/evidence · CC6.1
├ access-policy-v7.pdf
├ quarterly-access-review.csv
├ mfa-enforcement-config.json
├ privileged-role-roster.csv
├ reviewer-signoff.md
└ citation.md ✦ review-ready
Cited rule · Common Criteria 6.1
“The entity implements logical access security software, infrastructure, and architectures over protected information assets.”
Source
AICPA TSC 2017 (rev. 2022)
Reviewer
J. Patel · former EY
Why this matters
The quarterly-access-review CSV and privileged-role-roster together prove the control is operating — not just that a policy exists. Both surfaced automatically from your existing tools.