Role-based access and least privilege
Summary
The entity authorises, modifies, or removes access to data, software, functions, and other protected information assets based on roles, responsibilities, and the principle of least privilege.
Read the full official text: https://www.aicpa-cima.com/resources/download/2022-trust-services-criteria
← Criterion CC6.2
User registration, authorisation, and de-provisioning
Criterion CC6.4 →
Physical access restriction
Track SOC 2 criterion CC6.3 as evidence
eurocompliant maps this obligation to a checklist task and the evidence that satisfies it, alongside every other framework you follow.
Start free trial