SOC 2
CC - Common Criteria (Security)

SOC 2 SOC2-CC6.3: CC6.3 Role-based access, least privilege and segregation of duties

Rights over data, programs, functions and other protected assets is granted, changed or removed according to roles, responsibilities or system design and changes, applying least privilege and segregation of duties. Points of focus: access is created or modified on the asset owner's authorisation; it is removed when no longer needed; access structures (role-based, for example) limit privileges and separate incompatible functions; and roles and access rules are reviewed periodically for people who no longer need them (staff, contractors, vendors, partner personnel) and for system or service accounts that should not exist, and adjusted.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 496 controls across 85 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

FedRAMP High · 47 controls

  • AC-14 Permitted Actions Without Identification or Authentication
  • AC-19 Access Control for Mobile Devices
  • AC-2 Account Management
  • AC-2(1) Automated System Account Management
  • AC-2(2) Automated Temporary and Emergency Account Management
  • AC-2(3) Disable Accounts
  • AC-2(4) Automated Audit Actions
  • AC-2(7) Privileged User Accounts
  • AC-2(9) Restrictions on Use of Shared and Group Accounts
  • AC-20(2) Portable Storage Devices Restricted Use
  • AC-21 Information Sharing
  • AC-22 Publicly Accessible Content
  • AC-3 Access Enforcement
  • AC-5 Separation of Duties
  • AC-6 Least Privilege
  • AC-6(1) Authorize Access to Security Functions
  • AC-6(10) Prohibit Non-Privileged Users from Executing Privileged Functions
  • AC-6(2) Non-Privileged Access for Nonsecurity Functions
  • AC-6(5) Privileged Accounts
  • AC-6(7) Review of User Privileges
  • AC-6(9) Log Use of Privileged Functions
  • AT-3 Role-Based Training
  • AU-9 Protection of Audit Information
  • AU-9(4) Access by Subset of Privileged Users
  • CA-9 Internal System Connections
  • CM-12 Information Location (CM-12)
  • CM-5 Access Restrictions for Change
  • CM-5(1) Access Restrictions for Change | Automated Access Enforcement and Audit Records (CM-5(1))
  • CM-5(5) Access Restrictions for Change | Privilege Limitation for Production and Operation (CM-5(5))
  • IA-11 Re-Authentication
  • IA-2(1) MFA to Privileged Accounts
  • IA-2(12) Acceptance of PIV Credentials
  • IA-4 Identifier Management
  • IA-5 Authenticator Management
  • IA-5(2) Public Key-Based Authentication
  • IA-5(6) Protection of Authenticators
  • IA-8(4) Identification and Authentication (Non-organizational Users) | Use of Defined Profiles (IA-8(4))
  • IR-9(4) Information Spillage Response | Exposure to Unauthorized Personnel (IR-9(4))
  • MP-2 Media Access
  • PS-4 Personnel Termination
  • PS-5 Personnel Transfer
  • RA-5(5) Privileged Access
  • SC-10 Network Disconnect
  • SC-2 Separation of System and User Functionality
  • SC-39 Process Isolation
  • SC-4 Information in Shared System Resources
  • SC-7(5) Deny by Default Allow by Exception

