Free compliance framework explorer — browse controls, evidence, and implementation guidance.Subscribe for updates →
SOC 247
ITSP.10.17198
ISO 42001soon
ISO 27001soon

Browse

33 controls

CC6.2Registration and authorization prior to issuing credentialsSOC 2Logical and Physical Access Controls

Official Requirement

Prior to issuing system credentials and granting system access, the entity registers and authorizes new internal and external users whose access is administered by the entity. For those users whose access is administered by the entity, user system credentials are removed when user access is no longer authorized.

Source: AICPA Trust Services Criteria (2017), incorporating COSO principles

In Plain English

Every account that exists in your systems must trace back to an approved provisioning request. When someone joins, there's a documented, approved ticket before credentials are issued. When someone leaves, especially involuntarily, access is revoked within a defined SLA. Auditors will sample onboarding and offboarding events and ask you to produce the approval record for each.

Help us build what matters.

Vote for the next framework, subscribe for updates, and let us know if you'd contribute.

The Trust Services Criteria referenced in this tool are published by the American Institute of Certified Public Accountants (AICPA) and incorporate principles from the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Criteria descriptions are reproduced for reference purposes. All implementation guidance, evidence recommendations, and control language are original work by Truvo Cyber. ISO 27001 and ISO 42001 are standards published by the International Organization for Standardization (ISO). Framework and standard names are the property of their respective owners. This tool is not affiliated with, endorsed by, or certified by AICPA, COSO, or ISO.

© 2026 Truvo Cyber. All rights reserved.

On-premises implementation and evidence

Provisioning workflow with documented approval before access is granted

Implementation steps

  1. New hire access requests are submitted as tickets with explicit approval from the hiring manager before Active Directory account creation
  2. Map job roles to AD groups via an RBAC matrix, provisioning adds users to groups, not individual permission assignments
  3. Document approval in the ticket before executing: approver name, approved systems, approved role, date
  4. For VPN and bastion host access, require a separate approval step, not all staff need production infrastructure access

Tools / systems

Evidence artifacts

Evidence frequency: Sample tickets collected quarterly; AD event log pulled at audit window close

Termination access revocation within defined SLA

Implementation steps

  1. Disable the Active Directory account immediately upon termination, this revokes login, VPN, and any Kerberos-authenticated service
  2. Revoke VPN certificate or remove user from RADIUS group within the same ticket
  3. Remove SSH authorized_keys from bastion and production servers for the terminated user
  4. Offboarding ticket must list every system, show removal confirmation, and be closed within the SLA window

Tools / systems

Evidence artifacts

Evidence frequency: All termination events form the population; collected and uploaded at audit window close