Logical & Physical Access Controls
Complete guide to CC6 Logical & Physical Access Controls controls. Plain-English explanations, AICPA text, risk levels, and evidence tips for each control.
Logical Access Security Measures
Plain English
You have implemented technical access controls (IAM, RBAC, MFA, SSO) that prevent unauthorized access to production systems and customer data. Access requires authentication.
View official AICPA language
The entity implements logical access security software, infrastructure, and architectures over protected information assets to protect them from security events.
What auditors look for
IAM configuration screenshots, MFA enrollment reports (must be 100%), SSO configuration, network firewall rules
New Access Provisioning
Plain English
When a new employee or contractor needs access, there is a formal process: request submitted, manager approved, access granted only after approval. No ad-hoc access grants.
View official AICPA language
Prior to issuing system credentials and granting system access, the entity registers and authorizes new internal and external users whose access is administered by the entity.
What auditors look for
Access request tickets (Jira/ServiceNow) showing requester, approver, and date. Onboarding checklist showing access provisioning steps.
Access Removal on Termination
Plain English
When an employee leaves, their access is revoked within a defined timeframe (typically 24 hours for terminations, immediate for involuntary). This must be consistently applied.
View official AICPA language
The entity authorizes, modifies, or removes access to data, software, functions, and other protected information assets based on roles, responsibilities, or the system design and changes.
What auditors look for
Offboarding checklist with access revocation steps, IAM audit logs showing account deactivation, HR termination records vs access logs
Physical Access Controls
Plain English
Physical access to offices, data centers, or server rooms is restricted and logged. For cloud-only companies, this means your cloud provider's data center controls (AWS/GCP/Azure SOC reports).
View official AICPA language
The entity restricts physical access to facilities and protected information assets to authorized individuals.
What auditors look for
AWS/GCP/Azure SOC 2 reports (sub-service organization), office access logs, security camera footage policy, visitor log
Disposal of Assets
Plain English
When disposing of hardware (laptops, hard drives), you have a documented process to wipe data before disposal. For cloud, this means terminating instances and ensuring data deletion.
View official AICPA language
The entity discontinues logical and physical protections over physical assets only after the ability to read or recover data and software from those assets has been diminished and is no longer required by the entity's commitments and system requirements.
What auditors look for
Asset disposal records, data destruction certificates, MDM remote wipe logs for decommissioned devices
Remote Access
Plain English
Remote access to your production environment requires VPN and/or strong authentication (MFA + SSO). All remote sessions are logged. Malware protection is enforced on company endpoints.
View official AICPA language
The entity implements controls to prevent or detect and act upon the introduction of unauthorized or malicious software.
What auditors look for
VPN configuration and user list, MDM enrollment showing all endpoints have EDR/antivirus, MFA report for remote access users
Transmission and Movement of Data
Plain English
Data is encrypted in transit (TLS 1.2+ on all endpoints). Sensitive data is not transmitted via unencrypted channels (email, Slack). Your API enforces HTTPS only.
View official AICPA language
The entity restricts the transmission, movement, and removal of information to authorized internal and external users and processes, and protects it during transmission.
What auditors look for
TLS certificate reports, API gateway configuration showing HTTPS enforcement, DLP policy documentation
Anti-Malware Controls
Plain English
All employee endpoints have EDR/antivirus deployed and managed centrally. Your MDM enforces this. You have alerts for malware detection and a process to respond.
View official AICPA language
The entity implements controls to prevent or detect and act upon the introduction of unauthorized or malicious software.
What auditors look for
MDM dashboard showing endpoint coverage, EDR coverage report, malware detection alert logs from the review period
Track all 8 controls in your free checklist
Assign owners, collect evidence, and get your readiness score — no credit card required.
Start Free Today