Skip to content
compliancebase
SOC 2CC6 — Limits Access to System Components

CC6.6

Limits Access to System Components

SOC 2 · 2017 TSC (2022 Revised Points of Focus) · Last verified July 2026

Objective

The entity implements logical access security measures to protect against threats from sources outside its system boundaries.

Points of focus

  • Restricts external access to system components
  • Implements network and perimeter security measures
  • Controls remote access channels

Implementation notes

AICPA CC6.6 focuses on logical measures that protect against threats from outside system boundaries. Prefer private networking, deny-by-default security groups, and SSO-backed VPN or ZTNA for admin paths. Continuously review public exposure — no ad-hoc open admin ports — and retain diagrams plus baseline configs as Type II evidence. Inventory every internet-facing endpoint (APIs, admin consoles, Bastion hosts) and map each to an owner and hardening baseline. Prefer temporary just-in-time access over standing VPN membership. When auditors sample, expect to show rule change history, exception tickets for any broad CIDR allowances, and remote-access authentication logs for the observation period — not a one-page network sketch created the week before fieldwork.

Audit tip: Be ready to explain how production is isolated and how remote admin access is authenticated and logged.

Evidence auditors typically request:

  • Network diagrams / cloud security group baselines
  • VPN or ZTNA configuration standards
  • WAF / edge protection configs where used
  • External vulnerability scan summaries

Common gaps

  • Publicly exposed admin interfaces
  • Overly permissive security groups
  • Unreviewed third-party connections

Cross-Framework Mapping

FrameworkRequirementImplementation note
SOC 2CC6.6This control
ISO 27001A.8.20, A.8.3Network security and information access restriction
HIPAA164.312(e)(1)Transmission security
GDPRArticle 32(1)Technical security measures

Primary sources

Frequently Asked Questions

Not uniquely — zero-trust network access can satisfy remote access control if users are authenticated, authorized, and logged. Document the chosen pattern and keep configuration standards current for auditor walkthroughs.

Availability protections may fall under availability criteria if that category is in scope. Still document edge protections (CDN, WAF, rate limits) that limit external exposure as part of your boundary story under CC6.6.

CC6.1 is identity and access foundations — inventory, authentication, and restricting who may use assets. CC6.6 emphasizes protecting against external threats at and beyond network boundaries: exposure, remote channels, and perimeter controls.

Yes — document what you configure versus what the provider assures, keep your security-group and remote-access configs evidenced, and retain current provider reports for inherited network and facility layers.

Often firewall or security-group rules, remote access configuration and logs, and exceptions to baseline hardening. Be ready to explain any public endpoints and how admin paths are restricted.

Framework versions referenced in this page:

  • SOC 22017 TSC (2022 Revised Points of Focus)

Last verified: July 2026 · Primary sources linked above