← all controls
CC6.2SOC 2

Logical access - user registration and authorization

Before issuing credentials, the entity authorizes and registers new internal and external users.

Trust Service Criterion
CC
Audit period
type-2
Points of focus
  • Access requests require approval
  • User identities are verified before provisioning
  • Access is provisioned according to role