Home / Rules / SOC 2 (Trust Services Criteria) / SOC 2 CC6.3 Role-based access, least privilege and segregation of duties
SOC 2 CC6.3 Role-based access, least privilege and segregation of duties
Rights over data, programs, functions and other protected assets is granted, changed or removed according to roles, responsibilities or system design and changes, applying least privilege and segregation of duties. Points of focus: access is created or modified on the asset owner's authorisation; it is removed when no longer needed; access structures (role-based, for example) limit privileges and separate incompatible functions; and roles and access rules are reviewed periodically for people who no longer need them (staff, contractors, vendors, partner personnel) and for system or service accounts that should not exist, and adjusted.
Steps that cite it
Evidence commonly asked for
- Role definitions and role-to-permission matrix
- Change-of-role tickets showing old access removed
- Privileged access list and review evidence
- Segregation of duties rules, for example developers cannot deploy to production unaided
Accepted citation forms are listed on the answer format page.