Frameworks / SOC 2 / SOC2-CC6.2 SOC 2
CC - Common Criteria (Security)
SOC 2 SOC2-CC6.2: CC6.2 Registering and authorising users before issuing credentials Before system credentials are issued and access is granted, internal and external users whose access the organisation administers are registered and authorised; their credentials are removed once their access is no longer authorised. Points of focus (2022 revision): every kind of credential, for employees, contractors, vendors, partner staff, systems and software, is issued only after authorisation; credentials are reviewed periodically for continued validity, including inappropriate system or service accounts; and credentials that are no longer valid are disabled, destroyed or otherwise blocked from use.
Maintained by Gerard Blokdyk · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 319 controls across 54 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
AC-14 Permitted Actions Without Identification or Authentication AC-17 Remote Access AC-2 Account Management AC-2(1) Automated System Account Management AC-2(13) Disable Accounts for High-Risk Individuals AC-2(2) Automated Temporary and Emergency Account Management AC-2(3) Disable Accounts AC-2(4) Automated Audit Actions AC-2(7) Privileged User Accounts AC-2(9) Restrictions on Use of Shared and Group Accounts AC-20 Use of External Systems AC-22 Publicly Accessible Content AC-3 Access Enforcement AC-6(1) Authorize Access to Security Functions AC-6(5) Privileged Accounts AC-6(7) Review of User Privileges AU-9(4) Access by Subset of Privileged Users CM-5 Access Restrictions for Change IA-11 Re-Authentication IA-12 Identity Proofing (IA-12) IA-12(2) Identity Proofing | Identity Evidence (IA-12(2)) IA-12(3) Identity Proofing | Identity Evidence Validation and Verification (IA-12(3)) IA-2 Identification and Authentication (Organizational Users) IA-2(1) MFA to Privileged Accounts IA-2(12) Acceptance of PIV Credentials IA-2(2) MFA to Non-Privileged Accounts IA-2(5) Identification and Authentication (Organizational Users) | Individual Authentication with Group Authentication (IA-2(5)) IA-3 Device Identification and Authentication IA-4 Identifier Management IA-4(4) Identifier Management | Identify User Status (IA-4(4)) IA-5 Authenticator Management IA-5(2) Public Key-Based Authentication IA-6 Authentication Feedback IA-8 Identification and Authentication (Non-Organizational Users) IA-8(1) Identification and Authentication (Non-organizational Users) | Acceptance of PIV Credentials from Other Agencies (IA-8(1)) IA-8(2) Identification and Authentication (Non-organizational Users) | Acceptance of External Authenticators (IA-8(2)) IA-8(4) Identification and Authentication (Non-organizational Users) | Use of Defined Profiles (IA-8(4)) IR-9(4) Information Spillage Response | Exposure to Unauthorized Personnel (IR-9(4)) MA-5 Maintenance Personnel MP-2 Media Access PS-3 Personnel Screening PS-3(3) Personnel Screening | Information Requiring Special Protective Measures (PS-3(3)) PS-4 Personnel Termination PS-5 Personnel Transfer PS-6 Access Agreements RA-5(5) Privileged Access AC-14 Permitted Actions Without Identification or Authentication AC-17 Remote Access AC-2 Account Management AC-2(1) Automated System Account Management AC-2(13) Disable Accounts for High-Risk Individuals AC-2(2) Automated Temporary and Emergency Account Management AC-2(3) Disable Accounts AC-2(4) Automated Audit Actions AC-2(7) Privileged User Accounts AC-2(9) Restrictions on Use of Shared and Group Accounts AC-20 Use of External Systems AC-22 Publicly Accessible Content AC-3 Access Enforcement AC-6(1) Authorize Access to Security Functions AC-6(5) Privileged Accounts AC-6(7) Review of User Privileges AU-9(4) Access by Subset of Privileged Users CM-5 Access Restrictions for Change IA-11 Re-Authentication IA-12 Identity Proofing (IA-12) IA-12(2) Identity Proofing | Identity Evidence (IA-12(2)) IA-12(3) Identity Proofing | Identity Evidence Validation and Verification (IA-12(3)) IA-2 Identification and Authentication (Organizational Users) IA-2(1) MFA to Privileged Accounts IA-2(12) Acceptance of PIV Credentials IA-2(2) MFA to Non-Privileged Accounts IA-2(5) Identification and Authentication (Organizational Users) | Individual Authentication with Group Authentication (IA-2(5)) IA-3 Device Identification and Authentication IA-4 Identifier Management IA-4(4) Identifier Management | Identify User Status (IA-4(4)) IA-5 Authenticator Management IA-5(2) Public Key-Based Authentication IA-6 Authentication Feedback IA-8 Identification and Authentication (Non-Organizational Users) IA-8(1) Identification and Authentication (Non-organizational Users) | Acceptance of PIV Credentials from Other Agencies (IA-8(1)) IA-8(2) Identification and Authentication (Non-organizational Users) | Acceptance of External Authenticators (IA-8(2)) IA-8(4) Identification and Authentication (Non-organizational Users) | Use of Defined Profiles (IA-8(4)) IR-9(4) Information Spillage Response | Exposure to Unauthorized Personnel (IR-9(4)) MA-5 Maintenance Personnel MP-2 Media Access PS-3 Personnel Screening PS-3(3) Personnel Screening | Information Requiring Special Protective Measures (PS-3(3)) PS-4 Personnel Termination PS-5 Personnel Transfer PS-6 Access Agreements RA-5(5) Privileged Access 11.4.7 11.4.7 Multi-tenant providers support customer penetration testing 2.2.2 2.2.2 Vendor default accounts managed 3.7.6 3.7.6 Split knowledge and dual control for manual key operations 7.2.1 7.2.1 Access control model defined 7.2.3 7.2.3 Privileges approved by authorized personnel 7.2.5.1 7.2.5.1 Application and system account access reviewed periodically 8.2.1 8.2.1 Unique ID assigned to every user 8.2.2 8.2.2 Shared and generic IDs only by exception 8.2.3 8.2.3 Service provider unique factors per customer 8.2.4 8.2.4 User ID lifecycle changes authorized 8.2.5 8.2.5 Terminated users' access revoked immediately 8.2.6 8.2.6 Inactive accounts removed within 90 days 8.2.7 8.2.7 Third-party remote access accounts controlled 8.3.1 8.3.1 Access authenticated with at least one factor 8.3.11 8.3.11 Tokens, smart cards and certificates individually assigned 8.3.3 8.3.3 Identity verified before factor changes 8.4.1 8.4.1 MFA for non-console administrative CDE access 8.4.2 8.4.2 MFA for all non-console CDE access 8.4.3 8.4.3 MFA for remote access that could reach CDE 8.5.1 8.5.1 MFA system resistant to replay and bypass 9.2.3 9.2.3 Physical protection of network hardware and lines 9.2.4 9.2.4 Locking of consoles in sensitive areas 9.4.1 9.4.1 Physical security of all media 7.2.4 7.2.4 User accounts and privileges reviewed every six months 7.3.1 7.3.1 Need-to-know access control system covers all components 8.6.1 8.6.1 Interactive use of system accounts controlled CIS-12.5 Centralize Network Authentication, Authorization, and Auditing (AAA) CIS-12.7 Ensure Remote Devices Utilize a VPN and are Connecting to an Enterprise’s AAA Infrastructure CIS-13.5 Manage Access Control for Remote Assets CIS-13.9 Deploy Port-Level Access Control CIS-4.7 Manage Default Accounts on Enterprise Assets and Software CIS-5.1 Establish and Maintain an Inventory of Accounts CIS-5.3 Disable Dormant Accounts CIS-5.5 Establish and Maintain an Inventory of Service Accounts CIS-5.6 Centralize Account Management CIS-6.1 Establish an Access Granting Process CIS-6.2 Establish an Access Revoking Process CIS-6.3 Require MFA for Externally-Exposed Applications CIS-6.5 Require MFA for Administrative Access CIS-6.6 Establish and Maintain an Inventory of Authentication and Authorization Systems CIS-6.7 Centralize Access Control CIS-6.8 Define and Maintain Role-Based Access Control 5.15 Access control 5.16 Identity management 5.17 Authentication information 5.18 Access rights 6.1 Screening 6.5 Responsibilities after termination or change