CC6 Security Required

Logical & Physical Access Controls

Complete guide to CC6 Logical & Physical Access Controls controls. Plain-English explanations, AICPA text, risk levels, and evidence tips for each control.

8 Controls
3 Critical
3 High
CC6.1 critical

Logical Access Security Measures

You have implemented technical access controls (IAM, RBAC, MFA, SSO) that prevent unauthorized access to production systems and customer data. Access requires authentication.

View official AICPA language

The entity implements logical access security software, infrastructure, and architectures over protected information assets to protect them from security events.

What auditors look for

IAM configuration screenshots, MFA enrollment reports (must be 100%), SSO configuration, network firewall rules

CC6.2 critical

New Access Provisioning

When a new employee or contractor needs access, there is a formal process: request submitted, manager approved, access granted only after approval. No ad-hoc access grants.

View official AICPA language

Prior to issuing system credentials and granting system access, the entity registers and authorizes new internal and external users whose access is administered by the entity.

What auditors look for

Access request tickets (Jira/ServiceNow) showing requester, approver, and date. Onboarding checklist showing access provisioning steps.

CC6.3 critical

Access Removal on Termination

When an employee leaves, their access is revoked within a defined timeframe (typically 24 hours for terminations, immediate for involuntary). This must be consistently applied.

View official AICPA language

The entity authorizes, modifies, or removes access to data, software, functions, and other protected information assets based on roles, responsibilities, or the system design and changes.

What auditors look for

Offboarding checklist with access revocation steps, IAM audit logs showing account deactivation, HR termination records vs access logs

CC6.4 medium

Physical Access Controls

Physical access to offices, data centers, or server rooms is restricted and logged. For cloud-only companies, this means your cloud provider's data center controls (AWS/GCP/Azure SOC reports).

View official AICPA language

The entity restricts physical access to facilities and protected information assets to authorized individuals.

What auditors look for

AWS/GCP/Azure SOC 2 reports (sub-service organization), office access logs, security camera footage policy, visitor log

CC6.5 medium

Disposal of Assets

When disposing of hardware (laptops, hard drives), you have a documented process to wipe data before disposal. For cloud, this means terminating instances and ensuring data deletion.

View official AICPA language

The entity discontinues logical and physical protections over physical assets only after the ability to read or recover data and software from those assets has been diminished and is no longer required by the entity's commitments and system requirements.

What auditors look for

Asset disposal records, data destruction certificates, MDM remote wipe logs for decommissioned devices

CC6.6 high

Remote Access

Remote access to your production environment requires VPN and/or strong authentication (MFA + SSO). All remote sessions are logged. Malware protection is enforced on company endpoints.

View official AICPA language

The entity implements controls to prevent or detect and act upon the introduction of unauthorized or malicious software.

What auditors look for

VPN configuration and user list, MDM enrollment showing all endpoints have EDR/antivirus, MFA report for remote access users

CC6.7 high

Transmission and Movement of Data

Data is encrypted in transit (TLS 1.2+ on all endpoints). Sensitive data is not transmitted via unencrypted channels (email, Slack). Your API enforces HTTPS only.

View official AICPA language

The entity restricts the transmission, movement, and removal of information to authorized internal and external users and processes, and protects it during transmission.

What auditors look for

TLS certificate reports, API gateway configuration showing HTTPS enforcement, DLP policy documentation

CC6.8 high

Anti-Malware Controls

All employee endpoints have EDR/antivirus deployed and managed centrally. Your MDM enforces this. You have alerts for malware detection and a process to respond.

View official AICPA language

The entity implements controls to prevent or detect and act upon the introduction of unauthorized or malicious software.

What auditors look for

MDM dashboard showing endpoint coverage, EDR coverage report, malware detection alert logs from the review period

Track all 8 controls in your free checklist

Assign owners, collect evidence, and get your readiness score — no credit card required.

Start Free Today