← SOC 2 · CC6 — Logical and Physical Access
CC6.2 — Registration and authorisation of new users
high
access-controlonboarding
Requirement
Prior to issuing system credentials, the entity registers and authorises new internal and external users, and removes access when it is no longer required.
What the engine looks for
Every group below must be satisfied — by an affirmative statement, not a plan, a hedge or a denial — for the control to count as covered. A term ending in … matches any word it begins. Supporting terms do not change the verdict — they raise confidence and distinguish a policy that names a mechanism from one that gestures at a category.
Required element 1 — any one of
user registrationonboardingaccess requestprovisioningonboardprovisionon joininginductionnew startersnew joiners
Required element 2 — any one of
approvalauthorisedauthorizedmanagerapprove
Supporting terms — specificity signals
ticketjoinerworkflowdocumented request
Equivalent controls elsewhere
Matched on shared topics. Satisfying this control usually moves these too.
| Framework | Control | Title | Shared topics |
|---|---|---|---|
| ISO 27001 | A.5.16 | Identity management | access-control onboarding |
| GDPR | Art.29 | Processing under the authority of the controller | access-control |
| CCPA/CPRA | 1798.100(e) & 1798.150 | Reasonable security procedures | access-control |
| ISO 27001 | A.5.3 | Segregation of duties | access-control |
| ISO 27001 | A.5.15 | Access control | access-control |
| ISO 27001 | A.5.18 | Access rights review | access-control |
| ISO 27001 | A.6.1 | Screening | onboarding |
| ISO 27001 | A.6.2 | Terms and conditions of employment | onboarding |