FedRAMP Moderate · 47 controls

  • AC-14 Permitted Actions Without Identification or Authentication
  • AC-19 Access Control for Mobile Devices
  • AC-2 Account Management
  • AC-2(1) Automated System Account Management
  • AC-2(2) Automated Temporary and Emergency Account Management
  • AC-2(3) Disable Accounts
  • AC-2(4) Automated Audit Actions
  • AC-2(7) Privileged User Accounts
  • AC-2(9) Restrictions on Use of Shared and Group Accounts
  • AC-20(2) Portable Storage Devices Restricted Use
  • AC-21 Information Sharing
  • AC-22 Publicly Accessible Content
  • AC-3 Access Enforcement
  • AC-5 Separation of Duties
  • AC-6 Least Privilege
  • AC-6(1) Authorize Access to Security Functions
  • AC-6(10) Prohibit Non-Privileged Users from Executing Privileged Functions
  • AC-6(2) Non-Privileged Access for Nonsecurity Functions
  • AC-6(5) Privileged Accounts
  • AC-6(7) Review of User Privileges
  • AC-6(9) Log Use of Privileged Functions
  • AT-3 Role-Based Training
  • AU-9 Protection of Audit Information
  • AU-9(4) Access by Subset of Privileged Users
  • CA-9 Internal System Connections
  • CM-12 Information Location (CM-12)
  • CM-5 Access Restrictions for Change
  • CM-5(1) Access Restrictions for Change | Automated Access Enforcement and Audit Records (CM-5(1))
  • CM-5(5) Access Restrictions for Change | Privilege Limitation for Production and Operation (CM-5(5))
  • IA-11 Re-Authentication
  • IA-2(1) MFA to Privileged Accounts
  • IA-2(12) Acceptance of PIV Credentials
  • IA-4 Identifier Management
  • IA-5 Authenticator Management
  • IA-5(2) Public Key-Based Authentication
  • IA-5(6) Protection of Authenticators
  • IA-8(4) Identification and Authentication (Non-organizational Users) | Use of Defined Profiles (IA-8(4))
  • IR-9(4) Information Spillage Response | Exposure to Unauthorized Personnel (IR-9(4))
  • MP-2 Media Access
  • PS-4 Personnel Termination
  • PS-5 Personnel Transfer
  • RA-5(5) Privileged Access
  • SC-10 Network Disconnect
  • SC-2 Separation of System and User Functionality
  • SC-39 Process Isolation
  • SC-4 Information in Shared System Resources
  • SC-7(5) Deny by Default Allow by Exception

PCI DSS 4.0 · 44 controls

  • 1.4.5 1.4.5 Internal IP and routing disclosure limited
  • 10.1.2 10.1.2 Roles for logging and monitoring assigned and understood
  • 10.3.1 10.3.1 Audit log read access limited to job need
  • 2.2.3 2.2.3 Primary functions with different security levels managed
  • 3.3.3 3.3.3 Issuer SAD storage limited, justified and encrypted
  • 3.4.2 3.4.2 Remote access blocks copying or relocating PAN
  • 3.5.1.2 3.5.1.2 Disk or partition encryption only on removable media
  • 3.5.1.3 3.5.1.3 Disk encryption access independent of OS authentication
  • 3.6.1.2 3.6.1.2 Permitted storage forms for secret and private keys
  • 3.6.1.3 3.6.1.3 Cleartext key component access limited to minimum custodians
  • 3.6.1.4 3.6.1.4 Cryptographic keys kept in fewest locations
  • 3.7.6 3.7.6 Split knowledge and dual control for manual key operations
  • 3.7.7 3.7.7 Prevent unauthorized substitution of keys
  • 6.5.5 6.5.5 No live PANs in pre-production
  • 7.2.1 7.2.1 Access control model defined
  • 7.2.2 7.2.2 User access assigned by job function and least privilege
  • 7.2.5.1 7.2.5.1 Application and system account access reviewed periodically
  • 7.3.2 7.3.2 Access control system enforces role-based permissions
  • 7.3.3 7.3.3 Access control default deny all
  • 8.2.2 8.2.2 Shared and generic IDs only by exception
  • 8.2.3 8.2.3 Service provider unique factors per customer
  • 8.2.4 8.2.4 User ID lifecycle changes authorized
  • 8.2.5 8.2.5 Terminated users' access revoked immediately
  • 8.2.6 8.2.6 Inactive accounts removed within 90 days
  • 8.2.7 8.2.7 Third-party remote access accounts controlled
  • 8.3.11 8.3.11 Tokens, smart cards and certificates individually assigned
  • 8.4.1 8.4.1 MFA for non-console administrative CDE access
  • 8.4.2 8.4.2 MFA for all non-console CDE access
  • 8.5.1 8.5.1 MFA system resistant to replay and bypass
  • 9.2.3 9.2.3 Physical protection of network hardware and lines
  • 9.2.4 9.2.4 Locking of consoles in sensitive areas
  • 9.4.1 9.4.1 Physical security of all media
  • 9.4.4 9.4.4 Management approval for media leaving facility
  • 3.4.1 3.4.1 PAN masked on display except for authorized roles
  • 3.6.1 3.6.1 Procedures protect keys against disclosure and misuse
  • 3.7.1 3.7.1 Generation of strong cryptographic keys
  • 6.5.3 6.5.3 Separate pre-production from production
  • 6.5.4 6.5.4 Separate roles between production and pre-production
  • 7.2.4 7.2.4 User accounts and privileges reviewed every six months
  • 7.2.5 7.2.5 Application and system accounts least privilege
  • 7.2.6 7.2.6 Query access to stored cardholder data restricted
  • 7.3.1 7.3.1 Need-to-know access control system covers all components
  • 8.6.1 8.6.1 Interactive use of system accounts controlled
  • 8.6.3 8.6.3 System account passwords protected against misuse

