Frameworks / SOC 2 / SOC2-CC6.3 SOC 2
CC - Common Criteria (Security)
SOC 2 SOC2-CC6.3: CC6.3 Role-based access, least privilege and segregation of duties Rights over data, programs, functions and other protected assets is granted, changed or removed according to roles, responsibilities or system design and changes, applying least privilege and segregation of duties. Points of focus: access is created or modified on the asset owner's authorisation; it is removed when no longer needed; access structures (role-based, for example) limit privileges and separate incompatible functions; and roles and access rules are reviewed periodically for people who no longer need them (staff, contractors, vendors, partner personnel) and for system or service accounts that should not exist, and adjusted.
Maintained by Gerard Blokdyk · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 496 controls across 85 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
AC-14 Permitted Actions Without Identification or Authentication AC-19 Access Control for Mobile Devices AC-2 Account Management AC-2(1) Automated System Account Management AC-2(2) Automated Temporary and Emergency Account Management AC-2(3) Disable Accounts AC-2(4) Automated Audit Actions AC-2(7) Privileged User Accounts AC-2(9) Restrictions on Use of Shared and Group Accounts AC-20(2) Portable Storage Devices Restricted Use AC-21 Information Sharing AC-22 Publicly Accessible Content AC-3 Access Enforcement AC-5 Separation of Duties AC-6 Least Privilege AC-6(1) Authorize Access to Security Functions AC-6(10) Prohibit Non-Privileged Users from Executing Privileged Functions AC-6(2) Non-Privileged Access for Nonsecurity Functions AC-6(5) Privileged Accounts AC-6(7) Review of User Privileges AC-6(9) Log Use of Privileged Functions AT-3 Role-Based Training AU-9 Protection of Audit Information AU-9(4) Access by Subset of Privileged Users CA-9 Internal System Connections CM-12 Information Location (CM-12) CM-5 Access Restrictions for Change CM-5(1) Access Restrictions for Change | Automated Access Enforcement and Audit Records (CM-5(1)) CM-5(5) Access Restrictions for Change | Privilege Limitation for Production and Operation (CM-5(5)) IA-11 Re-Authentication IA-2(1) MFA to Privileged Accounts IA-2(12) Acceptance of PIV Credentials IA-4 Identifier Management IA-5 Authenticator Management IA-5(2) Public Key-Based Authentication IA-5(6) Protection of Authenticators IA-8(4) Identification and Authentication (Non-organizational Users) | Use of Defined Profiles (IA-8(4)) IR-9(4) Information Spillage Response | Exposure to Unauthorized Personnel (IR-9(4)) MP-2 Media Access PS-4 Personnel Termination PS-5 Personnel Transfer RA-5(5) Privileged Access SC-10 Network Disconnect SC-2 Separation of System and User Functionality SC-39 Process Isolation SC-4 Information in Shared System Resources SC-7(5) Deny by Default Allow by Exception AC-14 Permitted Actions Without Identification or Authentication AC-19 Access Control for Mobile Devices AC-2 Account Management AC-2(1) Automated System Account Management AC-2(2) Automated Temporary and Emergency Account Management AC-2(3) Disable Accounts AC-2(4) Automated Audit Actions AC-2(7) Privileged User Accounts AC-2(9) Restrictions on Use of Shared and Group Accounts AC-20(2) Portable Storage Devices Restricted Use AC-21 Information Sharing AC-22 Publicly Accessible Content AC-3 Access Enforcement AC-5 Separation of Duties AC-6 Least Privilege AC-6(1) Authorize Access to Security Functions AC-6(10) Prohibit Non-Privileged Users from Executing Privileged Functions AC-6(2) Non-Privileged Access for Nonsecurity Functions AC-6(5) Privileged Accounts AC-6(7) Review of User Privileges AC-6(9) Log Use of Privileged Functions AT-3 Role-Based Training AU-9 Protection of Audit Information AU-9(4) Access by Subset of Privileged Users CA-9 Internal System Connections CM-12 Information Location (CM-12) CM-5 Access