SOC 2
CC - Common Criteria (Security)

SOC 2 SOC2-CC6.1: CC6.1 Logical access security over protected information assets

Access security software, infrastructure and architecture are in place over protected information assets to guard them against security events. Points of focus: information assets are inventoried, classified and managed; logical access to hardware, data at rest, in processing and in transit, software, admin rights, mobile devices, output and offline components is limited through access control software and rules; users, devices and software prove who they are before they get in, locally or remotely; networks are segmented so unrelated parts are isolated; external points of access and the data and users passing through them are inventoried and managed; access rules combine classification, data separation, port and protocol limits, identity and certificates; identification and authentication requirements are defined and managed; new infrastructure and software are registered and authorised before receiving credentials, which are removed when no longer needed; encryption protects data at rest where risk warrants; and keys are protected from generation to destruction. The 2022 revision adds: new system architectures are security-assessed before they go live; restricted components expressly include servers, storage, network elements, APIs and endpoints, with standard hardening applied; stronger authentication such as multifactor is used where the risk strategy calls for it; isolation may use zero trust designs and other techniques beyond network segmentation; cryptographic modules, algorithms, key lengths and designs suit the risk strategy; and, where confidentiality or privacy is in scope, access to confidential or personal information is limited to the purposes identified and to personnel who need it.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 566 controls across 48 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

