Frameworks / SOC 2 / SOC2-CC6.1 SOC 2
CC - Common Criteria (Security)
SOC 2 SOC2-CC6.1: CC6.1 Logical access security over protected information assets Access security software, infrastructure and architecture are in place over protected information assets to guard them against security events. Points of focus: information assets are inventoried, classified and managed; logical access to hardware, data at rest, in processing and in transit, software, admin rights, mobile devices, output and offline components is limited through access control software and rules; users, devices and software prove who they are before they get in, locally or remotely; networks are segmented so unrelated parts are isolated; external points of access and the data and users passing through them are inventoried and managed; access rules combine classification, data separation, port and protocol limits, identity and certificates; identification and authentication requirements are defined and managed; new infrastructure and software are registered and authorised before receiving credentials, which are removed when no longer needed; encryption protects data at rest where risk warrants; and keys are protected from generation to destruction. The 2022 revision adds: new system architectures are security-assessed before they go live; restricted components expressly include servers, storage, network elements, APIs and endpoints, with standard hardening applied; stronger authentication such as multifactor is used where the risk strategy calls for it; isolation may use zero trust designs and other techniques beyond network segmentation; cryptographic modules, algorithms, key lengths and designs suit the risk strategy; and, where confidentiality or privacy is in scope, access to confidential or personal information is limited to the purposes identified and to personnel who need it.
Maintained by Gerard Blokdyk · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 566 controls across 48 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
1.2.1 1.2.1 Ruleset configuration standards for NSCs 1.2.4 1.2.4 Accurate data-flow diagram for account data 1.2.5 1.2.5 Allowed services, protocols and ports justified 1.2.8 1.2.8 NSC configuration files secured and consistent 1.4.4 1.4.4 Cardholder data stores not reachable from untrusted networks 1.4.5 1.4.5 Internal IP and routing disclosure limited 10.1.1 10.1.1 Requirement 10 policies and procedures maintained and in use 10.1.2 10.1.2 Roles for logging and monitoring assigned and understood 10.2.1.1 10.2.1.1 Logs capture individual user access to cardholder data 10.2.1.2 10.2.1.2 Logs capture all administrative actions 10.2.1.3 10.2.1.3 Access to the audit logs is itself logged 10.2.1.4 10.2.1.4 Logs capture invalid logical access attempts 10.2.1.5 10.2.1.5 Logs capture changes to identification and authentication credentials 10.2.1.7 10.2.1.7 Logs capture creation and deletion of system-level objects 10.2.2 10.2.2 Required details recorded for each auditable event 10.3.1 10.3.1 Audit log read access limited to job need 10.3.2 10.3.2 Audit log files protected from modification 10.6.3 10.6.3 Time sync configuration and time data protected 11.2.2 11.2.2 Inventory of authorized wireless access points 11.4.7 11.4.7 Multi-tenant providers support customer penetration testing 12.3.3 12.3.3 Cryptographic cipher suite and protocol inventory reviewed annually 12.4.1 12.4.1 Executive responsibility for a PCI DSS compliance program 12.5.1 12.5.1 Inventory of in-scope system components 2.2.1 2.2.1 System configuration standards maintained 2.2.2 2.2.2 Vendor default accounts managed 2.2.3 2.2.3 Primary functions with different security levels managed 2.2.4 2.2.4 Only necessary functionality enabled 2.2.5 2.2.5 Insecure services, protocols or daemons secured 2.2.6 2.2.6 System security