Physical access to facilities and protected assets such as data centres, rooms holding backup media and other sensitive spaces is limited to authorised personnel. Points of focus: physical access for staff, contractors, vendors and partner personnel to data centres, offices and work areas is created or changed on appropriate authorisation; it is removed when no longer needed; organisation devices such as badges, laptops and phones are recovered when the holder no longer needs access (added in 2022); and access is reviewed periodically against job responsibilities. Where facilities are run by a hosting or cloud provider, the provider's SOC report and the complementary controls it expects are part of the evidence.
This control maps to 190 controls across 24 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
SOC 2 SOC2-CC6.4 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of SOC 2 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 49 of 61 SOC 2 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 193 were rejected on the NIST SP 800-53 Rev 5 pair alone.
The graph holds this control, the 190 it maps to, and the evidence behind each claim, over MCP and REST.