PCI DSS 4.0 · 85 controls

  • 1.2.1 1.2.1 Ruleset configuration standards for NSCs
  • 1.2.4 1.2.4 Accurate data-flow diagram for account data
  • 1.2.5 1.2.5 Allowed services, protocols and ports justified
  • 1.2.8 1.2.8 NSC configuration files secured and consistent
  • 1.4.4 1.4.4 Cardholder data stores not reachable from untrusted networks
  • 1.4.5 1.4.5 Internal IP and routing disclosure limited
  • 10.1.1 10.1.1 Requirement 10 policies and procedures maintained and in use
  • 10.1.2 10.1.2 Roles for logging and monitoring assigned and understood
  • 10.2.1.1 10.2.1.1 Logs capture individual user access to cardholder data
  • 10.2.1.2 10.2.1.2 Logs capture all administrative actions
  • 10.2.1.3 10.2.1.3 Access to the audit logs is itself logged
  • 10.2.1.4 10.2.1.4 Logs capture invalid logical access attempts
  • 10.2.1.5 10.2.1.5 Logs capture changes to identification and authentication credentials
  • 10.2.1.7 10.2.1.7 Logs capture creation and deletion of system-level objects
  • 10.2.2 10.2.2 Required details recorded for each auditable event
  • 10.3.1 10.3.1 Audit log read access limited to job need
  • 10.3.2 10.3.2 Audit log files protected from modification
  • 10.6.3 10.6.3 Time sync configuration and time data protected
  • 11.2.2 11.2.2 Inventory of authorized wireless access points
  • 11.4.7 11.4.7 Multi-tenant providers support customer penetration testing
  • 12.3.3 12.3.3 Cryptographic cipher suite and protocol inventory reviewed annually
  • 12.4.1 12.4.1 Executive responsibility for a PCI DSS compliance program
  • 12.5.1 12.5.1 Inventory of in-scope system components
  • 2.2.1 2.2.1 System configuration standards maintained
  • 2.2.2 2.2.2 Vendor default accounts managed
  • 2.2.3 2.2.3 Primary functions with different security levels managed
  • 2.2.4 2.2.4 Only necessary functionality enabled
  • 2.2.5 2.2.5 Insecure services, protocols or daemons secured
  • 2.2.6 2.2.6 System security parameters configured against misuse
  • 2.2.7 2.2.7 Non-console administrative access encrypted
  • 2.3.1 2.3.1 Wireless vendor defaults changed or confirmed secure
  • 2.3.2 2.3.2 Wireless encryption keys changed on triggers
  • 3.3.3 3.3.3 Issuer SAD storage limited, justified and encrypted
  • 3.4.2 3.4.2 Remote access blocks copying or relocating PAN
  • 3.5.1.1 3.5.1.1 PAN hashes are keyed cryptographic hashes
  • 3.5.1.2 3.5.1.2 Disk or partition encryption only on removable media
  • 3.5.1.3 3.5.1.3 Disk encryption access independent of OS authentication
  • 3.6.1.1 3.6.1.1 Service provider cryptographic architecture documented
  • 3.6.1.2 3.6.1.2 Permitted storage forms for secret and private keys
  • 3.6.1.3 3.6.1.3 Cleartext key component access limited to minimum custodians
  • 3.6.1.4 3.6.1.4 Cryptographic keys kept in fewest locations
  • 3.7.2 3.7.2 Secure distribution of cryptographic keys
  • 3.7.3 3.7.3 Secure storage of cryptographic keys
  • 3.7.6 3.7.6 Split knowledge and dual control for manual key operations
  • 3.7.7 3.7.7 Prevent unauthorized substitution of keys
  • 3.7.9 3.7.9 Key guidance for service provider customers
  • 4.2.1 4.2.1 Strong cryptography safeguards PAN over public networks
  • 4.2.1.1 4.2.1.1 Inventory of trusted transmission keys and certificates
  • 4.2.1.2 4.2.1.2 Wireless networks use strong cryptography
  • 6.2.3.1 6.2.3.1 Manual code review independence and approval
  • 6.5.5 6.5.5 No live PANs in pre-production
  • 7.2.1 7.2.1 Access control model defined
  • 7.3.2 7.3.2 Access control system enforces role-based permissions
  • 7.3.3 7.3.3 Access control default deny all
  • 8.2.2 8.2.2 Shared and generic IDs only by exception
  • 8.2.3 8.2.3 Service provider unique factors per customer
  • 8.2.5 8.2.5 Terminated users' access revoked immediately
  • 8.2.6 8.2.6 Inactive accounts removed within 90 days
  • 8.2.8 8.2.8 Re-authentication after 15 minutes idle
  • 8.3.1 8.3.1 Access authenticated with at least one factor
  • 8.3.10 8.3.10 Service provider customer password guidance
  • 8.3.10.1 8.3.10.1 Service provider customer passwords 90 days or dynamic
  • 8.3.11 8.3.11 Tokens, smart cards and certificates individually assigned
  • 8.3.2 8.3.2 Authentication factors unreadable with strong cryptography
  • 8.3.4 8.3.4 Lockout after 10 attempts for 30 minutes
  • 8.3.5 8.3.5 Initial and reset passwords unique and changed
  • 8.3.6 8.3.6 Password minimum length 12 and complexity
  • 8.3.7 8.3.7 No reuse of last four passwords
  • 8.3.9 8.3.9 Single-factor passwords changed every 90 days or dynamic analysis
  • 8.4.1 8.4.1 MFA for non-console administrative CDE access
  • 8.4.2 8.4.2 MFA for all non-console CDE access
  • 8.4.3 8.4.3 MFA for remote access that could reach CDE
  • 8.5.1 8.5.1 MFA system resistant to replay and bypass
  • 9.2.4 9.2.4 Locking of consoles in sensitive areas
  • 9.4.1 9.4.1 Physical security of all media
  • 9.4.4 9.4.4 Management approval for media leaving facility
  • 9.5.1.1 9.5.1.1 Current register of POI devices
  • 3.4.1 3.4.1 PAN masked on display except for authorized roles
  • 3.7.1 3.7.1 Generation of strong cryptographic keys
  • 6.5.3 6.5.3 Separate pre-production from production
  • 7.2.5 7.2.5 Application and system accounts least privilege
  • 7.3.1 7.3.1 Need-to-know access control system covers all components
  • 8.6.1 8.6.1 Interactive use of system accounts controlled
  • 8.6.2 8.6.2 No hard-coded passwords for interactive system accounts
  • 8.6.3 8.6.3 System account passwords protected against misuse

