Skip to content

Community-review CWE-862 to SOC 2 CC6.1 mapping #5

Description

@Synvoya

Goal

Independently review this one preselected mapping:

CWE-862 Missing Authorization → SOC 2 CC6.1 Logical and Physical Access Controls

Determine whether the mapping should be confirmed as written, revised, or removed. If it is retained and the review is accepted, its reviewer state moves from maintainer-policy-reviewed to community-verified.

This is evidence work. It does not establish SOC 2 compliance, an audit result, or certification.

Primary source

Use the official AICPA Trust Services Criteria and Points of Focus, criterion CC6.1:

https://us.aicpa.org/content/dam/aicpa/interestareas/frc/assuranceadvisoryservices/downloadabledocuments/trust-services-criteria-redlined.pdf

CC6.1 appears on page 29 of the PDF. Review both the criterion and its Restricts Logical Access point of focus.

Do not substitute an unofficial control summary. If the AICPA document is inaccessible, comment here rather than guessing.

Exact repository scope

  1. Review the current entry at data/cwe_to_controls.jsoncwe_map["CWE-862"].SOC2 → control CC6.1.
  2. State whether the current low confidence and rationale are defensible.
  3. Update that entry only if your conclusion requires a wording, confidence, or reviewer change.
  4. Record the contributor attribution in the reviewer field using the format documented in CONTRIBUTING.md.
  5. Update the community-verified count in docs/COMPLIANCE-RATIONALE.md only if the mapping is retained and confirmed.
  6. Use .github/PULL_REQUEST_TEMPLATE/compliance-mapping.md.

Required PR evidence

  • A short quotation from CC6.1 or its relevant point of focus, within normal quotation limits.
  • The official document, criterion ID, page number, link, and date checked.
  • Your basis: a credential or honestly no formal GRC credential, reasoning from the published text.
  • Separate:
    • the technical link between missing authorization and logical access restriction; and
    • the audit-interpretation question of whether a code finding is evidence for this organizational criterion.
  • Explicitly preserve the statement that CodeInspectus provides code-visible evidence only.

Verification

Run:

npm run build
npm run eval

Do not change detection behavior as part of this contribution.

Metadata

Metadata

Assignees

Labels

documentationImprovements or additions to documentationgood first issueGood for newcomershelp wantedExtra attention is needed

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions