simpl.
Cybersecurity GRC 17 items

SOC 2 Logical & Physical Access Control Audit

Audits logical and physical access controls against the SOC 2 CC6 series covering provisioning, authentication, and de-provisioning.

SOC 2AICPA TSC

Free PDF · enter your email to download.

Access Provisioning & Authorization

  • Is logical access to systems restricted through role-based authorization approved by an owner? *
  • Are new user access requests documented and approved before access is granted? *
  • Is access granted based on the principle of least privilege? *
  • Are privileged/administrative accounts inventoried and restricted to authorized personnel? *

Authentication

  • Is multi-factor authentication enforced for remote and administrative access? *
  • Does a password policy enforce complexity, length, and rotation requirements? *
  • Are shared or generic accounts prohibited, or compensating controls documented where required? *

Access Review & De-Provisioning

  • Are user access rights reviewed at least quarterly? *
  • Is access revoked within a defined SLA upon termination or role change? *
  • What is the target SLA in hours for revoking access upon termination?
  • Are terminated user accounts confirmed disabled through periodic review? *

Physical Access

  • Is physical access to facilities and data centers restricted to authorized personnel? *
  • Are physical access rights reviewed and revoked upon termination? *
  • Are visitors logged and escorted within restricted areas? *

Data Transmission & Disposal

  • Is data encrypted in transit using approved protocols (TLS 1.2+)? *
  • Are removable media and endpoints controlled to prevent unauthorized data movement? *
  • Is media and hardware sanitized or destroyed before disposal or reuse? *

Download the full SOC 2 Logical & Physical Access Control Audit checklist

Get it as a clean, printable PDF — free.