FedRAMP High · 63 controls

  • AC-11 Device Lock
  • AC-11(1) Device Lock | Pattern-hiding Displays (AC-11(1))
  • AC-12 Session Termination
  • AC-17 Remote Access
  • AC-17(2) Protection of Confidentiality and Integrity Using Encryption
  • AC-17(3) Managed Access Control Points
  • AC-18(1) Authentication and Encryption
  • AC-18(3) Wireless Access | Disable Wireless Networking (AC-18(3))
  • AC-19 Access Control for Mobile Devices
  • AC-19(5) Full Device or Container-Based Encryption
  • AC-2 Account Management
  • AC-2(13) Disable Accounts for High-Risk Individuals
  • AC-2(5) Inactivity Logout
  • AC-2(7) Privileged User Accounts
  • AC-2(9) Restrictions on Use of Shared and Group Accounts
  • AC-20(2) Portable Storage Devices Restricted Use
  • AC-3 Access Enforcement
  • AC-7 Unsuccessful Logon Attempts
  • AU-3(1) Additional Audit Information
  • AU-9 Protection of Audit Information
  • CA-9 Internal System Connections
  • CM-12 Information Location (CM-12)
  • CM-12(1) Information Location | Automated Tools to Support Information Location (CM-12(1))
  • CM-5(1) Access Restrictions for Change | Automated Access Enforcement and Audit Records (CM-5(1))
  • CM-7 Least Functionality
  • CM-7(1) Periodic Review
  • CP-9(8) System Backup | Cryptographic Protection (CP-9(8))
  • IA-2 Identification and Authentication (Organizational Users)
  • IA-2(1) MFA to Privileged Accounts
  • IA-2(12) Acceptance of PIV Credentials
  • IA-2(2) MFA to Non-Privileged Accounts
  • IA-2(6) Identification and Authentication (Organizational Users) | Access to Accounts: separate Device (IA-2(6))
  • IA-2(8) Access to Accounts Replay Resistant
  • IA-5 Authenticator Management
  • IA-5(1) Password-Based Authentication
  • IA-5(6) Protection of Authenticators
  • IA-5(7) Authenticator Management | No Embedded Unencrypted Static Authenticators (IA-5(7))
  • IA-6 Authentication Feedback
  • IA-7 Cryptographic Module Authentication
  • IA-8 Identification and Authentication (Non-Organizational Users)
  • IA-8(1) Identification and Authentication (Non-organizational Users) | Acceptance of PIV Credentials from Other Agencies (IA-8(1))
  • IA-8(2) Identification and Authentication (Non-organizational Users) | Acceptance of External Authenticators (IA-8(2))
  • MA-4 Nonlocal Maintenance
  • MP-2 Media Access
  • PL-8 Security and Privacy Architectures
  • PS-4 Personnel Termination
  • PS-5 Personnel Transfer
  • RA-5(5) Privileged Access
  • RA-9 Criticality Analysis (RA-9)
  • SA-8 Security and Privacy Engineering Principles
  • SA-9(2) Identification of Functions, Ports, Protocols, and Services
  • SC-10 Network Disconnect
  • SC-12 Cryptographic Key Establishment and Management
  • SC-13 Cryptographic Protection
  • SC-15 Collaborative Computing Devices and Applications
  • SC-22 Architecture and Provisioning for Name/Address Resolution Service
  • SC-23 Session Authenticity
  • SC-28(1) Cryptographic Protection
  • SC-39 Process Isolation
  • SC-4 Information in Shared System Resources
  • SC-7 Boundary Protection
  • SC-7(5) Deny by Default Allow by Exception
  • SI-11 Error Handling

