Theme comparison · access-control
Access control across frameworks
How logical access control shows up across SOC 2, ISO 27001, GDPR, and HIPAA — shared intent, different evidence shapes.
Frameworks covered: SOC 2, ISO/IEC 27001, GDPR, HIPAA
Key differences
| Dimension | SOC 2 / ISO (assurance) | GDPR / HIPAA (legal) |
|---|---|---|
| Primary source of obligation | SOC 2 CC6 criteria and ISO/IEC 27001:2022 Annex A access themes (customer attestation or certification artifacts) | GDPR Article 32 technical and organisational measures and HIPAA Security Rule access controls at 45 CFR §164.312 (legal / regulatory duties) |
| Evidence shape | Policies, IdP configs, dated access reviews, MFA enforcement screenshots, joiner-mover-leaver tickets sampled over a Type II window or ISMS period | Documented measures appropriate to risk (GDPR); HIPAA required vs addressable specifications with implementation or equivalent rationale on file |
| Audience | Buyers, CPA firms, and certification bodies evaluating a service organization or ISMS | Supervisory authorities, covered entities, business associates, and contractual counterparties enforcing law — not interchangeable with a SOC 2 report |
| Failure mode | Sample exceptions, stale reviews, or system-description mismatches that qualify an attestation opinion or nonconformity | Regulatory investigation, contractual breach, or OCR/EDPB scrutiny when access measures are missing, undocumented, or unjustified |
Control overlap
Identity lifecycle, least privilege, MFA, encryption in transit, and periodic access reviews appear across SOC 2 CC6, ISO Annex A (for example A.5.15 / A.8.x themes), GDPR Article 32, and HIPAA §164.312. The operating system can be shared — one IdP, one review calendar, one remote-access pattern — while the vocabulary and artifacts differ. Map once in a crosswalk: control owner, evidence location, and which framework clause each artifact supports. Do not assume a SOC 2 sample set automatically satisfies HIPAA addressable documentation or GDPR accountability records.
Sequencing advice
Build one IAM and access-review operating rhythm first (usually against SOC 2 CC6.1–CC6.3 patterns), then annotate the same evidence for ISO SoA lines, GDPR Article 32 measures, and HIPAA required/addressable decisions. Avoid four parallel access programs with four review cadences. If you process PHI, complete HIPAA access and transmission decisions in parallel with SOC 2 — attestation does not replace the Security Rule. Start from /controls/soc-2/cc6-1 and expand outward; use /compare/soc-2-vs-iso-27001 for dual-track sequencing at the program level.