SOC2-CC6.4 CC6.4 Restricting physical access to facilities and assets
SOC2-CC6.4 in SOC 2 (the AICPA 2017 Trust Services Criteria with the revised points of focus). All SOC 2 controls held. Open SOC 2 on the standards site.
The control as we hold it
CC6.4 Restricting physical access to facilities and assets. Physical access to facilities and protected assets such as data centres, rooms holding backup media and other sensitive spaces is limited to authorised personnel. Points of focus: physical access for staff, contractors, vendors and partner personnel to data centres, offices and work areas is created or changed on appropriate authorisation; it is removed when no longer needed; organisation devices such as badges, laptops and phones are recovered when the holder no longer needs access (added in 2022); and access is reviewed periodically against job responsibilities. Where facilities are run by a hosting or cloud provider, the.
Reviewed and closest counterparts in the other frameworks
Reviewed rows come from a released pair; a closest match is the nearest held text and is not a reviewed row.
HIPAA Security Rule
- 164.310(a)(1) Facility Access Controls (Standard) (closest match)
- 164.310(a)(2)(ii) Facility Security Plan (Addressable) (closest match)
- 164.310(a)(2)(iii) Access Control and Validation Procedures (Addressable) (closest match)
- 164.310(a)(2)(iv) Maintenance Records (Addressable) (closest match)
- 164.310(b) Workstation Use (Standard) (closest match)
- 164.310(c) Workstation Security (Standard) (closest match)
- 164.310(d)(1) Device and Media Controls (Standard) (closest match)
- 164.310(d)(2)(iii) Accountability (Addressable) (closest match)
NIST SP 800-53 Rev 5
- NIST800-MA-5 MA-5 Maintenance Personnel (closest match)
- NIST800-MA-7 MA-7 Field Maintenance (closest match)
- NIST800-MP-2 MP-2 Media Access (closest match)
- NIST800-MP-4 MP-4 Media Storage (closest match)
- NIST800-MP-5 MP-5 Media Transport (closest match)
- NIST800-PE-1 PE-1 Policy and Procedures (closest match)
- NIST800-PE-2 PE-2 Physical Access Authorizations (closest match)
- NIST800-PE-3 PE-3 Physical Access Control (closest match)
What an auditor commonly asks for
General guidance for this control area (domain: CC - Common Criteria (Security)), in our words, not a statement of the standard and not binding on an assessor.
- the board or management oversight record
- the risk assessment and its treatment
- the access-review and change-approval records
- the monitoring, logging and incident records