FedRAMP Moderate · 63 controls

  • AC-11 Device Lock
  • AC-11(1) Device Lock | Pattern-hiding Displays (AC-11(1))
  • AC-12 Session Termination
  • AC-17 Remote Access
  • AC-17(2) Protection of Confidentiality and Integrity Using Encryption
  • AC-17(3) Managed Access Control Points
  • AC-18(1) Authentication and Encryption
  • AC-18(3) Wireless Access | Disable Wireless Networking (AC-18(3))
  • AC-19 Access Control for Mobile Devices
  • AC-19(5) Full Device or Container-Based Encryption
  • AC-2 Account Management
  • AC-2(13) Disable Accounts for High-Risk Individuals
  • AC-2(5) Inactivity Logout
  • AC-2(7) Privileged User Accounts
  • AC-2(9) Restrictions on Use of Shared and Group Accounts
  • AC-20(2) Portable Storage Devices Restricted Use
  • AC-3 Access Enforcement
  • AC-7 Unsuccessful Logon Attempts
  • AU-3(1) Additional Audit Information
  • AU-9 Protection of Audit Information
  • CA-9 Internal System Connections
  • CM-12 Information Location (CM-12)
  • CM-12(1) Information Location | Automated Tools to Support Information Location (CM-12(1))
  • CM-5(1) Access Restrictions for Change | Automated Access Enforcement and Audit Records (CM-5(1))
  • CM-7 Least Functionality
  • CM-7(1) Periodic Review
  • CP-9(8) System Backup | Cryptographic Protection (CP-9(8))
  • IA-2 Identification and Authentication (Organizational Users)
  • IA-2(1) MFA to Privileged Accounts
  • IA-2(12) Acceptance of PIV Credentials
  • IA-2(2) MFA to Non-Privileged Accounts
  • IA-2(6) Identification and Authentication (Organizational Users) | Access to Accounts: separate Device (IA-2(6))
  • IA-2(8) Access to Accounts Replay Resistant
  • IA-5 Authenticator Management
  • IA-5(1) Password-Based Authentication
  • IA-5(6) Protection of Authenticators
  • IA-5(7) Authenticator Management | No Embedded Unencrypted Static Authenticators (IA-5(7))
  • IA-6 Authentication Feedback
  • IA-7 Cryptographic Module Authentication
  • IA-8 Identification and Authentication (Non-Organizational Users)
  • IA-8(1) Identification and Authentication (Non-organizational Users) | Acceptance of PIV Credentials from Other Agencies (IA-8(1))
  • IA-8(2) Identification and Authentication (Non-organizational Users) | Acceptance of External Authenticators (IA-8(2))
  • MA-4 Nonlocal Maintenance
  • MP-2 Media Access
  • PL-8 Security and Privacy Architectures
  • PS-4 Personnel Termination
  • PS-5 Personnel Transfer
  • RA-5(5) Privileged Access
  • RA-9 Criticality Analysis (RA-9)
  • SA-8 Security and Privacy Engineering Principles
  • SA-9(2) Identification of Functions, Ports, Protocols, and Services
  • SC-10 Network Disconnect
  • SC-12 Cryptographic Key Establishment and Management
  • SC-13 Cryptographic Protection
  • SC-15 Collaborative Computing Devices and Applications
  • SC-22 Architecture and Provisioning for Name/Address Resolution Service
  • SC-23 Session Authenticity
  • SC-28(1) Cryptographic Protection
  • SC-39 Process Isolation
  • SC-4 Information in Shared System Resources
  • SC-7 Boundary Protection
  • SC-7(5) Deny by Default Allow by Exception
  • SI-11 Error Handling

