CC6.6: Protection from external threats
The boundary between the company's systems and the outside world is defended: firewalls, WAF, secure remote access, MFA on external entry points, and hardened endpoints.
Category: Security (common criteria, required in every SOC 2 report) · Series: CC6 (Logical and physical access controls) · TSC 2017 (2022 points of focus)
That summary is Policyseed’s own paraphrase, written to be read next to the policy sections below. The authoritative wording is the AICPA’s Trust Services Criteria, which the CPA firm tests your controls against during the examination.
Policies that address CC6.6
The Policyseed crosswalk points CC6.6 at 3 policies. Each link opens the full sample text at the section an auditor would read. Section 4 holds the statements management commits to; section 5 holds the procedures that produce evidence.
- P04 Authentication and Password Policy, section 4 (Policy Statements). Owner: Security Owner.
- P19 Endpoint and Workstation Security Policy, section 4 (Policy Statements). Owner: IT/Operations Lead.
- P20 Network and Infrastructure Security Policy, section 4 (Policy Statements). Owner: Engineering Lead.
Evidence examples for CC6.6
Artifacts a company of 5 to 200 people can realistically produce. The Audit Kit’s evidence checklist lists them per policy with an owner column so each one has a name against it before the examination.
- Cloud security group or firewall rule export for production showing no unrestricted inbound admin ports
- WAF or edge protection configuration screenshot
- MFA enforcement screenshot for the identity provider, source control organization and cloud console
- MDM compliance report showing disk encryption and firewall enabled on all managed devices
Related criteria in CC6 (Logical and physical access controls)
- CC6.1: Logical access security
- CC6.2: User registration and deprovisioning
- CC6.3: Role-based access and least privilege
- CC6.4: Physical access
- CC6.5: Disposal of physical assets
- CC6.7: Data in transit and on removable media
- CC6.8: Malicious software
Previous: CC6.5 Disposal of physical assets. Next: CC6.7 Data in transit and on removable media. All 38 criteria are listed on the template index.
Policyseed provides governance policy templates and AI tailoring. It is not legal advice and not a compliance guarantee. Management adopts the policies; the CPA firm performs the SOC 2 examination.