SOC 2
CC - Common Criteria (Security)

SOC 2 SOC2-CC6.4: CC6.4 Restricting physical access to facilities and assets

Physical access to facilities and protected assets such as data centres, rooms holding backup media and other sensitive spaces is limited to authorised personnel. Points of focus: physical access for staff, contractors, vendors and partner personnel to data centres, offices and work areas is created or changed on appropriate authorisation; it is removed when no longer needed; organisation devices such as badges, laptops and phones are recovered when the holder no longer needs access (added in 2022); and access is reviewed periodically against job responsibilities. Where facilities are run by a hosting or cloud provider, the provider's SOC report and the complementary controls it expects are part of the evidence.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 190 controls across 24 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

FedRAMP High · 25 controls

  • AC-6(1) Authorize Access to Security Functions
  • CP-6(3) Alternate Storage Site | Accessibility (CP-6(3))
  • CP-7(2) Alternate Processing Site | Accessibility (CP-7(2))
  • MA-5 Maintenance Personnel
  • MA-5(1) Maintenance Personnel | Individuals Without Appropriate Access (MA-5(1))
  • MP-2 Media Access
  • MP-4 Media Storage
  • MP-5 Media Transport
  • MP-7 Media Use
  • PE-10 Emergency Shutoff (PE-10)
  • PE-13 Fire Protection
  • PE-13(1) Fire Protection | Detection Systems: Automatic Activation and Notification (PE-13(1))
  • PE-13(2) Fire Protection | Suppression Systems: Automatic Activation and Notification (PE-13(2))
  • PE-16 Delivery and Removal
  • PE-17 Alternate Work Site
  • PE-2 Physical Access Authorizations
  • PE-3 Physical Access Control
  • PE-4 Access Control for Transmission (PE-4)
  • PE-5 Access Control for Output Devices (PE-5)
  • PE-6 Monitoring Physical Access
  • PE-6(1) Monitoring Physical Access | Intrusion Alarms and Surveillance Equipment (PE-6(1))
  • PE-8 Visitor Access Records
  • PS-4 Personnel Termination
  • SA-9(5) External System Services | Processing, Storage, and Service Location (SA-9(5))
  • SR-11(2) Component Authenticity | Configuration Control for Component Service and Repair (SR-11(2))

FedRAMP Moderate · 25 controls

  • AC-6(1) Authorize Access to Security Functions
  • CP-6(3) Alternate Storage Site | Accessibility (CP-6(3))
  • CP-7(2) Alternate Processing Site | Accessibility (CP-7(2))
  • MA-5 Maintenance Personnel
  • MA-5(1) Maintenance Personnel | Individuals Without Appropriate Access (MA-5(1))
  • MP-2 Media Access
  • MP-4 Media Storage
  • MP-5 Media Transport
  • MP-7 Media Use
  • PE-10 Emergency Shutoff (PE-10)
  • PE-13 Fire Protection
  • PE-13(1) Fire Protection | Detection Systems: Automatic Activation and Notification (PE-13(1))
  • PE-13(2) Fire Protection | Suppression Systems: Automatic Activation and Notification (PE-13(2))
  • PE-16 Delivery and Removal
  • PE-17 Alternate Work Site
  • PE-2 Physical Access Authorizations
  • PE-3 Physical Access Control
  • PE-4 Access Control for Transmission (PE-4)
  • PE-5 Access Control for Output Devices (PE-5)
  • PE-6 Monitoring Physical Access
  • PE-6(1) Monitoring Physical Access | Intrusion Alarms and Surveillance Equipment (PE-6(1))
  • PE-8 Visitor Access Records
  • PS-4 Personnel Termination
  • SA-9(5) External System Services | Processing, Storage, and Service Location (SA-9(5))
  • SR-11(2) Component Authenticity | Configuration Control for Component Service and Repair (SR-11(2))

