SOC for Cybersecurity - Cybersecurity Risk Management Examination
SOC for Cybersecurity: Security Criteria

SOC for Cybersecurity - Cybersecurity Risk Management Examination SOC-CY-S1: Logical and Physical Access Controls

Controls to restrict logical and physical access to the cybersecurity infrastructure

What else in your programme already covers this

This control maps to 130 controls across 52 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 6 controls

ISO/IEC 27011:2024 · 4 controls

API 1164 · 3 controls

BSI IT-Grundschutz · 3 controls

  • BSI-03 Multi-factor authentication requirements
  • BSI-04 Remote access controls
  • BSI-05 Wireless access restrictions

IEC 62443 · 3 controls

ISO 13485 · 3 controls

ISO 27019 · 3 controls

ISO 27043 · 3 controls

ISO 27799 · 3 controls

ISO/IEC 27010:2015 · 3 controls

ISO/SAE 21434 · 3 controls

NIST SP 1800-32 · 3 controls

SOC 2 · 2 controls

  • SOC2-CC6.1 Implements logical access security software, infrastructure and architectures over protected information assets
  • SOC2-CC6.3 Role-based access and least privilege are enforced

South Korea ISMS-P · 2 controls

  • 58.43 Animal Care Facilities

APPI · 1 control

  • APPI-A26 Report of Leakage to the Commission and Notification to the Person
  • AT-DSG-6 Sections 12-13 - Image processing (video surveillance/CCTV)

Bahrain PDPL · 1 control

  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))
  • UAE-PDPL-Art.6_7 Sensitive personal data and children's data (UAE PDPL Articles 6-7)
  • 62351-8 Role-based access control (RBAC)

ISO 20000-1 · 1 control

ISO/IEC 27400:2022 · 1 control

ITIL 4 · 1 control

  • NIST-CSF-PR.AA-06 Physical access to assets is managed, monitored, and enforced commensurate with risk
  • 3.10 Encrypt Sensitive Data in Transit

Saudi Arabia PDPL · 1 control

Taiwan PDPA · 1 control

Uruguay DPL · 1 control

  • URUGUAY-3 Sensitive Data, Health Data, Children

Virginia CDPA · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in SOC for Cybersecurity: Security Criteria

Query this from an agent

The graph holds this control, the 130 it maps to, and the evidence behind each claim, over MCP and REST.