NIST SP 800-53 Rev 5 · 43 controls

CMMC 2.0 · 30 controls

ISO 27002:2022 · 18 controls

  • 5.15 Access control
  • 5.16 Identity management
  • 5.17 Authentication information
  • 5.18 Access rights
  • 5.23 Information security for use of cloud services
  • 5.3 Segregation of duties
  • 5.32 Intellectual property rights
  • 5.36 Compliance with policies, rules and standards for information security
  • 6.5 Responsibilities after termination or change of employment
  • 6.7 Remote working
  • 8.1 User endpoint devices
  • 8.18 Use of privileged utility programs
  • 8.2 Privileged access rights
  • 8.22 Segregation of networks
  • 8.3 Information access restriction
  • 8.31 Separation of development, test and production environments
  • 8.33 Test information
  • 8.4 Access to source code

CIS Controls v8 · 17 controls

  • CIS-12.2 Establish and Maintain a Secure Network Architecture
  • CIS-12.5 Centralize Network Authentication, Authorization, and Auditing (AAA)
  • CIS-12.8 Establish and Maintain Dedicated Computing Resources for All Administrative Work
  • CIS-13.5 Manage Access Control for Remote Assets
  • CIS-13.9 Deploy Port-Level Access Control
  • CIS-16.10 Apply Secure Design Principles in Application Architectures
  • CIS-3.3 Configure Data Access Control Lists
  • CIS-4.12 Separate Enterprise Workspaces on Mobile End-User Devices
  • CIS-4.6 Securely Manage Enterprise Assets and Software
  • CIS-5.3 Disable Dormant Accounts
  • CIS-5.4 Restrict Administrator Privileges to Dedicated Administrator Accounts
  • CIS-5.5 Establish and Maintain an Inventory of Service Accounts
  • CIS-5.6 Centralize Account Management
  • CIS-6.2 Establish an Access Revoking Process
  • CIS-6.5 Require MFA for Administrative Access
  • CIS-6.7 Centralize Access Control
  • CIS-6.8 Define and Maintain Role-Based Access Control

ISO 27001:2022 · 16 controls

  • 5.10 Acceptable use of information and other associated assets
  • 5.15 Access control
  • 5.16 Identity management
  • 5.18 Access rights
  • 5.23 Information security for use of cloud services
  • 5.3 Segregation of duties
  • 6.5 Responsibilities after termination or change of employment
  • 6.7 Remote working
  • 8.1 User end point devices
  • 8.11 Data masking
  • 8.18 Use of privileged utility programs
  • 8.2 Privileged access rights
  • 8.22 Segregation of networks
  • 8.3 Information access restriction
  • 8.4 Access to source code
  • 8.5 Secure authentication

HIPAA Security Rule · 13 controls

NIST SP 800-66 Rev 2 · 11 controls

ISO 27701:2019 · 9 controls

  • 5.6 Operation
  • 6.3.2 Mobile devices and teleworking
  • 6.4.2 During employment
  • 6.4.3 Termination and change of employment
  • 6.6 Access control
  • 6.6.1 Business requirements of access control
  • 6.6.2 User access management
  • 6.6.3 User responsibilities
  • 6.6.4 System and application access control