Restrictions for Change CM-5(1) Access Restrictions for Change | Automated Access Enforcement and Audit Records (CM-5(1)) CM-5(5) Access Restrictions for Change | Privilege Limitation for Production and Operation (CM-5(5)) IA-11 Re-Authentication IA-2(1) MFA to Privileged Accounts IA-2(12) Acceptance of PIV Credentials IA-4 Identifier Management IA-5 Authenticator Management IA-5(2) Public Key-Based Authentication IA-5(6) Protection of Authenticators IA-8(4) Identification and Authentication (Non-organizational Users) | Use of Defined Profiles (IA-8(4)) IR-9(4) Information Spillage Response | Exposure to Unauthorized Personnel (IR-9(4)) MP-2 Media Access PS-4 Personnel Termination PS-5 Personnel Transfer RA-5(5) Privileged Access SC-10 Network Disconnect SC-2 Separation of System and User Functionality SC-39 Process Isolation SC-4 Information in Shared System Resources SC-7(5) Deny by Default Allow by Exception 1.4.5 1.4.5 Internal IP and routing disclosure limited 10.1.2 10.1.2 Roles for logging and monitoring assigned and understood 10.3.1 10.3.1 Audit log read access limited to job need 2.2.3 2.2.3 Primary functions with different security levels managed 3.3.3 3.3.3 Issuer SAD storage limited, justified and encrypted 3.4.2 3.4.2 Remote access blocks copying or relocating PAN 3.5.1.2 3.5.1.2 Disk or partition encryption only on removable media 3.5.1.3 3.5.1.3 Disk encryption access independent of OS authentication 3.6.1.2 3.6.1.2 Permitted storage forms for secret and private keys 3.6.1.3 3.6.1.3 Cleartext key component access limited to minimum custodians 3.6.1.4 3.6.1.4 Cryptographic keys kept in fewest locations 3.7.6 3.7.6 Split knowledge and dual control for manual key operations 3.7.7 3.7.7 Prevent unauthorized substitution of keys 6.5.5 6.5.5 No live PANs in pre-production 7.2.1 7.2.1 Access control model defined 7.2.2 7.2.2 User access assigned by job function and least privilege 7.2.5.1 7.2.5.1 Application and system account access reviewed periodically 7.3.2 7.3.2 Access control system enforces role-based permissions 7.3.3 7.3.3 Access control default deny all 8.2.2 8.2.2 Shared and generic IDs only by exception 8.2.3 8.2.3 Service provider unique factors per customer 8.2.4 8.2.4 User ID lifecycle changes authorized 8.2.5 8.2.5 Terminated users' access revoked immediately 8.2.6 8.2.6 Inactive accounts removed within 90 days 8.2.7 8.2.7 Third-party remote access accounts controlled 8.3.11 8.3.11 Tokens, smart cards and certificates individually assigned 8.4.1 8.4.1 MFA for non-console administrative CDE access 8.4.2 8.4.2 MFA for all non-console CDE access 8.5.1 8.5.1 MFA system resistant to replay and bypass 9.2.3 9.2.3 Physical protection of network hardware and lines 9.2.4 9.2.4 Locking of consoles in sensitive areas 9.4.1 9.4.1 Physical security of all media 9.4.4 9.4.4 Management approval for media leaving facility 3.4.1 3.4.1 PAN masked on display except for authorized roles 3.6.1 3.6.1 Procedures protect keys against disclosure and misuse 3.7.1 3.7.1 Generation of strong cryptographic keys 6.5.3 6.5.3 Separate pre-production from production 6.5.4 6.5.4 Separate roles between production and pre-production 7.2.4 7.2.4 User accounts and privileges reviewed every six months 7.2.5 7.2.5 Application and system accounts least privilege 7.2.6 7.2.6 Query access to stored cardholder data restricted 7.3.1 7.3.1 Need-to-know access control system covers all components 8.6.1 8.6.1 Interactive use of system accounts controlled 8.6.3 8.6.3 System account passwords protected against misuse 5.15 Access control 5.16 Identity management 5.17 Authentication information 5.18 Access rights 5.23 Information security for use of cloud services 5.3 Segregation of duties 5.32 Intellectual property rights 5.36 Compliance with policies, rules and standards for information security 6.5 Responsibilities after termination or change of employment 6.7 Remote working 8.1 User