CC6.1Implements logical access security software and infrastructure
Access to your systems and data requires a login, and that login is properly protected.
Reaching systems and data requires authenticating first, and the means of doing so is itself protected and configured deliberately.
CC6.2Registers and authorises new users
Someone approves each new account before it is created - accounts do not just appear.
Access is granted through an approval that is recorded, so every account can be traced back to a decision somebody made.
CC6.3Manages access rights over the user lifecycle
When someone changes role or leaves, their access changes or is removed the same day.
Access changes when a person's role changes and ends when they leave, rather than accumulating quietly over years.
CC6.4Restricts physical access
Only the right people can physically walk up to your servers, network equipment, or offices holding sensitive data.
Places holding systems or data - offices, racks, storage - admit only the people entitled to be there.
CC6.5Disposes of assets securely
Old laptops, drives, and phones are wiped properly before they are sold, recycled, or thrown away.
Hardware and media leaving the business are cleared first, because a decommissioned laptop is a complete copy of whatever was on it.
CC6.6Protects against external threats
Your systems are defended against attacks coming from the internet.
The boundary between the business and everything outside it is defended, so reaching in requires getting past something.
CC6.7Restricts the movement of information
Sensitive data is encrypted when it travels, and people cannot copy it somewhere it should not go.
Data moving between people, systems and organisations is controlled and protected on the way, so it goes where it was meant to and arrives unread.
CC6.8Prevents and detects unauthorised software
You would notice if malware or unapproved software were installed on a company device.
Software nobody approved is prevented where it can be and noticed where it cannot, so what runs on the estate is what was intended to.