Requirement · SOC2-CC6.1
CC6.1 · Logical access security software, infrastructure and architectures
Controls (5)
| Control | Name | Domain |
|---|---|---|
| ACC-01 | MFA and SSO enforced for workforce access | Access Control |
| ACC-03 | Privileged access is just-in-time and reviewed | Access Control |
| CHG-03 | Developers have no standing production access; deployments via pipeline only | Change Management |
| ENC-01 | Customer and payment data encrypted at rest and in transit | Data Protection |
| PAY-01 | Payment APIs secured with mTLS, signing and customer 2FA | Payments Security |