CC6.1 Implements logical access security software, infrastructure and architectures over protected information assets
Restricts logical access to protected information assets using access control software, supporting infrastructure and system architectures, covering inventory and classification of information assets, identification and
6
artefacts
2
held by a system
1
at each review
moderate
to go live
Identity provider / directory
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Access control software configuration and the rule sets that enforce it · Identity provider / directory
- Joiner, mover and leaver records showing credential issue and removal for people, infrastructure and software · Identity provider / directory
periodic reviewEvidence produced at each review
- Network segmentation design with firewall or ACL rule review evidence · Identity provider / directory
governing documentDocuments that govern the control
- Inventory of information assets with classification and owner · Policy repository / GRC workspace
- Register of points of access used by outside entities and the data that flows through each · Policy repository / GRC workspace
- Encryption standard covering data at rest and in transit, with key generation, storage, use and destruction records · Policy repository / GRC workspace
First move
Start with the 2 of 6 artefacts that already live in a system (Identity provider / directory); keep the periodic reviews but log each one as a dated record with a named reviewer.
Common gaps auditors find
- Physical access evidence offered against a criterion that is logical only, which belongs at CC6.4
- Asset inventory incomplete, so unmanaged systems sit outside the access control rule sets
- Service, machine and infrastructure accounts excluded from identification and authentication
- Encryption keys held by the same administrators the encryption is meant to constrain
- Credentials for decommissioned infrastructure and software never removed
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetCC5.3 COSO principle 12: Deploys control activities through policies and procedures · CC6.2 Prior to granting access, registration and authorization processes are established