Control Mapping Readerplace a control, see the map

SOC2-CC6.4 CC6.4 Restricting physical access to facilities and assets

SOC2-CC6.4 in SOC 2 (the AICPA 2017 Trust Services Criteria with the revised points of focus). All SOC 2 controls held. Open SOC 2 on the standards site.

The control as we hold it

CC6.4 Restricting physical access to facilities and assets. Physical access to facilities and protected assets such as data centres, rooms holding backup media and other sensitive spaces is limited to authorised personnel. Points of focus: physical access for staff, contractors, vendors and partner personnel to data centres, offices and work areas is created or changed on appropriate authorisation; it is removed when no longer needed; organisation devices such as badges, laptops and phones are recovered when the holder no longer needs access (added in 2022); and access is reviewed periodically against job responsibilities. Where facilities are run by a hosting or cloud provider, the.

Reviewed and closest counterparts in the other frameworks

Reviewed rows come from a released pair; a closest match is the nearest held text and is not a reviewed row.

HIPAA Security Rule

NIST SP 800-53 Rev 5

What an auditor commonly asks for

General guidance for this control area (domain: CC - Common Criteria (Security)), in our words, not a statement of the standard and not binding on an assessor.

Buy the reviewed crosswalk pair Place your own control