This template was created by the people of ICT Institute
You can find the latest version and other templates here:
[Link]
You can use this template freely under the Create Commons Attribution license
[Link]
You can do the following with the templates:
Share. You can share the templates and any documents made with these templates freely, with any on
Adapt. You can make new documents based on the templates, make changes, add elements or delete
If you are a customer, you do not have to mention ICT Institute anywhere
If you are not a customer, you must keep the text "create by the people of ICT Institute" somewhere
Note that the use of these templates is of course at your own risk.
Note also that the ISO standards are copyrighted. You must buy the standard from NEN or ISO before u
Read also:
[Link]
[Link]
[Link]
tion license
hese templates freely, with any one that you want to share it with.
changes, add elements or delete elements as much as you want. You can even do this in commercial organisations of for comm
ple of ICT Institute" somewhere
tandard from NEN or ISO before using it
mercial organisations of for commercial purposes.
Authorisation Matrix
Version 1
Classification Internal use
owner of this register CISO
Policy for access by role type
This is a descrpition of access rights per role. Extra access rights may only be give by the CEO based on business nee
A VOG is a formal Certificate of Conduct, provided by the Dutch government
Role Description Examples
CEO, accountable for the entire
Managing director organization Sieuwert
Information Security Executive,
CISO accountable for InfoSeC Joost
Maintains internal systems and
IT-admin networks Mitchell
Sales employee Sales department, non-managers John
Head of Sales Sales Director Frank
…
Role n.
ve by the CEO based on business need
office key Tag Telephone Laptop System 1 role System 2 role
x x x x User User
x x x x Security admin Security admin
x x x Global admin Global admin
x x x User User
x x x User User
Website CRM role Social media May sign Column1
User n/a Everything
Security admin n/a Contracts <250k
Global admin n/a n/a
n/a User n/a
User n/a Contracts <1mln
Employee ID Name Role
0001 Sieuwert van Otterloo Director en consultant
…
…
Employed since Last active
2015 2023
VOG
No Person Role screening categories screening Required to sign
completed inforsec rules?
required
Director and
1 Sieuwert consultant yes 11,12,13,21,22,71 yes yes
2
3
…
Note: VOG (Verklaring Omstrent Gedrag) is the best way to do employee screening in the Netherlands
For non-Dutch organisations, check what type of employee screening (calling references, diploma validation, …)
Rules signed
yes
in the Netherlands
ences, diploma validation, …) works for you
Date Change Author
Approval