CC6.6
Limits Access to System Components
SOC 2 · 2017 TSC (2022 Revised Points of Focus) · Last verified July 2026
Objective
The entity implements logical access security measures to protect against threats from sources outside its system boundaries.
Points of focus
- Restricts external access to system components
- Implements network and perimeter security measures
- Controls remote access channels
Implementation notes
AICPA CC6.6 focuses on logical measures that protect against threats from outside system boundaries. Prefer private networking, deny-by-default security groups, and SSO-backed VPN or ZTNA for admin paths. Continuously review public exposure — no ad-hoc open admin ports — and retain diagrams plus baseline configs as Type II evidence. Inventory every internet-facing endpoint (APIs, admin consoles, Bastion hosts) and map each to an owner and hardening baseline. Prefer temporary just-in-time access over standing VPN membership. When auditors sample, expect to show rule change history, exception tickets for any broad CIDR allowances, and remote-access authentication logs for the observation period — not a one-page network sketch created the week before fieldwork.
Audit tip: Be ready to explain how production is isolated and how remote admin access is authenticated and logged.
Evidence auditors typically request:
- Network diagrams / cloud security group baselines
- VPN or ZTNA configuration standards
- WAF / edge protection configs where used
- External vulnerability scan summaries
Common gaps
- Publicly exposed admin interfaces
- Overly permissive security groups
- Unreviewed third-party connections
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| SOC 2 | CC6.6 | This control |
| ISO 27001 | A.8.20, A.8.3 | Network security and information access restriction |
| HIPAA | 164.312(e)(1) | Transmission security |
| GDPR | Article 32(1) | Technical security measures |
Primary sources
- AICPA Trust Services Criteria: AICPA TSP Section 100 — 2017 Trust Services Criteria with 2022 Revised Points of Focus