parameters configured against misuse 2.2.7 2.2.7 Non-console administrative access encrypted 2.3.1 2.3.1 Wireless vendor defaults changed or confirmed secure 2.3.2 2.3.2 Wireless encryption keys changed on triggers 3.3.3 3.3.3 Issuer SAD storage limited, justified and encrypted 3.4.2 3.4.2 Remote access blocks copying or relocating PAN 3.5.1.1 3.5.1.1 PAN hashes are keyed cryptographic hashes 3.5.1.2 3.5.1.2 Disk or partition encryption only on removable media 3.5.1.3 3.5.1.3 Disk encryption access independent of OS authentication 3.6.1.1 3.6.1.1 Service provider cryptographic architecture documented 3.6.1.2 3.6.1.2 Permitted storage forms for secret and private keys 3.6.1.3 3.6.1.3 Cleartext key component access limited to minimum custodians 3.6.1.4 3.6.1.4 Cryptographic keys kept in fewest locations 3.7.2 3.7.2 Secure distribution of cryptographic keys 3.7.3 3.7.3 Secure storage of cryptographic keys 3.7.6 3.7.6 Split knowledge and dual control for manual key operations 3.7.7 3.7.7 Prevent unauthorized substitution of keys 3.7.9 3.7.9 Key guidance for service provider customers 4.2.1 4.2.1 Strong cryptography safeguards PAN over public networks 4.2.1.1 4.2.1.1 Inventory of trusted transmission keys and certificates 4.2.1.2 4.2.1.2 Wireless networks use strong cryptography 6.2.3.1 6.2.3.1 Manual code review independence and approval 6.5.5 6.5.5 No live PANs in pre-production 7.2.1 7.2.1 Access control model defined 7.3.2 7.3.2 Access control system enforces role-based permissions 7.3.3 7.3.3 Access control default deny all 8.2.2 8.2.2 Shared and generic IDs only by exception 8.2.3 8.2.3 Service provider unique factors per customer 8.2.5 8.2.5 Terminated users' access revoked immediately 8.2.6 8.2.6 Inactive accounts removed within 90 days 8.2.8 8.2.8 Re-authentication after 15 minutes idle 8.3.1 8.3.1 Access authenticated with at least one factor 8.3.10 8.3.10 Service provider customer password guidance 8.3.10.1 8.3.10.1 Service provider customer passwords 90 days or dynamic 8.3.11 8.3.11 Tokens, smart cards and certificates individually assigned 8.3.2 8.3.2 Authentication factors unreadable with strong cryptography 8.3.4 8.3.4 Lockout after 10 attempts for 30 minutes 8.3.5 8.3.5 Initial and reset passwords unique and changed 8.3.6 8.3.6 Password minimum length 12 and complexity 8.3.7 8.3.7 No reuse of last four passwords 8.3.9 8.3.9 Single-factor passwords changed every 90 days or dynamic analysis 8.4.1 8.4.1 MFA for non-console administrative CDE access 8.4.2 8.4.2 MFA for all non-console CDE access 8.4.3 8.4.3 MFA for remote access that could reach CDE 8.5.1 8.5.1 MFA system resistant to replay and bypass 9.2.4 9.2.4 Locking of consoles in sensitive areas 9.4.1 9.4.1 Physical security of all media 9.4.4 9.4.4 Management approval for media leaving facility 9.5.1.1 9.5.1.1 Current register of POI devices 3.4.1 3.4.1 PAN masked on display except for authorized roles 3.7.1 3.7.1 Generation of strong cryptographic keys 6.5.3 6.5.3 Separate pre-production from production 7.2.5 7.2.5 Application and system accounts least privilege 7.3.1 7.3.1 Need-to-know access control system covers all components 8.6.1 8.6.1 Interactive use of system accounts controlled 8.6.2 8.6.2 No hard-coded passwords for interactive system accounts 8.6.3 8.6.3 System account passwords protected against misuse AC-11 Device Lock AC-11(1) Device Lock | Pattern-hiding Displays (AC-11(1)) AC-12 Session Termination AC-17 Remote Access AC-17(2) Protection of Confidentiality and Integrity Using Encryption AC-17(3) Managed Access Control Points AC-18(1) Authentication and Encryption AC-18(3) Wireless Access | Disable Wireless Networking (AC-18(3)) AC-19 Access Control for Mobile Devices AC-19(5) Full Device or Container-Based Encryption AC-2 Account Management AC-2(13) Disable Accounts for High-Risk Individuals AC-2(5) Inactivity