User registration, authorisation, and de-provisioning
Summary
Prior to issuing system credentials and granting system access, the entity registers and authorises new internal and external users, and removes access when it is no longer required.
access controlprovisioningdeprovisioningoffboarding
Read the full official text: https://www.aicpa-cima.com/resources/download/2022-trust-services-criteria
Track SOC 2 criterion CC6.2 as evidence
eurocompliant maps this obligation to a checklist task and the evidence that satisfies it, alongside every other framework you follow.
Start free trial