SOC2-CC6.2 CC6.2 Registering and authorising users before issuing credentials
SOC2-CC6.2 in SOC 2 (the AICPA 2017 Trust Services Criteria with the revised points of focus). All SOC 2 controls held. Open SOC 2 on the standards site.
The control as we hold it
CC6.2 Registering and authorising users before issuing credentials. Before system credentials are issued and access is granted, internal and external users whose access the organisation administers are registered and authorised; their credentials are removed once their access is no longer authorised. Points of focus (2022 revision): every kind of credential, for employees, contractors, vendors, partner staff, systems and software, is issued only after authorisation; credentials are reviewed periodically for continued validity, including inappropriate system or service accounts; and credentials that are no longer valid are disabled, destroyed or otherwise blocked from use.
Reviewed and closest counterparts in the other frameworks
Reviewed rows come from a released pair; a closest match is the nearest held text and is not a reviewed row.
HIPAA Security Rule
- 164.308(a)(3)(i) Workforce Security (Standard) (closest match)
- 164.308(a)(3)(ii)(A) Authorization and Supervision (Addressable) (closest match)
- 164.308(a)(3)(ii)(B) Workforce Clearance Procedure (Addressable) (closest match)
- 164.308(a)(3)(ii)(C) Termination Procedures (Addressable) (closest match)
- 164.308(a)(4)(i) Information Access Management (Standard) (closest match)
- 164.308(a)(4)(ii)(B) Access Authorization (Addressable) (closest match)
- 164.308(a)(4)(ii)(C) Access Establishment and Modification (Addressable) (closest match)
- 164.308(a)(5)(ii)(D) Password Management (Addressable) (closest match)
NIST SP 800-53 Rev 5
- NIST800-AC-1 AC-1 Policy and Procedures (closest match)
- NIST800-AC-2 AC-2 Account Management (closest match)
- NIST800-AC-3 AC-3 Access Enforcement (closest match)
- NIST800-AC-14 AC-14 Permitted Actions Without Identification or Authentication (closest match)
- NIST800-AC-17 AC-17 Remote Access (closest match)
- NIST800-AC-21 AC-21 Information Sharing (closest match)
- NIST800-AC-24 AC-24 Access Control Decisions (closest match)
- NIST800-AT-3 AT-3 Role-based Training (closest match)
What an auditor commonly asks for
General guidance for this control area (domain: CC - Common Criteria (Security)), in our words, not a statement of the standard and not binding on an assessor.
- the board or management oversight record
- the risk assessment and its treatment
- the access-review and change-approval records
- the monitoring, logging and incident records