A policy defining how access to systems and data is granted, managed, reviewed, and revoked within an organization.