of employment 8.2 Privileged access rights 8.3 Information access restriction 8.4 Access to source code 8.5 Secure authentication 5.15 Access control 5.16 Identity management 5.17 Authentication information 5.18 Access rights 6.5 Responsibilities after termination or change of employment 8.2 Privileged access rights 8.3 Information access restriction NIST-CSF-GV.RR-04 Cybersecurity is included in human resources practices NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization NIST-CSF-PR.AA-02 Identities are proofed and bound to credentials based on the context of interactions NIST-CSF-PR.AA-03 Users, services, and hardware are authenticated NIST-CSF-PR.AA-04 Identity assertions are protected, conveyed, and verified NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties NIST-CSF-PR.IR-01 Networks and environments are protected from unauthorized logical access and usage C5-HR-05 Responsibilities in the event of termination or change of employment C5-IDM-02 Granting and change of user accounts and access rights C5-IDM-03 Locking and withdrawal of user accounts in the event of inactivity or multiple failed logins C5-IDM-04 Withdraw or adjust access rights as the task area changes C5-IDM-06 Privileged access rights C5-PSS-05 Authentication Mechanisms 6.4.1 Prior to employment 6.4.3 Termination and change of employment 6.6 Access control 6.6.1 Business requirements of access control 6.6.2 User access management 6.6.4 System and application access control ANSSI-HYG-05 Maintain an Exhaustive Inventory of Privileged Accounts ANSSI-HYG-06 Organise Joiner, Leaver and Role Change Procedures ANSSI-HYG-08 Identify Each Person by Name and Separate User and Administrator Roles ASBv3-PA-4 Review and reconcile user access regularly IM-3 Manage application identities securely and automatically PA-3 Manage lifecycle of identities and entitlements ASD37-18 Restrict administrative privileges (Essential) ASD37-20 Multi-factor authentication (Essential) AWWA-1.3 Security Awareness and Training AWWA-2.1 User Access Management MYHR-REG-11 Ensuring required information is given to the System Operator MYHR-SEC-2 Access controls and user account management SSAE18-CC6.2 CC6.2 - New User Registration and Authorization SSAE18-SOC1-06 Transaction Processing Controls SAM-1 Customer Information Confidentiality (Section 48) SAM-6 Legal Authorization Requirements CE-AC.1 User Account Approval Process CE-AC.3 Remove or Disable Accounts When No Longer Required E8-ADMIN-ML1 Restrict Administrative Privileges (ML1) SOC3-LOGICAL-ACCESS Logical Access AUCDR-IS-1 Limit risk of unauthorised access to the CDR data environment BSI-02 Access enforcement and least privilege DSO-3 Data Access Management CAT-IRP-4 Organizational characteristics 62351-8 Role-based access control (RBAC) ISO-19650-2-5.7 Information model delivery ISO27799-01 ePHI access controls and authorization 27011-8.1 User Endpoint Devices ISO27043-14 Privileged access management 27400-6.1 Secure Device Design ISO21434-14 Privileged access management Art.21.2.i Human resources security, access control policies and asset management NIST190-08 Privileged access in cloud environments SOCI-CIRMP-SUPPLY CIRMP hazard vector: Supply chain ISMSP-AC-01 Access Control Policy UK-TSA-NET-02 Access Control and Authentication ACE-CR-4 Cargo Release Authorization UGA-10 Sensitive Personal Data Prohibition Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in CC - Common Criteria (Security) You are reading one control. How much of SOC 2 have you already done? SOC 2 SOC2-CC6.2 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of SOC 2 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 49 of 61 SOC 2 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 193 were rejected on the NIST SP 800-53 Rev 5 pair alone.
Query this from an agent The graph holds this control, the 319 it maps to, and the evidence behind each claim, over MCP and REST.