SOC2 CC6.3
3 / 8

Role-Based Access Control

CC6 — Logical and Physical Access Controls  ·  Not yet reviewed

Status

What this control requires

The entity authorizes, modifies, or removes access to data, software, functions, and other protected information assets based on roles, responsibilities, or the system design and changes, giving consideration to the concepts of least privilege and segregation of duties.

Details

Notes — what's been done, what's missing, any gaps