CC6.7
Restricts Transmission of Information
SOC 2 · 2017 TSC (2022 Revised Points of Focus) · Last verified July 2026
Objective
The entity restricts the transmission, movement, and removal of information to authorized internal and external users and processes, and protects it during transmission.
Points of focus
- Protects data during transmission
- Restricts movement/removal of information to authorized channels
- Uses encryption or equivalent protections for sensitive transit
Implementation notes
Enforce HTTPS everywhere customer or admin data moves, disable legacy TLS, and inventory bulk export and support-tool features that can remove data. Apply least privilege to who can run exports. Under AICPA CC6.7, protect transmission and restrict movement to authorized channels — document approved paths and encryption standards for Type II evidence. Treat support tooling, warehouse syncs, and partner SFTP drops as transmission channels with the same scrutiny as customer-facing APIs. Keep a short allowlist of approved transfer mechanisms and reject ad-hoc email or chat exports of production data. For the observation window, retain TLS configuration baselines, certificate inventories, and samples of export approvals so auditors can follow how data left the boundary — not only that encryption exists in theory.
Audit tip: Show encryption in transit for customer data paths and explain approved egress channels.
Evidence auditors typically request:
- TLS configuration standards / certificates
- DLP or egress controls where used
- Secure file transfer procedures
- Email/outbound data handling policy
Common gaps
- Cleartext admin protocols on internal networks
- Untracked exports to personal storage
- Expired or weak TLS configurations
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| SOC 2 | CC6.7 | This control |
| ISO 27001 | A.8.24, A.5.14 | Cryptography & information transfer |
| HIPAA | 164.312(e)(1) | Transmission security |
| GDPR | Article 32(1)(a) | Pseudonymisation/encryption measures |
Primary sources
- AICPA Trust Services Criteria: AICPA TSP Section 100 — 2017 Trust Services Criteria with 2022 Revised Points of Focus