SOC2-CC6.6 CC6.6 Protection against threats from outside the system boundary
SOC2-CC6.6 in SOC 2 (the AICPA 2017 Trust Services Criteria with the revised points of focus). All SOC 2 controls held. Open SOC 2 on the standards site.
The control as we hold it
CC6.6 Protection against threats from outside the system boundary. Logical access security measures protect against threats originating outside the system boundary. Points of focus: the kinds of activity allowed through each communication channel are limited; identification and authentication credentials are protected when sent outside the boundary; extra authentication is required for access from outside; and boundary protection such as firewalls, demilitarised zones, intrusion detection or prevention and endpoint detection and response is configured, maintained and monitored to guard external access points against attempted and unauthorised access.
Reviewed and closest counterparts in the other frameworks
Reviewed rows come from a released pair; a closest match is the nearest held text and is not a reviewed row.
HIPAA Security Rule
- 164.308(a)(1)(ii)(A) Risk Analysis (Required) (closest match)
- 164.308(a)(4)(ii)(A) Isolating Health Care Clearinghouse Functions (Required if applicable) (closest match)
- 164.312(b) Audit Controls (Standard) (closest match)
- 164.312(c)(2) Mechanism to Authenticate ePHI (Addressable) (closest match)
- 164.312(d) Person or Entity Authentication (Standard) (closest match)
- 164.312(e)(1) Transmission Security (Standard) (closest match)
- 164.312(e)(2)(ii) Encryption of Transmissions (Addressable) (closest match)
NIST SP 800-53 Rev 5
- NIST800-AC-12 AC-12 Session Termination (closest match)
- NIST800-AC-17 AC-17 Remote Access (closest match)
- NIST800-AC-18 AC-18 Wireless Access (closest match)
- NIST800-AC-19 AC-19 Access Control for Mobile Devices (closest match)
- NIST800-AC-20 AC-20 Use of External Systems (closest match)
- NIST800-AU-16 AU-16 Cross-organizational Audit Logging (closest match)
- NIST800-CA-9 CA-9 Internal System Connections (closest match)
- NIST800-CP-8 CP-8 Telecommunications Services (closest match)
What an auditor commonly asks for
General guidance for this control area (domain: CC - Common Criteria (Security)), in our words, not a statement of the standard and not binding on an assessor.
- the board or management oversight record
- the risk assessment and its treatment
- the access-review and change-approval records
- the monitoring, logging and incident records