Logout AC-2(7) Privileged User Accounts AC-2(9) Restrictions on Use of Shared and Group Accounts AC-20(2) Portable Storage Devices Restricted Use AC-3 Access Enforcement AC-7 Unsuccessful Logon Attempts AU-3(1) Additional Audit Information AU-9 Protection of Audit Information CA-9 Internal System Connections CM-12 Information Location (CM-12) CM-12(1) Information Location | Automated Tools to Support Information Location (CM-12(1)) CM-5(1) Access Restrictions for Change | Automated Access Enforcement and Audit Records (CM-5(1)) CM-7 Least Functionality CM-7(1) Periodic Review CP-9(8) System Backup | Cryptographic Protection (CP-9(8)) IA-2 Identification and Authentication (Organizational Users) IA-2(1) MFA to Privileged Accounts IA-2(12) Acceptance of PIV Credentials IA-2(2) MFA to Non-Privileged Accounts IA-2(6) Identification and Authentication (Organizational Users) | Access to Accounts: separate Device (IA-2(6)) IA-2(8) Access to Accounts Replay Resistant IA-5 Authenticator Management IA-5(1) Password-Based Authentication IA-5(6) Protection of Authenticators IA-5(7) Authenticator Management | No Embedded Unencrypted Static Authenticators (IA-5(7)) IA-6 Authentication Feedback IA-7 Cryptographic Module Authentication IA-8 Identification and Authentication (Non-Organizational Users) IA-8(1) Identification and Authentication (Non-organizational Users) | Acceptance of PIV Credentials from Other Agencies (IA-8(1)) IA-8(2) Identification and Authentication (Non-organizational Users) | Acceptance of External Authenticators (IA-8(2)) MA-4 Nonlocal Maintenance MP-2 Media Access PL-8 Security and Privacy Architectures PS-4 Personnel Termination PS-5 Personnel Transfer RA-5(5) Privileged Access RA-9 Criticality Analysis (RA-9) SA-8 Security and Privacy Engineering Principles SA-9(2) Identification of Functions, Ports, Protocols, and Services SC-10 Network Disconnect SC-12 Cryptographic Key Establishment and Management SC-13 Cryptographic Protection SC-15 Collaborative Computing Devices and Applications SC-22 Architecture and Provisioning for Name/Address Resolution Service SC-23 Session Authenticity SC-28(1) Cryptographic Protection SC-39 Process Isolation SC-4 Information in Shared System Resources SC-7 Boundary Protection SC-7(5) Deny by Default Allow by Exception SI-11 Error Handling AC-11 Device Lock AC-11(1) Device Lock | Pattern-hiding Displays (AC-11(1)) AC-12 Session Termination AC-17 Remote Access AC-17(2) Protection of Confidentiality and Integrity Using Encryption AC-17(3) Managed Access Control Points AC-18(1) Authentication and Encryption AC-18(3) Wireless Access | Disable Wireless Networking (AC-18(3)) AC-19 Access Control for Mobile Devices AC-19(5) Full Device or Container-Based Encryption AC-2 Account Management AC-2(13) Disable Accounts for High-Risk Individuals AC-2(5) Inactivity Logout AC-2(7) Privileged User Accounts AC-2(9) Restrictions on Use of Shared and Group Accounts AC-20(2) Portable Storage Devices Restricted Use AC-3 Access Enforcement AC-7 Unsuccessful Logon Attempts AU-3(1) Additional Audit Information AU-9 Protection of Audit Information CA-9 Internal System Connections CM-12 Information Location (CM-12) CM-12(1) Information Location | Automated Tools to Support Information Location (CM-12(1)) CM-5(1) Access Restrictions for Change | Automated Access Enforcement and Audit Records (CM-5(1)) CM-7 Least Functionality CM-7(1) Periodic Review CP-9(8) System Backup | Cryptographic Protection (CP-9(8)) IA-2 Identification and Authentication (Organizational Users) IA-2(1) MFA to Privileged Accounts IA-2(12) Acceptance of PIV Credentials IA-2(2) MFA to Non-Privileged Accounts IA-2(6) Identification and Authentication (Organizational Users) | Access to Accounts: separate Device (IA-2(6)) IA-2(8) Access to Accounts Replay Resistant IA-5 Authenticator Management