the window of opportunity for unauthorised access.

4.5 Information system access

4.5.1 User responsibilities

  • All users shall ensure that they lock their screens whenever they leave their desks to reduce the risk of unauthorised access.
  • All users shall ensure that their desks are kept clear of any information or removable storage media to reduce the risk of unauthorised access.
  • All users shall keep their passwords confidential and unique user identities shall not be shared.
  • Passwords shall be changed whenever there is an indication of possible system compromise in line with RoS password guidance.

4.5.2 Administration

  • Managers shall review user access rights on an annual basis and after any changes to users roles and responsibilities.
  • Users shall have a unique user identity, so that the user can be held accountable for any actions carried out by their allocated user identity.
  • A formal record of all users connected to RoS systems shall be maintained, including the necessary approvals.
  • Privileged access management shall be controlled through a formal process and only the minimum privileges shall be granted to carry out the role or task.
  • A formal record of all privileges allocated shall be maintained.
  • When an account is no longer required, e.g. through resignation or a change in duties, the account shall be disabled immediately.
  • Unused accounts shall be monitored and appropriate action taken in line with RoS procedures for disabling and deleting accounts.
  • Removal of accounts shall also include the removal of any associated access rights.

4.5.3 System configuration

  • Access to information systems shall be granted using a formal user registration process.
  • An account may be defined at the operating system level or the application level, but auditing shall capture the unique user identity being used.
  • Where technically possible, all standard accounts that are delivered with operating systems shall be disabled, deleted or have their ‘default’ passwords changed on system installation.

4.5.4 Application information system access

  • All RoS users shall only be granted access to those application functions required to carry out their roles.
  • All RoS users shall only be granted access to information in applications in accordance with business access requirements and policy.
  • All RoS users shall only have access to sensitive systems if there is a business need to do so and they have successfully completed any additional necessary vetting processes.
  • Sensitive systems should be physically or logically isolated to meet the requirements of restricted access to authorised personnel.
  • RoS shall provide all users with access to the information, applications, systems and services required to meet their responsibilities in a safe and secure manner that is as effective and efficient as possible.
  • Account access from outside of the UK is prohibited without explicit Director level approval and risk assessment being conducted prior (access is blocked by default and any attempt will trigger an investigation).
  • All account requests shall be supported by an appropriate sponsor within the requestors line management or an appropriate business sponsor when applying for guest accounts on a specific system, service or line of business application or service.

5. Roles and responsibilities

5.1  All RoS users are bound by the commitments of this policy, and:

  • are required to effectively operate the range of procedures and controls which facilitate compliance in practice
  • must report any non-conformances of or improvement to policy requirements to the Information Security Assurance Group (ISAG)

5.2  Managers and team leads must ensure that all relative processes, products or service support compliance of this policy.

5.3  The ISAG has ownership of this policy and is responsible for enforcement of its requirements.

5.4  The ISAG is accountable for information governance, which includes requirements for the protection and handling of RoS information assets.

5.5  Frameworks (or agreements) must be in place to ensure that all partners within a supply chain are aware of the policy requirements and understand their responsibilities for compliance.

5.6  This policy should be part of the publication scheme. Internally this must be a mandatory read for all users.

6. Approval and review

This policy will be reviewed and approved by the RoS Information Security Assurance Group (ISAG) annually, unless earlier review is appropriate.

AuthorInformation Assurance Advisor
ReviewedHead of Information Security Risk & Assurance
ClearedHead of Risk & Information Governance
ApprovalInformation Security Assurance Group (ISAG) Approval date August 2026
Policy versionv.5.0
Review responsibilityInformation Security Assurance Group (ISAG) Review date August 2027
Publication scheme Yes
Email to contactSRA@ros.gov.uk