Skip to main content

Repository → 💼 SOC 2 → 💼 CC6 Logical and Physical Access Controls

💼 CC6.3 The entity authorizes, modifies, or removes access to data, software, functions, and other protected information assets based on roles, responsibilities, or the system design and changes, giving consideration to the concepts of least privilege and segregation of duties, to meet the entity's objectives.

  • ID: /frameworks/soc-2/cc6/03

Description

Empty...

Similar

Sub Sections

SectionSub SectionsInternal RulesPoliciesFlagsCompliance
💼 CC6.3-1 Creates or Modifies Access to Protected Information Assets3no data
💼 CC6.3-2 Removes Access to Protected Information Assets3no data
💼 CC6.3-3 Uses Access Control Structures14no data
💼 CC6.3-4 Reviews Access Roles and Rulesno data