๐ผ CC6.3-4 Reviews Access Roles and Rules
- Contextual name: ๐ผ CC6.3-4 Reviews Access Roles and Rules
- ID:
/frameworks/soc-2/cc6/03/04
- Located in: ๐ผ CC6.3 The entity authorizes, modifies, or removes access to data, software, functions, and other protected information assets based on roles, responsibilities, or the system design and changes, giving consideration to the concepts of least privilege and segregation of duties, to meet the entity's objectives.
Descriptionโ
The appropriateness of access roles and access rules is reviewed on a periodic basis for unnecessary and inappropriate individuals (for example, employees, contractors, vendors, business partner personnel) and inappropriate system or service accounts. Access roles and rules are modified, as appropriate.
Similarโ
Sub Sectionsโ
Section | Sub Sections | Internal Rules | Policies | Flags |
---|