endpoint devices 8.18 Use of privileged utility programs 8.2 Privileged access rights 8.22 Segregation of networks 8.3 Information access restriction 8.31 Separation of development, test and production environments 8.33 Test information 8.4 Access to source code CIS-12.2 Establish and Maintain a Secure Network Architecture CIS-12.5 Centralize Network Authentication, Authorization, and Auditing (AAA) CIS-12.8 Establish and Maintain Dedicated Computing Resources for All Administrative Work CIS-13.5 Manage Access Control for Remote Assets CIS-13.9 Deploy Port-Level Access Control CIS-16.10 Apply Secure Design Principles in Application Architectures CIS-3.3 Configure Data Access Control Lists CIS-4.12 Separate Enterprise Workspaces on Mobile End-User Devices CIS-4.6 Securely Manage Enterprise Assets and Software CIS-5.3 Disable Dormant Accounts CIS-5.4 Restrict Administrator Privileges to Dedicated Administrator Accounts CIS-5.5 Establish and Maintain an Inventory of Service Accounts CIS-5.6 Centralize Account Management CIS-6.2 Establish an Access Revoking Process CIS-6.5 Require MFA for Administrative Access CIS-6.7 Centralize Access Control CIS-6.8 Define and Maintain Role-Based Access Control 5.10 Acceptable use of information and other associated assets 5.15 Access control 5.16 Identity management 5.18 Access rights 5.23 Information security for use of cloud services 5.3 Segregation of duties 6.5 Responsibilities after termination or change of employment 6.7 Remote working 8.1 User end point devices 8.11 Data masking 8.18 Use of privileged utility programs 8.2 Privileged access rights 8.22 Segregation of networks 8.3 Information access restriction 8.4 Access to source code 8.5 Secure authentication 5.6 Operation 6.3.2 Mobile devices and teleworking 6.4.2 During employment 6.4.3 Termination and change of employment 6.6 Access control 6.6.1 Business requirements of access control 6.6.2 User access management 6.6.3 User responsibilities 6.6.4 System and application access control NIST-CSF-GV.RR-04 Cybersecurity is included in human resources practices NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization NIST-CSF-PR.AA-03 Users, services, and hardware are authenticated NIST-CSF-PR.AA-04 Identity assertions are protected, conveyed, and verified NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties NIST-CSF-PR.DS-10 The confidentiality, integrity, and availability of data-in-use are protected NIST-CSF-PR.IR-01 Networks and environments are protected from unauthorized logical access and usage ASBv3-AM-4 Limit access to asset management ASBv3-GS-2 Define and implement enterprise segmentation/separation of duties strategy ASBv3-PA-4 Review and reconcile user access regularly ASBv3-PA-7 Follow just enough administration (least privilege) principle PA-1 Separate and limit highly privileged/administrative users PA-2 Avoid standing access for user accounts and permissions ANSSI-HYG-05 Maintain an Exhaustive Inventory of Privileged Accounts ANSSI-HYG-08 Identify Each Person by Name and Separate User and Administrator Roles ANSSI-HYG-09 Assign the Correct Rights on Sensitive Resources ANSSI-HYG-29 Limit Administration Rights on Workstations to Operational Need ASD37-18 Restrict administrative privileges (Essential) ASD37-20 Multi-factor authentication (Essential) ASD37-21 Disable local administrator accounts (Excellent) ASD37-37 Personnel management (Very Good) BSI-02 Access enforcement and least privilege BSI-03 Multi-factor authentication requirements BSI-04 Remote access controls BSI-05 Wireless access restrictions CE-AC.3 Remove or Disable Accounts When No Longer Required CE-AC.4 Privileged Account Approval and Tracking CE-AC.5 Separate Admin Accounts for Administrative Activities CE-AC.6 Periodic Review of Privileged Access E8-ADMIN-ML1 Restrict Administrative Privileges (ML1) E8-ADMIN-ML2 Restrict Administrative Privileges (ML2) E8-ADMIN-ML3 Restrict Administrative