NIST SP 800-53 Rev 5 · 56 controls

CMMC 2.0 · 43 controls

CIS Controls v8 · 38 controls

  • CIS-1.1 Establish and Maintain Detailed Enterprise Asset Inventory
  • CIS-1.3 Utilize an Active Discovery Tool
  • CIS-1.4 Use Dynamic Host Configuration Protocol (DHCP) Logging to Update Enterprise Asset Inventory
  • CIS-1.5 Use a Passive Asset Discovery Tool
  • CIS-12.2 Establish and Maintain a Secure Network Architecture
  • CIS-12.3 Securely Manage Network Infrastructure
  • CIS-12.4 Establish and Maintain Architecture Diagram(s)
  • CIS-12.5 Centralize Network Authentication, Authorization, and Auditing (AAA)
  • CIS-12.6 Use of Secure Network Management and Communication Protocols
  • CIS-12.7 Ensure Remote Devices Utilize a VPN and are Connecting to an Enterprise’s AAA Infrastructure
  • CIS-12.8 Establish and Maintain Dedicated Computing Resources for All Administrative Work
  • CIS-13.5 Manage Access Control for Remote Assets
  • CIS-13.9 Deploy Port-Level Access Control
  • CIS-14.3 Train Workforce Members on Authentication Best Practices
  • CIS-16.10 Apply Secure Design Principles in Application Architectures
  • CIS-16.11 Leverage Vetted Modules or Services for Application Security Components
  • CIS-3.3 Configure Data Access Control Lists
  • CIS-3.6 Encrypt Data on End-User Devices
  • CIS-4.10 Enforce Automatic Device Lockout on Portable End-User Devices
  • CIS-4.12 Separate Enterprise Workspaces on Mobile End-User Devices
  • CIS-4.3 Configure Automatic Session Locking on Enterprise Assets
  • CIS-4.4 Implement and Manage a Firewall on Servers
  • CIS-4.6 Securely Manage Enterprise Assets and Software
  • CIS-4.7 Manage Default Accounts on Enterprise Assets and Software
  • CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • CIS-5.2 Use Unique Passwords
  • CIS-5.3 Disable Dormant Accounts
  • CIS-5.5 Establish and Maintain an Inventory of Service Accounts
  • CIS-5.6 Centralize Account Management
  • CIS-6.1 Establish an Access Granting Process
  • CIS-6.2 Establish an Access Revoking Process
  • CIS-6.3 Require MFA for Externally-Exposed Applications
  • CIS-6.4 Require MFA for Remote Network Access
  • CIS-6.5 Require MFA for Administrative Access
  • CIS-6.6 Establish and Maintain an Inventory of Authentication and Authorization Systems
  • CIS-6.7 Centralize Access Control
  • CIS-6.8 Define and Maintain Role-Based Access Control
  • CIS-8.5 Collect Detailed Audit Logs

ISO 27001:2022 · 30 controls

  • 5.10 Acceptable use of information and other associated assets
  • 5.11 Return of assets
  • 5.15 Access control
  • 5.16 Identity management
  • 5.17 Authentication information
  • 5.18 Access rights
  • 5.23 Information security for use of cloud services
  • 5.33 Protection of records
  • 5.9 Inventory of information and other associated assets
  • 6.5 Responsibilities after termination or change of employment
  • 6.7 Remote working
  • 7.1 Physical security perimeters
  • 7.12 Cabling security
  • 7.2 Physical entry
  • 7.3 Securing offices, rooms and facilities
  • 7.4 Physical security monitoring
  • 7.6 Working in secure areas
  • 7.7 Clear desk and clear screen
  • 7.9 Security of assets off-premises
  • 8.1 User end point devices
  • 8.18 Use of privileged utility programs
  • 8.2 Privileged access rights
  • 8.20 Networks security
  • 8.21 Security of network services
  • 8.22 Segregation of networks
  • 8.27 Secure system architecture and engineering principles
  • 8.3 Information access restriction
  • 8.31 Separation of development, test and production environments
  • 8.4 Access to source code
  • 8.5 Secure authentication

ISO 27002:2022 · 18 controls

  • 5.15 Access control
  • 5.16 Identity management
  • 5.17 Authentication information
  • 5.18 Access rights
  • 5.23 Information security for use of cloud services
  • 5.32 Intellectual property rights
  • 5.9 Inventory of information and other associated assets
  • 6.7 Remote working
  • 8.1 User endpoint devices
  • 8.15 Logging
  • 8.18 Use of privileged utility programs
  • 8.2 Privileged access rights
  • 8.22 Segregation of networks
  • 8.27 Secure system architecture and engineering principles
  • 8.3 Information access restriction
  • 8.34 Protection of information systems during audit testing
  • 8.4 Access to source code
  • 8.5 Secure authentication