IA-5(1) Password-Based Authentication IA-5(6) Protection of Authenticators IA-5(7) Authenticator Management | No Embedded Unencrypted Static Authenticators (IA-5(7)) IA-6 Authentication Feedback IA-7 Cryptographic Module Authentication IA-8 Identification and Authentication (Non-Organizational Users) IA-8(1) Identification and Authentication (Non-organizational Users) | Acceptance of PIV Credentials from Other Agencies (IA-8(1)) IA-8(2) Identification and Authentication (Non-organizational Users) | Acceptance of External Authenticators (IA-8(2)) MA-4 Nonlocal Maintenance MP-2 Media Access PL-8 Security and Privacy Architectures PS-4 Personnel Termination PS-5 Personnel Transfer RA-5(5) Privileged Access RA-9 Criticality Analysis (RA-9) SA-8 Security and Privacy Engineering Principles SA-9(2) Identification of Functions, Ports, Protocols, and Services SC-10 Network Disconnect SC-12 Cryptographic Key Establishment and Management SC-13 Cryptographic Protection SC-15 Collaborative Computing Devices and Applications SC-22 Architecture and Provisioning for Name/Address Resolution Service SC-23 Session Authenticity SC-28(1) Cryptographic Protection SC-39 Process Isolation SC-4 Information in Shared System Resources SC-7 Boundary Protection SC-7(5) Deny by Default Allow by Exception SI-11 Error Handling CIS-1.1 Establish and Maintain Detailed Enterprise Asset Inventory CIS-1.3 Utilize an Active Discovery Tool CIS-1.4 Use Dynamic Host Configuration Protocol (DHCP) Logging to Update Enterprise Asset Inventory CIS-1.5 Use a Passive Asset Discovery Tool CIS-12.2 Establish and Maintain a Secure Network Architecture CIS-12.3 Securely Manage Network Infrastructure CIS-12.4 Establish and Maintain Architecture Diagram(s) CIS-12.5 Centralize Network Authentication, Authorization, and Auditing (AAA) CIS-12.6 Use of Secure Network Management and Communication Protocols CIS-12.7 Ensure Remote Devices Utilize a VPN and are Connecting to an Enterprise’s AAA Infrastructure CIS-12.8 Establish and Maintain Dedicated Computing Resources for All Administrative Work CIS-13.5 Manage Access Control for Remote Assets CIS-13.9 Deploy Port-Level Access Control CIS-14.3 Train Workforce Members on Authentication Best Practices CIS-16.10 Apply Secure Design Principles in Application Architectures CIS-16.11 Leverage Vetted Modules or Services for Application Security Components CIS-3.3 Configure Data Access Control Lists CIS-3.6 Encrypt Data on End-User Devices CIS-4.10 Enforce Automatic Device Lockout on Portable End-User Devices CIS-4.12 Separate Enterprise Workspaces on Mobile End-User Devices CIS-4.3 Configure Automatic Session Locking on Enterprise Assets CIS-4.4 Implement and Manage a Firewall on Servers CIS-4.6 Securely Manage Enterprise Assets and Software CIS-4.7 Manage Default Accounts on Enterprise Assets and Software CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software CIS-5.2 Use Unique Passwords CIS-5.3 Disable Dormant Accounts CIS-5.5 Establish and Maintain an Inventory of Service Accounts CIS-5.6 Centralize Account Management CIS-6.1 Establish an Access Granting Process CIS-6.2 Establish an Access Revoking Process CIS-6.3 Require MFA for Externally-Exposed Applications CIS-6.4 Require MFA for Remote Network Access CIS-6.5 Require MFA for Administrative Access CIS-6.6 Establish and Maintain an Inventory of Authentication and Authorization Systems CIS-6.7 Centralize Access Control CIS-6.8 Define and Maintain Role-Based Access Control CIS-8.5 Collect Detailed Audit Logs 5.10 Acceptable use of information and other associated assets 5.11 Return of assets 5.15 Access control 5.16 Identity management 5.17 Authentication information 5.18 Access rights 5.23 Information security for use of cloud services 5.33 Protection of records 5.9 Inventory of information and other associated assets 6.5 