SOC 2
CC - Common Criteria (Security)

SOC 2 SOC2-CC6.2: CC6.2 Registering and authorising users before issuing credentials

Before system credentials are issued and access is granted, internal and external users whose access the organisation administers are registered and authorised; their credentials are removed once their access is no longer authorised. Points of focus (2022 revision): every kind of credential, for employees, contractors, vendors, partner staff, systems and software, is issued only after authorisation; credentials are reviewed periodically for continued validity, including inappropriate system or service accounts; and credentials that are no longer valid are disabled, destroyed or otherwise blocked from use.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 319 controls across 54 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

FedRAMP High · 46 controls

  • AC-14 Permitted Actions Without Identification or Authentication
  • AC-17 Remote Access
  • AC-2 Account Management
  • AC-2(1) Automated System Account Management
  • AC-2(13) Disable Accounts for High-Risk Individuals
  • AC-2(2) Automated Temporary and Emergency Account Management
  • AC-2(3) Disable Accounts
  • AC-2(4) Automated Audit Actions
  • AC-2(7) Privileged User Accounts
  • AC-2(9) Restrictions on Use of Shared and Group Accounts
  • AC-20 Use of External Systems
  • AC-22 Publicly Accessible Content
  • AC-3 Access Enforcement
  • AC-6(1) Authorize Access to Security Functions
  • AC-6(5) Privileged Accounts
  • AC-6(7) Review of User Privileges
  • AU-9(4) Access by Subset of Privileged Users
  • CM-5 Access Restrictions for Change
  • IA-11 Re-Authentication
  • IA-12 Identity Proofing (IA-12)
  • IA-12(2) Identity Proofing | Identity Evidence (IA-12(2))
  • IA-12(3) Identity Proofing | Identity Evidence Validation and Verification (IA-12(3))
  • IA-2 Identification and Authentication (Organizational Users)
  • IA-2(1) MFA to Privileged Accounts
  • IA-2(12) Acceptance of PIV Credentials
  • IA-2(2) MFA to Non-Privileged Accounts
  • IA-2(5) Identification and Authentication (Organizational Users) | Individual Authentication with Group Authentication (IA-2(5))
  • IA-3 Device Identification and Authentication
  • IA-4 Identifier Management
  • IA-4(4) Identifier Management | Identify User Status (IA-4(4))
  • IA-5 Authenticator Management
  • IA-5(2) Public Key-Based Authentication
  • IA-6 Authentication Feedback
  • IA-8 Identification and Authentication (Non-Organizational Users)
  • IA-8(1) Identification and Authentication (Non-organizational Users) | Acceptance of PIV Credentials from Other Agencies (IA-8(1))
  • IA-8(2) Identification and Authentication (Non-organizational Users) | Acceptance of External Authenticators (IA-8(2))
  • IA-8(4) Identification and Authentication (Non-organizational Users) | Use of Defined Profiles (IA-8(4))
  • IR-9(4) Information Spillage Response | Exposure to Unauthorized Personnel (IR-9(4))
  • MA-5 Maintenance Personnel
  • MP-2 Media Access
  • PS-3 Personnel Screening
  • PS-3(3) Personnel Screening | Information Requiring Special Protective Measures (PS-3(3))
  • PS-4 Personnel Termination
  • PS-5 Personnel Transfer
  • PS-6 Access Agreements
  • RA-5(5) Privileged Access

FedRAMP Moderate · 46 controls

  • AC-14 Permitted Actions Without Identification or Authentication
  • AC-17 Remote Access
  • AC-2 Account Management
  • AC-2(1) Automated System Account Management
  • AC-2(13) Disable Accounts for High-Risk Individuals
  • AC-2(2) Automated Temporary and Emergency Account Management
  • AC-2(3) Disable Accounts
  • AC-2(4) Automated Audit Actions
  • AC-2(7) Privileged User Accounts
  • AC-2(9) Restrictions on Use of Shared and Group Accounts
  • AC-20 Use of External Systems
  • AC-22 Publicly Accessible Content
  • AC-3 Access Enforcement
  • AC-6(1) Authorize Access to Security Functions
  • AC-6(5) Privileged Accounts
  • AC-6(7) Review of User Privileges
  • AU-9(4) Access by Subset of Privileged Users
  • CM-5 Access Restrictions for Change
  • IA-11 Re-Authentication
  • IA-12 Identity Proofing (IA-12)
  • IA-12(2) Identity Proofing | Identity Evidence (IA-12(2))
  • IA-12(3) Identity Proofing | Identity Evidence Validation and Verification (IA-12(3))
  • IA-2 Identification and Authentication (Organizational Users)
  • IA-2(1) MFA to Privileged Accounts
  • IA-2(12) Acceptance of PIV Credentials
  • IA-2(2) MFA to Non-Privileged Accounts
  • IA-2(5) Identification and Authentication (Organizational Users) | Individual Authentication with Group Authentication (IA-2(5))
  • IA-3 Device Identification and Authentication
  • IA-4 Identifier Management
  • IA-4(4) Identifier Management | Identify User Status (IA-4(4))
  • IA-5 Authenticator Management
  • IA-5(2) Public Key-Based Authentication
  • IA-6 Authentication Feedback
  • IA-8 Identification and Authentication (Non-Organizational Users)
  • IA-8(1) Identification and Authentication (Non-organizational Users) | Acceptance of PIV Credentials from Other Agencies (IA-8(1))
  • IA-8(2) Identification and Authentication (Non-organizational Users) | Acceptance of External Authenticators (IA-8(2))
  • IA-8(4) Identification and Authentication (Non-organizational Users) | Use of Defined Profiles (IA-8(4))
  • IR-9(4) Information Spillage Response | Exposure to Unauthorized Personnel (IR-9(4))
  • MA-5 Maintenance Personnel
  • MP-2 Media Access
  • PS-3 Personnel Screening
  • PS-3(3) Personnel Screening | Information Requiring Special Protective Measures (PS-3(3))
  • PS-4 Personnel Termination
  • PS-5 Personnel Transfer
  • PS-6 Access Agreements
  • RA-5(5) Privileged Access

