control

CC6.3 — The entity authorizes, modifies, or removes access to data, software, functions, and other protected information assets based on roles, responsibilities, or the system design and changes, giving consideration to the concepts of least privilege and segregation of duties, to meet the entity's objectives.

The entity authorizes, modifies, or removes access to data, software, functions, and other protected information assets based on roles, responsibilities, or the system design and changes, giving consideration to the concepts of least privilege and segregation of duties, to meet the entity's objectives.

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

framework
soc2
type
preventive
category
technical

Details

control_id
CC6.3
framework
soc2
group
Common Criteria (Security)
domains
  • Access Control & Identity Management
risk_count
7
control_type
preventive
control_category
technical
automation
hybrid
key_control
True
requirement_status
Not provided
requirement_frequency
Not provided
source_url
Not provided
source_pages
Not provided

Source

No record-specific source URL is provided.

Connections