HIPAA Security Rule · 17 controls

C5 (Germany) · 16 controls

  • C5-AM-01 Asset Inventory
  • C5-COS-01 Technical safeguards
  • C5-COS-07 Documentation of the network topology
  • C5-CRY-01 Policy for the use of encryption procedures and key management
  • C5-CRY-03 Encryption of sensitive data for storage
  • C5-CRY-04 Secure key management
  • C5-DEV-10 Separation of environments
  • C5-IDM-01 Policy for user accounts and access rights
  • C5-IDM-03 Locking and withdrawal of user accounts in the event of inactivity or multiple failed logins
  • C5-IDM-08 Confidentiality of authentication information
  • C5-IDM-09 Authentication mechanisms
  • C5-OPS-12 Logging and Monitoring - Access, Storage and Deletion
  • C5-OPS-14 Logging and Monitoring - Storage of the Logging Data
  • C5-OPS-24 Separation of Datasets in the Cloud Infrastructure
  • C5-PSS-05 Authentication Mechanisms
  • C5-PSS-07 Confidentiality of Authentication Information
  • ASBv3-AM-1 Track asset inventory and their risks
  • ASBv3-DP-5 Use customer-managed key option in data at rest encryption when required
  • ASBv3-DP-6 Use a secure key management process
  • ASBv3-DP-7 Use a secure certificate management process
  • ASBv3-DP-8 Ensure security of key and certificate repository
  • ASBv3-GS-6 Define and implement identity and privileged access strategy
  • ASBv3-IM-2 Protect identity and authentication systems
  • ASBv3-IM-8 Restrict the exposure of credential and secrets
  • ASBv3-PA-7 Follow just enough administration (least privilege) principle
  • BR-2 Protect backup and recovery data
  • DP-4 Enable data at rest encryption by default
  • IM-1 Use centralized identity and authentication system
  • IM-6 Use strong authentication controls
  • IM-7 Restrict resource access based on conditions

NIST SP 800-66 Rev 2 · 14 controls

ISO 27701:2019 · 12 controls

  • 5.5 Support
  • 5.6 Operation
  • 6.3.2 Mobile devices and teleworking
  • 6.5.2 Information classification
  • 6.6 Access control
  • 6.6.1 Business requirements of access control
  • 6.6.2 User access management
  • 6.6.3 User responsibilities
  • 6.6.4 System and application access control
  • 6.7.1 Cryptographic controls
  • 6.9 Operations security
  • 6.9.6 Technical vulnerability management
  • NIST-CSF-ID.AM-02 Inventories of software, services, and systems managed by the organization are maintained
  • NIST-CSF-ID.AM-03 Representations of the organization's authorized network communication and internal and external network data flows are maintained
  • NIST-CSF-ID.AM-05 Assets are prioritized based on classification, criticality, resources, and impact on the mission
  • NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization
  • NIST-CSF-PR.AA-03 Users, services, and hardware are authenticated
  • NIST-CSF-PR.AA-04 Identity assertions are protected, conveyed, and verified
  • NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
  • NIST-CSF-PR.AA-06 Physical access to assets is managed, monitored, and enforced commensurate with risk
  • NIST-CSF-PR.DS-01 The confidentiality, integrity, and availability of data-at-rest are protected
  • NIST-CSF-PR.IR-01 Networks and environments are protected from unauthorized logical access and usage
  • NIST-CSF-PR.PS-05 Installation and execution of unauthorized software are prevented
  • ANSSI-HYG-07 Authorise Network Connection Only for Managed Equipment
  • ANSSI-HYG-08 Identify Each Person by Name and Separate User and Administrator Roles
  • ANSSI-HYG-09 Assign the Correct Rights on Sensitive Resources
  • ANSSI-HYG-10 Define and Verify Password Selection and Sizing Rules
  • ANSSI-HYG-11 Protect Passwords Stored on Systems
  • ANSSI-HYG-12 Change Default Authentication Elements on Equipment and Services
  • ANSSI-HYG-13 Prefer Strong Authentication Where Possible
  • ANSSI-HYG-33 Adopt Security Policies Dedicated to Mobile Terminals