Responsibilities after termination or change of employment 6.7 Remote working 7.1 Physical security perimeters 7.12 Cabling security 7.2 Physical entry 7.3 Securing offices, rooms and facilities 7.4 Physical security monitoring 7.6 Working in secure areas 7.7 Clear desk and clear screen 7.9 Security of assets off-premises 8.1 User end point devices 8.18 Use of privileged utility programs 8.2 Privileged access rights 8.20 Networks security 8.21 Security of network services 8.22 Segregation of networks 8.27 Secure system architecture and engineering principles 8.3 Information access restriction 8.31 Separation of development, test and production environments 8.4 Access to source code 8.5 Secure authentication 5.15 Access control 5.16 Identity management 5.17 Authentication information 5.18 Access rights 5.23 Information security for use of cloud services 5.32 Intellectual property rights 5.9 Inventory of information and other associated assets 6.7 Remote working 8.1 User endpoint devices 8.15 Logging 8.18 Use of privileged utility programs 8.2 Privileged access rights 8.22 Segregation of networks 8.27 Secure system architecture and engineering principles 8.3 Information access restriction 8.34 Protection of information systems during audit testing 8.4 Access to source code 8.5 Secure authentication C5-AM-01 Asset Inventory C5-COS-01 Technical safeguards C5-COS-07 Documentation of the network topology C5-CRY-01 Policy for the use of encryption procedures and key management C5-CRY-03 Encryption of sensitive data for storage C5-CRY-04 Secure key management C5-DEV-10 Separation of environments C5-IDM-01 Policy for user accounts and access rights C5-IDM-03 Locking and withdrawal of user accounts in the event of inactivity or multiple failed logins C5-IDM-08 Confidentiality of authentication information C5-IDM-09 Authentication mechanisms C5-OPS-12 Logging and Monitoring - Access, Storage and Deletion C5-OPS-14 Logging and Monitoring - Storage of the Logging Data C5-OPS-24 Separation of Datasets in the Cloud Infrastructure C5-PSS-05 Authentication Mechanisms C5-PSS-07 Confidentiality of Authentication Information ASBv3-AM-1 Track asset inventory and their risks ASBv3-DP-5 Use customer-managed key option in data at rest encryption when required ASBv3-DP-6 Use a secure key management process ASBv3-DP-7 Use a secure certificate management process ASBv3-DP-8 Ensure security of key and certificate repository ASBv3-GS-6 Define and implement identity and privileged access strategy ASBv3-IM-2 Protect identity and authentication systems ASBv3-IM-8 Restrict the exposure of credential and secrets ASBv3-PA-7 Follow just enough administration (least privilege) principle BR-2 Protect backup and recovery data DP-4 Enable data at rest encryption by default IM-1 Use centralized identity and authentication system IM-6 Use strong authentication controls IM-7 Restrict resource access based on conditions 5.5 Support 5.6 Operation 6.3.2 Mobile devices and teleworking 6.5.2 Information classification 6.6 Access control 6.6.1 Business requirements of access control 6.6.2 User access management 6.6.3 User responsibilities 6.6.4 System and application access control 6.7.1 Cryptographic controls 6.9 Operations security 6.9.6 Technical vulnerability management NIST-CSF-ID.AM-02 Inventories of software, services, and systems managed by the organization are maintained NIST-CSF-ID.AM-03 Representations of the organization's authorized network communication and internal and external network data flows are maintained NIST-CSF-ID.AM-05 Assets are prioritized based on classification, criticality, resources, and impact on the mission NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization NIST-CSF-PR.AA-03 Users, services, and hardware are authenticated NIST-CSF-PR.AA-04 Identity assertions are protected, conveyed, and verified NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties NIST-CSF-PR.AA-06 Physical access to assets is managed, monitored, and enforced commensurate with risk NIST-CSF-PR.DS-01 The confidentiality, integrity, and availability of data-at-rest are protected NIST-CSF-PR.IR-01 Networks and environments are protected from unauthorized logical access and usage NIST-CSF-PR.PS-05 Installation and execution of unauthorized software are prevented ANSSI-HYG-07 Authorise Network Connection Only for Managed Equipment ANSSI-HYG-08 Identify Each Person by Name and Separate User and Administrator Roles ANSSI-HYG-09 Assign the Correct Rights on Sensitive Resources ANSSI-HYG-10 Define and Verify Password Selection and Sizing Rules ANSSI-HYG-11 Protect Passwords Stored on Systems ANSSI-HYG-12 Change Default Authentication Elements on Equipment and Services ANSSI-HYG-13 Prefer Strong Authentication Where Possible ANSSI-HYG-33 Adopt Security Policies Dedicated to Mobile Terminals ASD37-18 Restrict administrative privileges (Essential) ASD37-20 Multi-factor authentication (Essential) ASD37-22 Network segmentation (Excellent) ASD37-23 Protect authentication credentials (Excellent) 3.1.2e Restrict Access to Organization-Owned, Provisioned, or Issued Information Resources 3.13.1e Create Diversity in System Components to Limit Malicious Code Propagation 3.13.2e Introduce Unpredictability into System Operations 3.5.3e Prohibit Connection of Unknown or Unverified System Components CE-AC.2 Authenticate Users Before Granting Access CE-AC.4 Privileged Account Approval and Tracking CE-FW.1 Boundary Firewalls Deployed CE-SC.6 Multi-Factor Authentication for Cloud Services E8-ADMIN-ML1 Restrict Administrative Privileges (ML1) E8-MFA-ML2 Multi-Factor Authentication - Maturity Level 2 E8-MFA-ML3 Multi-Factor Authentication - Maturity Level 3 A.4.5 System and computing resources A.6 AI system life cycle A.9 Use of AI systems Art.21.2.h Policies and procedures on the use of cryptography and, where appropriate, encryption Art.21.2.i Human resources security, access control policies and asset management Art.21.2.j Multi-factor or continuous authentication, secured communications and secured emergency communications APPI-A23 Security Control Measures APPI-A46 Security and Proper Handling of Anonymized Personal Information AUCDR-IS-1 Limit risk of unauthorised access to the CDR data environment AUCDR-IS-2 Secure the network and systems within the data environment 27011-7.1 Physical security perimeters 27011-7.3 Equipment protection SEMD-PS-1 Critical Infrastructure Protection SEMD-PS-2 Site Security Measures 58.43 Animal Care Facilities SOC3-LOGICAL-ACCESS Logical Access CPS234-21 Implementation of Information Security Controls AWWA-2.4 Physical Access Controls AT-DSG-6 Sections 12-13 - Image processing (video surveillance/CCTV) EUAI-Art.59 Further processing of personal data for developing certain AI systems in the public interest in the AI regulatory sandbox CJIS-14 Physical Protection ISO28001-PS-01 Facility Security 27010-11.1 Physical Protection 27400-5.2 IoT Risk Assessment SOC-CY-S1 Logical and Physical Access Controls SSAE18-CC6.4 CC6.4 - Physical Access Restrictions SOCI-CIRMP-PHYSICAL CIRMP hazard vector: Physical security and natural hazards GT-2 Physical Security Threats Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in CC - Common Criteria (Security) You are reading one control. How much of SOC 2 have you already done? SOC 2 SOC2-CC6.1 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of SOC 2 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 49 of 61 SOC 2 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 193 were rejected on the NIST SP 800-53 Rev 5 pair alone.
Query this from an agent The graph holds this control, the 566 it maps to, and the evidence behind each claim, over MCP and REST.