CC6.1
Logical and Physical Access Controls
SOC 2 · 2017 TSC (2022 Revised Points of Focus) · Last verified July 2026
Objective
The entity implements logical access security software, infrastructure, and architectures over protected information assets to protect them from security events to meet the entity's objectives.
Points of focus
- Identifies and manages the inventory of information assets requiring protection
- Restricts logical access to information assets to authorized users
- Manages points of access to the system
- Manages identification and authentication of users
- Manages credentials for infrastructure and software
Implementation notes
Centralize workforce identity in one IdP with SSO into production and admin tools. Enforce MFA on all human access to production, cloud consoles, and privileged roles. Keep a living inventory of systems and service accounts with owners. Automate quarterly access-review packets from the IdP and retain dated sign-off plus remediations — AICPA CC6.1 is judged on logical access architectures and evidence, not calendar invites alone.
Audit tip: Bring a sample of access reviews that show population, reviewer, date, and remediations — not just a calendar invite.
Evidence auditors typically request:
- Access control policy covering joiner-mover-leaver
- Asset / system inventory tied to owners
- IdP configuration (SSO, MFA enforcement)
- Quarterly access review tickets with dated sign-off
- Privileged account inventory and break-glass procedures
Common gaps
- Access reviews without dated reviewer identity or change outcomes
- MFA gaps on VPN, cloud consoles, or privileged roles
- Orphaned service accounts and shared credentials
- Incomplete inventory of SaaS apps holding customer data
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| SOC 2 | CC6.1 | This control |
| ISO 27001 | A.5.15, A.8.2, A.8.3 | Access control and privileged access |
| HIPAA | 164.312(a)(1), 164.312(d) | Access control & authentication |
| GDPR | Article 32(1)(b) | Security of processing — access |
Primary sources
- AICPA Trust Services Criteria: AICPA TSP Section 100 — 2017 Trust Services Criteria with 2022 Revised Points of Focus