Skip to content
compliancebase
SOC 2CC6 — Logical and Physical Access Controls

CC6.1

Logical and Physical Access Controls

SOC 2 · 2017 TSC (2022 Revised Points of Focus) · Last verified July 2026

Objective

The entity implements logical access security software, infrastructure, and architectures over protected information assets to protect them from security events to meet the entity's objectives.

Points of focus

  • Identifies and manages the inventory of information assets requiring protection
  • Restricts logical access to information assets to authorized users
  • Manages points of access to the system
  • Manages identification and authentication of users
  • Manages credentials for infrastructure and software

Implementation notes

Centralize workforce identity in one IdP with SSO into production and admin tools. Enforce MFA on all human access to production, cloud consoles, and privileged roles. Keep a living inventory of systems and service accounts with owners. Automate quarterly access-review packets from the IdP and retain dated sign-off plus remediations — AICPA CC6.1 is judged on logical access architectures and evidence, not calendar invites alone.

Audit tip: Bring a sample of access reviews that show population, reviewer, date, and remediations — not just a calendar invite.

Evidence auditors typically request:

  • Access control policy covering joiner-mover-leaver
  • Asset / system inventory tied to owners
  • IdP configuration (SSO, MFA enforcement)
  • Quarterly access review tickets with dated sign-off
  • Privileged account inventory and break-glass procedures

Common gaps

  • Access reviews without dated reviewer identity or change outcomes
  • MFA gaps on VPN, cloud consoles, or privileged roles
  • Orphaned service accounts and shared credentials
  • Incomplete inventory of SaaS apps holding customer data

Cross-Framework Mapping

FrameworkRequirementImplementation note
SOC 2CC6.1This control
ISO 27001A.5.15, A.8.2, A.8.3Access control and privileged access
HIPAA164.312(a)(1), 164.312(d)Access control & authentication
GDPRArticle 32(1)(b)Security of processing — access

Primary sources

Frequently Asked Questions

CC6.1 emphasizes logical access architectures over protected assets. Encryption at rest is a common complementary control auditors expect alongside IAM; cite your crypto standards under related criteria and system description claims.

Quarterly is common for SaaS SOC 2 programs. Higher-risk privileged access may need more frequent review. Every review needs a dated artifact naming the reviewer, population, and remediations completed.

CC6 addresses logical and physical access as a family. CC6.1 focuses on logical access security software and architectures; physical facility controls appear in related CC6 criteria and your data center/provider assurances.

Contractors and vendors with system access must be in scope for provisioning, MFA, and reviews — same as employees when they can reach protected assets. Time-box access and include them in review populations.

Common mappings include A.5.15, A.8.2, and A.8.3. Exact mapping belongs in your SoA / crosswalk, not as a claim of identical requirements between Trust Services Criteria and Annex A.

Framework versions referenced in this page:

  • SOC 22017 TSC (2022 Revised Points of Focus)

Last verified: July 2026 · Primary sources linked above