Control Mapping Readerplace a control, see the map

SOC2-CC6.1 CC6.1 Logical access security over protected information assets

SOC2-CC6.1 in SOC 2 (the AICPA 2017 Trust Services Criteria with the revised points of focus). All SOC 2 controls held. Open SOC 2 on the standards site.

The control as we hold it

CC6.1 Logical access security over protected information assets. Access security software, infrastructure and architecture are in place over protected information assets to guard them against security events. Points of focus: information assets are inventoried, classified and managed; logical access to hardware, data at rest, in processing and in transit, software, admin rights, mobile devices, output and offline components is limited through access control software and rules; users, devices and software prove who they are before they get in, locally or remotely; networks are segmented so unrelated parts are isolated; external points of access and the data and users passing through them are.

Reviewed and closest counterparts in the other frameworks

Reviewed rows come from a released pair; a closest match is the nearest held text and is not a reviewed row.

ISO 27001:2022

HIPAA Security Rule

NIST SP 800-53 Rev 5

What an auditor commonly asks for

General guidance for this control area (domain: CC - Common Criteria (Security)), in our words, not a statement of the standard and not binding on an assessor.

Buy the reviewed crosswalk pair Place your own control