C5 (Germany) · 8 controls

  • NIST-CSF-GV.RR-04 Cybersecurity is included in human resources practices
  • NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization
  • NIST-CSF-PR.AA-03 Users, services, and hardware are authenticated
  • NIST-CSF-PR.AA-04 Identity assertions are protected, conveyed, and verified
  • NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
  • NIST-CSF-PR.DS-10 The confidentiality, integrity, and availability of data-in-use are protected
  • NIST-CSF-PR.IR-01 Networks and environments are protected from unauthorized logical access and usage
  • ASBv3-AM-4 Limit access to asset management
  • ASBv3-GS-2 Define and implement enterprise segmentation/separation of duties strategy
  • ASBv3-PA-4 Review and reconcile user access regularly
  • ASBv3-PA-7 Follow just enough administration (least privilege) principle
  • PA-1 Separate and limit highly privileged/administrative users
  • PA-2 Avoid standing access for user accounts and permissions

NIST SP 800-171 Rev 3 · 5 controls

  • ANSSI-HYG-05 Maintain an Exhaustive Inventory of Privileged Accounts
  • ANSSI-HYG-08 Identify Each Person by Name and Separate User and Administrator Roles
  • ANSSI-HYG-09 Assign the Correct Rights on Sensitive Resources
  • ANSSI-HYG-29 Limit Administration Rights on Workstations to Operational Need
  • ASD37-18 Restrict administrative privileges (Essential)
  • ASD37-20 Multi-factor authentication (Essential)
  • ASD37-21 Disable local administrator accounts (Excellent)
  • ASD37-37 Personnel management (Very Good)

BSI IT-Grundschutz · 4 controls

  • BSI-02 Access enforcement and least privilege
  • BSI-03 Multi-factor authentication requirements
  • BSI-04 Remote access controls
  • BSI-05 Wireless access restrictions

UK Cyber Essentials · 4 controls

  • CE-AC.3 Remove or Disable Accounts When No Longer Required
  • CE-AC.4 Privileged Account Approval and Tracking
  • CE-AC.5 Separate Admin Accounts for Administrative Activities
  • CE-AC.6 Periodic Review of Privileged Access

ACSC Essential Eight · 3 controls

  • E8-ADMIN-ML1 Restrict Administrative Privileges (ML1)
  • E8-ADMIN-ML2 Restrict Administrative Privileges (ML2)
  • E8-ADMIN-ML3 Restrict Administrative Privileges (ML3)

API 1164 · 3 controls

  • API1164-06 Access Control
  • API1164-07 Remote Access
  • API1164-09 Patch and Vulnerability Management
  • AWWA-1.3 Security Awareness and Training
  • AWWA-2.1 User Access Management
  • AWWA-2.4 Physical Access Controls
  • CAT-D3-1 Preventative controls
  • CAT-D4-3 Third-party access controls
  • CAT-IRP-4 Organizational characteristics

IEC 62443 · 3 controls

  • IEC62443-07 Personnel risk assessment
  • IEC62443-08 Electronic access perimeter management
  • IEC62443-10 Revocation of access procedures

ISO 27799:2025 · 3 controls

  • ISO27799-01 ePHI access controls and authorization
  • ISO27799-08 Information access management
  • ISO27799-17 Facility access controls

ISO/IEC 27019:2024 · 3 controls

  • ISO27019-07 Personnel risk assessment
  • ISO27019-08 Electronic access perimeter management
  • ISO27019-10 Revocation of access procedures

ISO/IEC 27043:2015 · 3 controls

  • ISO27043-11 Access control policy and enforcement
  • ISO27043-14 Privileged access management
  • ISO27043-15 Access review and recertification

ISO/SAE 21434 · 3 controls

  • ISO21434-12 User access management and provisioning
  • ISO21434-14 Privileged access management
  • ISO21434-15 Access review and recertification

