Free compliance framework explorer — browse controls, evidence, and implementation guidance.Subscribe for updates →
SOC 247
ITSP.10.17198
ISO 42001soon
ISO 27001soon

Browse

33 controls

CC6.6Controls against threats from outside system boundariesSOC 2Logical and Physical Access Controls

Official Requirement

The entity implements controls to prevent or detect and act upon the introduction of unauthorized or malicious software to meet the entity's objectives.

Source: AICPA Trust Services Criteria (2017), incorporating COSO principles

In Plain English

This criterion covers your external attack surface: what stops a threat actor from getting in from the internet? Firewall rules, IDS/IPS, WAF, email filtering, endpoint detection, DNS filtering, any control that reduces exposure at the boundary. The key is that these controls must be monitored and alert on events; passive controls that no one watches don't satisfy the criterion.

Help us build what matters.

Vote for the next framework, subscribe for updates, and let us know if you'd contribute.

The Trust Services Criteria referenced in this tool are published by the American Institute of Certified Public Accountants (AICPA) and incorporate principles from the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Criteria descriptions are reproduced for reference purposes. All implementation guidance, evidence recommendations, and control language are original work by Truvo Cyber. ISO 27001 and ISO 42001 are standards published by the International Organization for Standardization (ISO). Framework and standard names are the property of their respective owners. This tool is not affiliated with, endorsed by, or certified by AICPA, COSO, or ISO.

© 2026 Truvo Cyber. All rights reserved.

On-premises implementation and evidence

Perimeter firewall with default-deny policy and reviewed ruleset

Implementation steps

  1. Deploy a stateful firewall appliance at the network perimeter with a default-deny outbound and inbound policy
  2. All firewall rule changes go through the change management process: ticket, approval, implementation, documentation
  3. Conduct a full firewall rule review quarterly, each rule must have a documented owner and business justification; delete any rules that cannot be justified
  4. Integrate the firewall with your SIEM (your IDS/network monitoring platform, your SIEM/monitoring platform) so firewall deny events and anomalies are logged and reviewed

Tools / systems

Evidence artifacts

Evidence frequency: Quarterly firewall rule review; per-change tickets; annual policy review

Endpoint detection and response (EDR) with active monitoring

Implementation steps

  1. Deploy anti-malware and EDR on all production servers and user endpoints, coverage must be 100% of in-scope assets
  2. Configure automated definition updates and verify update status is centrally monitored
  3. Set scan schedule for on-prem servers (real-time plus scheduled full scan at off-peak hours)
  4. Route EDR/AV alerts to your SIEM (your SIEM/monitoring platform / your IDS/network monitoring platform) and confirm detections are reviewed within the detection response SLA

Tools / systems

Evidence artifacts

Evidence frequency: Quarterly console screenshot; detection logs collected at audit window close