{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"technical","framework":"soc2","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/soc2/","description":"Prior to issuing system credentials and granting system access, the entity registers and authorizes new internal and external users whose access is administered by the entity. For those users whose access is administered by the entity, user system credentials are removed when user access is no longer authorized.","details":{"automation":"hybrid","control_category":"technical","control_id":"CC6.2","control_type":"preventive","domains":["Access Control & Identity Management"],"framework":"soc2","group":"Common Criteria (Security)","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"id":"ctrl:soc2:CC6.2","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Asoc2%3ACC6.2","sourceIds":["soc2"],"sourceUrl":null,"title":"CC6.2 — Prior to issuing system credentials and granting system access, the entity registers and authorizes new internal and external users whose access is administered by the entity. For those users whose access is administered by the entity, user system credentials are removed when user access is no longer authorized.","type":"control"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4ee0089acbdf1d0e8565a4ffa2e7291588b25371743b391fa62faf8fbc177232","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-soc2-cc6-2-639c148c.json","sourceId":"ctrl:soc2:CC6.2","targetDetailPath":"/data/v1/records/std-soc2-26a01d3b.json","targetId":"std:soc2","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6117926bb515257ea47cd345ef189a9f142cbfa7449115ed1f3f4253ea3ec625","properties":{"control_id":"CC6.2","coverage":"full","delta":null,"framework":"soc2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2017 TSC"},"sourceDetailPath":"/data/v1/records/uc-uc-access-01-1e70b922.json","sourceId":"uc:UC-ACCESS-01","targetDetailPath":"/data/v1/records/ctrl-soc2-cc6-2-639c148c.json","targetId":"ctrl:soc2:CC6.2","type":"maps_to"}],"schemaVersion":1}