NIST SP 800-53 Rev 5 · 30 controls

PCI DSS 4.0 · 26 controls

  • 11.4.7 11.4.7 Multi-tenant providers support customer penetration testing
  • 2.2.2 2.2.2 Vendor default accounts managed
  • 3.7.6 3.7.6 Split knowledge and dual control for manual key operations
  • 7.2.1 7.2.1 Access control model defined
  • 7.2.3 7.2.3 Privileges approved by authorized personnel
  • 7.2.5.1 7.2.5.1 Application and system account access reviewed periodically
  • 8.2.1 8.2.1 Unique ID assigned to every user
  • 8.2.2 8.2.2 Shared and generic IDs only by exception
  • 8.2.3 8.2.3 Service provider unique factors per customer
  • 8.2.4 8.2.4 User ID lifecycle changes authorized
  • 8.2.5 8.2.5 Terminated users' access revoked immediately
  • 8.2.6 8.2.6 Inactive accounts removed within 90 days
  • 8.2.7 8.2.7 Third-party remote access accounts controlled
  • 8.3.1 8.3.1 Access authenticated with at least one factor
  • 8.3.11 8.3.11 Tokens, smart cards and certificates individually assigned
  • 8.3.3 8.3.3 Identity verified before factor changes
  • 8.4.1 8.4.1 MFA for non-console administrative CDE access
  • 8.4.2 8.4.2 MFA for all non-console CDE access
  • 8.4.3 8.4.3 MFA for remote access that could reach CDE
  • 8.5.1 8.5.1 MFA system resistant to replay and bypass
  • 9.2.3 9.2.3 Physical protection of network hardware and lines
  • 9.2.4 9.2.4 Locking of consoles in sensitive areas
  • 9.4.1 9.4.1 Physical security of all media
  • 7.2.4 7.2.4 User accounts and privileges reviewed every six months
  • 7.3.1 7.3.1 Need-to-know access control system covers all components
  • 8.6.1 8.6.1 Interactive use of system accounts controlled

CIS Controls v8 · 16 controls

  • CIS-12.5 Centralize Network Authentication, Authorization, and Auditing (AAA)
  • CIS-12.7 Ensure Remote Devices Utilize a VPN and are Connecting to an Enterprise’s AAA Infrastructure
  • CIS-13.5 Manage Access Control for Remote Assets
  • CIS-13.9 Deploy Port-Level Access Control
  • CIS-4.7 Manage Default Accounts on Enterprise Assets and Software
  • CIS-5.1 Establish and Maintain an Inventory of Accounts
  • CIS-5.3 Disable Dormant Accounts
  • CIS-5.5 Establish and Maintain an Inventory of Service Accounts
  • CIS-5.6 Centralize Account Management
  • CIS-6.1 Establish an Access Granting Process
  • CIS-6.2 Establish an Access Revoking Process
  • CIS-6.3 Require MFA for Externally-Exposed Applications
  • CIS-6.5 Require MFA for Administrative Access
  • CIS-6.6 Establish and Maintain an Inventory of Authentication and Authorization Systems
  • CIS-6.7 Centralize Access Control
  • CIS-6.8 Define and Maintain Role-Based Access Control

CMMC 2.0 · 15 controls

HIPAA Security Rule · 12 controls

NIST SP 800-66 Rev 2 · 12 controls

ISO 27001:2022 · 10 controls

  • 5.15 Access control
  • 5.16 Identity management
  • 5.17 Authentication information
  • 5.18 Access rights
  • 6.1 Screening
  • 6.5 Responsibilities after termination or change of employment
  • 8.2 Privileged access rights
  • 8.3 Information access restriction
  • 8.4 Access to source code
  • 8.5 Secure authentication

