Free compliance framework explorer — browse controls, evidence, and implementation guidance.Subscribe for updates →
SOC 247
ITSP.10.17198
ISO 42001soon
ISO 27001soon

Browse

33 controls

CC6.3Role-based access managementSOC 2Logical and Physical Access Controls

Official Requirement

The entity authorizes, modifies, or removes access to data, software, functions, and other protected information assets based on roles, responsibilities, or the system design and changes, giving consideration to the concepts of least privilege and segregation of duties to meet the entity's objectives.

Source: AICPA Trust Services Criteria (2017), incorporating COSO principles

In Plain English

Access is assigned based on what someone's job requires, not what they ask for or what is convenient. When roles change, access changes. No one has more access than they need, and no single person can both approve and execute a sensitive action. This is where many teams struggle, the RBAC matrix exists but is never enforced consistently.

Help us build what matters.

Vote for the next framework, subscribe for updates, and let us know if you'd contribute.

The Trust Services Criteria referenced in this tool are published by the American Institute of Certified Public Accountants (AICPA) and incorporate principles from the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Criteria descriptions are reproduced for reference purposes. All implementation guidance, evidence recommendations, and control language are original work by Truvo Cyber. ISO 27001 and ISO 42001 are standards published by the International Organization for Standardization (ISO). Framework and standard names are the property of their respective owners. This tool is not affiliated with, endorsed by, or certified by AICPA, COSO, or ISO.

© 2026 Truvo Cyber. All rights reserved.

On-premises implementation and evidence

Periodic user access reviews against RBAC matrix

Implementation steps

  1. Export AD group membership for all production-access groups; export VPN user list and bastion authorized accounts
  2. Cross-reference against current HR roster, anyone who left or changed roles since the last review is a finding
  3. Review privileged groups (Domain Admins, local Administrators on production servers), these should have the fewest members
  4. Sign and date the review coversheet; file it as audit evidence

Tools / systems

Evidence artifacts

Evidence frequency: Quarterly for infrastructure and application; semi-annual minimum; annual for SaaS

Least privilege for production infrastructure access

Implementation steps

  1. Remove all shared/generic admin accounts, every admin must have a named account with individual accountability
  2. Restrict Domain Admin membership to the absolute minimum; use tiered admin accounts (tier 0 / tier 1 model)
  3. Administrative access to production servers is restricted to the management network; no direct RDP/SSH from user VLAN
  4. Document the intended privilege level for each role in the RBAC matrix and review deviations quarterly

Tools / systems

Evidence artifacts

Evidence frequency: Quarterly review of privileged group membership; annual RBAC matrix sign-off