NIST SP 800-53 Rev 5 · 21 controls

PCI DSS 4.0 · 19 controls

  • 12.5.1 12.5.1 Inventory of in-scope system components
  • 2.2.3 2.2.3 Primary functions with different security levels managed
  • 3.7.3 3.7.3 Secure storage of cryptographic keys
  • 9.2.1 9.2.1 Facility entry controls for CDE systems
  • 9.2.1.1 9.2.1.1 Monitoring of entry to sensitive areas
  • 9.2.2 9.2.2 Controls on publicly accessible network jacks
  • 9.3.1 9.3.1 Personnel physical access procedures for the CDE
  • 9.3.1.1 9.3.1.1 Personnel access to sensitive areas controlled
  • 9.3.2 9.3.2 Visitor access procedures for the CDE
  • 9.3.3 9.3.3 Visitor badges returned or deactivated
  • 9.3.4 9.3.4 Visitor logs for facility and sensitive areas
  • 9.4.1.1 9.4.1.1 Secure storage location for offline backups
  • 9.4.1.2 9.4.1.2 Annual review of offline backup location security
  • 9.4.3 9.4.3 Securing media sent outside the facility
  • 9.4.5 9.4.5 Inventory logs of electronic media
  • 9.4.5.1 9.4.5.1 Annual inventories of electronic media
  • 9.5.1 9.5.1 Protection of POI devices from tampering
  • 9.5.1.1 9.5.1.1 Current register of POI devices
  • 9.5.1.2 9.5.1.2 Periodic inspection of POI device surfaces

ISO 27002:2022 · 16 controls

  • 5.15 Access control
  • 5.33 Protection of records
  • 5.9 Inventory of information and other associated assets
  • 7.1 Physical security perimeters
  • 7.10 Storage media
  • 7.12 Cabling security
  • 7.13 Equipment maintenance
  • 7.2 Physical entry
  • 7.3 Securing offices, rooms and facilities
  • 7.4 Physical security monitoring
  • 7.5 Protecting against physical and environmental threats
  • 7.6 Working in secure areas
  • 7.7 Clear desk and clear screen
  • 7.8 Equipment siting and protection
  • 7.9 Security of assets off-premises
  • 8.1 User endpoint devices

ISO 27001:2022 · 14 controls

  • 5.15 Access control
  • 5.9 Inventory of information and other associated assets
  • 6.5 Responsibilities after termination or change of employment
  • 7.1 Physical security perimeters
  • 7.12 Cabling security
  • 7.13 Equipment maintenance
  • 7.2 Physical entry
  • 7.3 Securing offices, rooms and facilities
  • 7.4 Physical security monitoring
  • 7.5 Protecting against physical and environmental threats
  • 7.6 Working in secure areas
  • 7.7 Clear desk and clear screen
  • 7.8 Equipment siting and protection
  • 7.9 Security of assets off-premises

CMMC 2.0 · 13 controls

HIPAA Security Rule · 9 controls

NIST SP 800-66 Rev 2 · 9 controls

ISO 27701:2019 · 6 controls

  • 5.5 Support
  • 6.5.1 Responsibility for assets
  • 6.5.3 Media handling
  • 6.8 Physical and environmental security
  • 6.8.1 Secure areas
  • 6.8.2 Equipment

NIST SP 800-171 Rev 3 · 5 controls

C5 (Germany) · 4 controls

  • C5-OPS-09 Data Backup and Recovery - Storage
  • C5-PS-01 Physical Security and Environmental Control Requirements
  • C5-PS-03 Perimeter Protection
  • C5-PS-04 Physical site access control
  • NIST-CSF-DE.CM-02 The physical environment is monitored to find potentially adverse events
  • NIST-CSF-PR.AA-06 Physical access to assets is managed, monitored, and enforced commensurate with risk
  • NIST-CSF-PR.IR-01 Networks and environments are protected from unauthorized logical access and usage
  • ANSSI-HYG-26 Control and Protect Access to Server Rooms and Technical Areas
  • ANSSI-HYG-30 Apply Physical Protection Measures to Mobile Devices

CIS Controls v8 · 2 controls

  • CIS-11.3 Protect Recovery Data
  • CIS-11.4 Establish and Maintain an Isolated Instance of Recovery Data

DORA · 2 controls

ISO 22301:2019 · 2 controls

  • 7.1 Resources
  • 8.3.4 Resource requirements

NIST SP 800-161 Rev 1 · 2 controls

APPI · 1 control

  • AUCDR-IS-1 Limit risk of unauthorised access to the CDR data environment
  • CFTC-SS-6 Physical Security and Environmental Controls Category

ISO/IEC 42001:2023 · 1 control

  • A.4.5 System and computing resources

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in CC - Common Criteria (Security)

You are reading one control. How much of SOC 2 have you already done?

SOC 2 SOC2-CC6.4 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of SOC 2 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 49 of 61 SOC 2 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 193 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 190 it maps to, and the evidence behind each claim, over MCP and REST.