Requirement · SOC2-CC6.1

CC6.1 · Logical access security software, infrastructure and architectures

Controls (5)

ControlNameDomain
ACC-01MFA and SSO enforced for workforce accessAccess Control
ACC-03Privileged access is just-in-time and reviewedAccess Control
CHG-03Developers have no standing production access; deployments via pipeline onlyChange Management
ENC-01Customer and payment data encrypted at rest and in transitData Protection
PAY-01Payment APIs secured with mTLS, signing and customer 2FAPayments Security