Privileges (ML3) API1164-06 Access Control API1164-07 Remote Access API1164-09 Patch and Vulnerability Management AWWA-1.3 Security Awareness and Training AWWA-2.1 User Access Management AWWA-2.4 Physical Access Controls CAT-D3-1 Preventative controls CAT-D4-3 Third-party access controls CAT-IRP-4 Organizational characteristics IEC62443-07 Personnel risk assessment IEC62443-08 Electronic access perimeter management IEC62443-10 Revocation of access procedures ISO27799-01 ePHI access controls and authorization ISO27799-08 Information access management ISO27799-17 Facility access controls ISO27019-07 Personnel risk assessment ISO27019-08 Electronic access perimeter management ISO27019-10 Revocation of access procedures ISO27043-11 Access control policy and enforcement ISO27043-14 Privileged access management ISO27043-15 Access review and recertification ISO21434-12 User access management and provisioning ISO21434-14 Privileged access management ISO21434-15 Access review and recertification MYHR-SEC-2 Access controls and user account management MYHR-SEC-7 Consumer access controls and consent DSO-2 Data Security DSO-3 Data Access Management 27010-9.1 Access Control to Shared Information 27010-9.2 Authentication of Sources 27011-5.3 Segregation of duties 27011-8.1 User Endpoint Devices 3.1.1e Dual Authorization for Sensitive System Operations 3.13.2e Introduce Unpredictability into System Operations SSAE18-CC6.2 CC6.2 - New User Registration and Authorization SSAE18-SOC1-06 Transaction Processing Controls SAM-1 Customer Information Confidentiality (Section 48) SAM-6 Legal Authorization Requirements ISMSP-AC-01 Access Control Policy ISMSP-AC-04 Network Access Control SOC3-LOGICAL-ACCESS Logical Access APPI-A26 Report of Leakage to the Commission and Notification to the Person AUCDR-IS-1 Limit risk of unauthorised access to the CDR data environment CA-ITSG33-SC-01 Security Control Catalogue EUAI-Art.59 Further processing of personal data for developing certain AI systems in the public interest in the AI regulatory sandbox FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c)) UAE-PDPL-Art.6_7 Sensitive personal data and children's data (UAE PDPL Articles 6-7) GDPR-Art.29 Processing under the authority of the controller or processor ICAO-ANX17-Chap2-ThreatAssessment-RiskManagement-Cyber-GASeP ICAO Annex 17 Chapter 2 - Threat Assessment + Risk Management + Cyber Threats to Critical Aviation Systems (Amendment 17/18) 62351-8 Role-based access control (RBAC) ISO-19650-2-5.7 Information model delivery ISO28001-PS-01 Facility Security ISO20000-15 Access management for services 27400-6.1 Secure Device Design 8.4 AI system impact assessment ITIL4-15 Access management for services Art.21.2.i Human resources security, access control policies and asset management NIST190-08 Privileged access in cloud environments SOC-CY-S1 Logical and Physical Access Controls SA-PDPL-15 Access control for personal data SOCI-CIRMP-SUPPLY CIRMP hazard vector: Supply chain TAIWAN-3 Data Subject Rights TEXASTDPSA-2 Consumer Rights SEMD-PS-2 Site Security Measures UK-TSA-NET-02 Access Control and Authentication ACE-CR-4 Cargo Release Authorization CPSC-CS.2 Authentication and Access Controls US-ITAR-EAR-DS-03 Access Controls UGA-10 Sensitive Personal Data Prohibition URUGUAY-3 Sensitive Data, Health Data, Children VIRGINIAVCDPA-3 Sensitive Data Consent and Children Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in CC - Common Criteria (Security) You are reading one control. How much of SOC 2 have you already done? SOC 2 SOC2-CC6.3 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of SOC 2 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 49 of 61 SOC 2 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 193 were rejected on the NIST SP 800-53 Rev 5 pair alone.
Query this from an agent The graph holds this control, the 496 it maps to, and the evidence behind each claim, over MCP and REST.