Cybersecurity GRC 17 items
SOC 2 Logical & Physical Access Control Audit
Audits logical and physical access controls against the SOC 2 CC6 series covering provisioning, authentication, and de-provisioning.
SOC 2AICPA TSC
Free PDF · enter your email to download.
Access Provisioning & Authorization
- Is logical access to systems restricted through role-based authorization approved by an owner? *
- Are new user access requests documented and approved before access is granted? *
- Is access granted based on the principle of least privilege? *
- Are privileged/administrative accounts inventoried and restricted to authorized personnel? *
Authentication
- Is multi-factor authentication enforced for remote and administrative access? *
- Does a password policy enforce complexity, length, and rotation requirements? *
- Are shared or generic accounts prohibited, or compensating controls documented where required? *
Access Review & De-Provisioning
- Are user access rights reviewed at least quarterly? *
- Is access revoked within a defined SLA upon termination or role change? *
- What is the target SLA in hours for revoking access upon termination?
- Are terminated user accounts confirmed disabled through periodic review? *
Physical Access
- Is physical access to facilities and data centers restricted to authorized personnel? *
- Are physical access rights reviewed and revoked upon termination? *
- Are visitors logged and escorted within restricted areas? *
Data Transmission & Disposal
- Is data encrypted in transit using approved protocols (TLS 1.2+)? *
- Are removable media and endpoints controlled to prevent unauthorized data movement? *
- Is media and hardware sanitized or destroyed before disposal or reuse? *
Download the full SOC 2 Logical & Physical Access Control Audit checklist
Get it as a clean, printable PDF — free.
