Home / Rules / SOC 2 (Trust Services Criteria) / SOC 2 CC6.2 Registering and authorising users before issuing credentials
SOC 2 CC6.2 Registering and authorising users before issuing credentials
Before system credentials are issued and access is granted, internal and external users whose access the organisation administers are registered and authorised; their credentials are removed once their access is no longer authorised. Points of focus (2022 revision): every kind of credential, for employees, contractors, vendors, partner staff, systems and software, is issued only after authorisation; credentials are reviewed periodically for continued validity, including inappropriate system or service accounts; and credentials that are no longer valid are disabled, destroyed or otherwise blocked from use.
Steps that cite it
- KC-01 S6 Decide the vendor's access
- KC-08 S1 Find the leaver exceptions
- KC-08 S3 Fix the still-open access
Evidence commonly asked for
- Access request tickets with owner approval for a sample of new users, service accounts and API credentials
- Termination records reconciled to account disablement dates
- Periodic credential validity review sign-offs covering human, system and service accounts, with remediation of findings
- Revocation records for keys, tokens and certificates no longer valid
Accepted citation forms are listed on the answer format page.