Control Mapping Readerplace a control, see the map

SOC2-CC6.6 CC6.6 Protection against threats from outside the system boundary

SOC2-CC6.6 in SOC 2 (the AICPA 2017 Trust Services Criteria with the revised points of focus). All SOC 2 controls held. Open SOC 2 on the standards site.

The control as we hold it

CC6.6 Protection against threats from outside the system boundary. Logical access security measures protect against threats originating outside the system boundary. Points of focus: the kinds of activity allowed through each communication channel are limited; identification and authentication credentials are protected when sent outside the boundary; extra authentication is required for access from outside; and boundary protection such as firewalls, demilitarised zones, intrusion detection or prevention and endpoint detection and response is configured, maintained and monitored to guard external access points against attempted and unauthorised access.

Reviewed and closest counterparts in the other frameworks

Reviewed rows come from a released pair; a closest match is the nearest held text and is not a reviewed row.

HIPAA Security Rule

NIST SP 800-53 Rev 5

What an auditor commonly asks for

General guidance for this control area (domain: CC - Common Criteria (Security)), in our words, not a statement of the standard and not binding on an assessor.

Buy the reviewed crosswalk pair Place your own control