ISO 27002:2022 · 7 controls

  • 5.15 Access control
  • 5.16 Identity management
  • 5.17 Authentication information
  • 5.18 Access rights
  • 6.5 Responsibilities after termination or change of employment
  • 8.2 Privileged access rights
  • 8.3 Information access restriction
  • NIST-CSF-GV.RR-04 Cybersecurity is included in human resources practices
  • NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization
  • NIST-CSF-PR.AA-02 Identities are proofed and bound to credentials based on the context of interactions
  • NIST-CSF-PR.AA-03 Users, services, and hardware are authenticated
  • NIST-CSF-PR.AA-04 Identity assertions are protected, conveyed, and verified
  • NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
  • NIST-CSF-PR.IR-01 Networks and environments are protected from unauthorized logical access and usage

C5 (Germany) · 6 controls

  • C5-HR-05 Responsibilities in the event of termination or change of employment
  • C5-IDM-02 Granting and change of user accounts and access rights
  • C5-IDM-03 Locking and withdrawal of user accounts in the event of inactivity or multiple failed logins
  • C5-IDM-04 Withdraw or adjust access rights as the task area changes
  • C5-IDM-06 Privileged access rights
  • C5-PSS-05 Authentication Mechanisms

ISO 27701:2019 · 6 controls

  • 6.4.1 Prior to employment
  • 6.4.3 Termination and change of employment
  • 6.6 Access control
  • 6.6.1 Business requirements of access control
  • 6.6.2 User access management
  • 6.6.4 System and application access control

NIST SP 800-171 Rev 3 · 4 controls

  • ANSSI-HYG-05 Maintain an Exhaustive Inventory of Privileged Accounts
  • ANSSI-HYG-06 Organise Joiner, Leaver and Role Change Procedures
  • ANSSI-HYG-08 Identify Each Person by Name and Separate User and Administrator Roles
  • ASBv3-PA-4 Review and reconcile user access regularly
  • IM-3 Manage application identities securely and automatically
  • PA-3 Manage lifecycle of identities and entitlements

NIST SP 800-161 Rev 1 · 3 controls

  • ASD37-18 Restrict administrative privileges (Essential)
  • ASD37-20 Multi-factor authentication (Essential)
  • AWWA-1.3 Security Awareness and Training
  • AWWA-2.1 User Access Management
  • MYHR-REG-11 Ensuring required information is given to the System Operator
  • MYHR-SEC-2 Access controls and user account management
  • SSAE18-CC6.2 CC6.2 - New User Registration and Authorization
  • SSAE18-SOC1-06 Transaction Processing Controls
  • SAM-1 Customer Information Confidentiality (Section 48)
  • SAM-6 Legal Authorization Requirements

UK Cyber Essentials · 2 controls

  • CE-AC.1 User Account Approval Process
  • CE-AC.3 Remove or Disable Accounts When No Longer Required
  • E8-ADMIN-ML1 Restrict Administrative Privileges (ML1)

AICPA SOC 3 · 1 control

  • SOC3-LOGICAL-ACCESS Logical Access
  • AUCDR-IS-1 Limit risk of unauthorised access to the CDR data environment

BSI IT-Grundschutz · 1 control

  • BSI-02 Access enforcement and least privilege
  • DSO-3 Data Access Management

DORA · 1 control

  • CAT-IRP-4 Organizational characteristics
  • 62351-8 Role-based access control (RBAC)

ISO 27799:2025 · 1 control

  • ISO27799-01 ePHI access controls and authorization

ISO/IEC 27011:2024 · 1 control

  • 27011-8.1 User Endpoint Devices

ISO/IEC 27043:2015 · 1 control

  • ISO27043-14 Privileged access management

ISO/IEC 27400:2022 · 1 control

  • 27400-6.1 Secure Device Design

ISO/SAE 21434 · 1 control

  • ISO21434-14 Privileged access management

NIS2 Directive · 1 control

  • Art.21.2.i Human resources security, access control policies and asset management

NIST SP 800-190 · 1 control

  • NIST190-08 Privileged access in cloud environments
  • SOCI-CIRMP-SUPPLY CIRMP hazard vector: Supply chain

South Korea ISMS-P · 1 control

  • ISMSP-AC-01 Access Control Policy
  • UK-TSA-NET-02 Access Control and Authentication
  • ACE-CR-4 Cargo Release Authorization
  • UGA-10 Sensitive Personal Data Prohibition

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in CC - Common Criteria (Security)

You are reading one control. How much of SOC 2 have you already done?

SOC 2 SOC2-CC6.2 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of SOC 2 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 49 of 61 SOC 2 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 193 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 319 it maps to, and the evidence behind each claim, over MCP and REST.