NIST SP 1800-32 · 3 controls

  • MYHR-SEC-2 Access controls and user account management
  • MYHR-SEC-7 Consumer access controls and consent
  • DSO-2 Data Security
  • DSO-3 Data Access Management

ISO/IEC 27010:2015 · 2 controls

  • 27010-9.1 Access Control to Shared Information
  • 27010-9.2 Authentication of Sources

ISO/IEC 27011:2024 · 2 controls

  • 27011-5.3 Segregation of duties
  • 27011-8.1 User Endpoint Devices

NIST SP 800-172 · 2 controls

  • 3.1.1e Dual Authorization for Sensitive System Operations
  • 3.13.2e Introduce Unpredictability into System Operations
  • SSAE18-CC6.2 CC6.2 - New User Registration and Authorization
  • SSAE18-SOC1-06 Transaction Processing Controls
  • SAM-1 Customer Information Confidentiality (Section 48)
  • SAM-6 Legal Authorization Requirements

South Korea ISMS-P · 2 controls

  • ISMSP-AC-01 Access Control Policy
  • ISMSP-AC-04 Network Access Control

AICPA SOC 3 · 1 control

  • SOC3-LOGICAL-ACCESS Logical Access

APPI · 1 control

  • APPI-A26 Report of Leakage to the Commission and Notification to the Person
  • AUCDR-IS-1 Limit risk of unauthorised access to the CDR data environment

Bahrain PDPL · 1 control

  • CA-ITSG33-SC-01 Security Control Catalogue

DORA · 1 control

EU AI Act · 1 control

  • EUAI-Art.59 Further processing of personal data for developing certain AI systems in the public interest in the AI regulatory sandbox
  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))
  • UAE-PDPL-Art.6_7 Sensitive personal data and children's data (UAE PDPL Articles 6-7)

GDPR · 1 control

  • GDPR-Art.29 Processing under the authority of the controller or processor
  • ICAO-ANX17-Chap2-ThreatAssessment-RiskManagement-Cyber-GASeP ICAO Annex 17 Chapter 2 - Threat Assessment + Risk Management + Cyber Threats to Critical Aviation Systems (Amendment 17/18)
  • 62351-8 Role-based access control (RBAC)
  • ISO28001-PS-01 Facility Security
  • ISO20000-15 Access management for services

ISO/IEC 27400:2022 · 1 control

  • 27400-6.1 Secure Device Design

ISO/IEC 42001:2023 · 1 control

  • 8.4 AI system impact assessment

ITIL 4 · 1 control

  • ITIL4-15 Access management for services

NIS2 Directive · 1 control

  • Art.21.2.i Human resources security, access control policies and asset management

NIST SP 800-190 · 1 control

  • NIST190-08 Privileged access in cloud environments

NIST SP 800-218 · 1 control

  • SOC-CY-S1 Logical and Physical Access Controls

Saudi Arabia PDPL · 1 control

  • SA-PDPL-15 Access control for personal data
  • SOCI-CIRMP-SUPPLY CIRMP hazard vector: Supply chain

Taiwan PDPA · 1 control

  • TAIWAN-3 Data Subject Rights
  • TEXASTDPSA-2 Consumer Rights
  • UK-TSA-NET-02 Access Control and Authentication
  • ACE-CR-4 Cargo Release Authorization
  • CPSC-CS.2 Authentication and Access Controls
  • US-ITAR-EAR-DS-03 Access Controls
  • UGA-10 Sensitive Personal Data Prohibition

Uruguay DPL · 1 control

  • URUGUAY-3 Sensitive Data, Health Data, Children

Virginia CDPA · 1 control

  • VIRGINIAVCDPA-3 Sensitive Data Consent and Children

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in CC - Common Criteria (Security)

You are reading one control. How much of SOC 2 have you already done?

SOC 2 SOC2-CC6.3 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of SOC 2 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 49 of 61 SOC 2 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 193 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 496 it maps to, and the evidence behind each claim, over MCP and REST.