NIST SP 800-171 Rev 3 · 6 controls

  • ASD37-18 Restrict administrative privileges (Essential)
  • ASD37-20 Multi-factor authentication (Essential)
  • ASD37-22 Network segmentation (Excellent)
  • ASD37-23 Protect authentication credentials (Excellent)

NIST SP 800-172 · 4 controls

  • 3.1.2e Restrict Access to Organization-Owned, Provisioned, or Issued Information Resources
  • 3.13.1e Create Diversity in System Components to Limit Malicious Code Propagation
  • 3.13.2e Introduce Unpredictability into System Operations
  • 3.5.3e Prohibit Connection of Unknown or Unverified System Components

UK Cyber Essentials · 4 controls

  • CE-AC.2 Authenticate Users Before Granting Access
  • CE-AC.4 Privileged Account Approval and Tracking
  • CE-FW.1 Boundary Firewalls Deployed
  • CE-SC.6 Multi-Factor Authentication for Cloud Services

ACSC Essential Eight · 3 controls

  • E8-ADMIN-ML1 Restrict Administrative Privileges (ML1)
  • E8-MFA-ML2 Multi-Factor Authentication - Maturity Level 2
  • E8-MFA-ML3 Multi-Factor Authentication - Maturity Level 3

ISO/IEC 42001:2023 · 3 controls

  • A.4.5 System and computing resources
  • A.6 AI system life cycle
  • A.9 Use of AI systems

NIS2 Directive · 3 controls

  • Art.21.2.h Policies and procedures on the use of cryptography and, where appropriate, encryption
  • Art.21.2.i Human resources security, access control policies and asset management
  • Art.21.2.j Multi-factor or continuous authentication, secured communications and secured emergency communications

APPI · 2 controls

  • APPI-A23 Security Control Measures
  • APPI-A46 Security and Proper Handling of Anonymized Personal Information
  • AUCDR-IS-1 Limit risk of unauthorised access to the CDR data environment
  • AUCDR-IS-2 Secure the network and systems within the data environment

DORA · 2 controls

ISO/IEC 27011:2024 · 2 controls

  • 27011-7.1 Physical security perimeters
  • 27011-7.3 Equipment protection
  • SEMD-PS-1 Critical Infrastructure Protection
  • SEMD-PS-2 Site Security Measures
  • 58.43 Animal Care Facilities

AICPA SOC 3 · 1 control

  • SOC3-LOGICAL-ACCESS Logical Access

APRA CPS 234 · 1 control

  • CPS234-21 Implementation of Information Security Controls
  • AT-DSG-6 Sections 12-13 - Image processing (video surveillance/CCTV)

EU AI Act · 1 control

  • EUAI-Art.59 Further processing of personal data for developing certain AI systems in the public interest in the AI regulatory sandbox
  • CJIS-14 Physical Protection

GDPR · 1 control

  • ISO28001-PS-01 Facility Security

ISO/IEC 27010:2015 · 1 control

  • 27010-11.1 Physical Protection

ISO/IEC 27400:2022 · 1 control

  • 27400-5.2 IoT Risk Assessment

NIST SP 800-218 · 1 control

  • SOC-CY-S1 Logical and Physical Access Controls
  • SSAE18-CC6.4 CC6.4 - Physical Access Restrictions
  • SOCI-CIRMP-PHYSICAL CIRMP hazard vector: Physical security and natural hazards

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in CC - Common Criteria (Security)

You are reading one control. How much of SOC 2 have you already done?

SOC 2 SOC2-CC6.1 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of SOC 2 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 49 of 61 SOC 2 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 193 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 566 it maps to, and the evidence behind each claim, over MCP and REST.