SOC2-CC1.2 CC1.2 Board independence and oversight of internal control (COSO principle 2)
SOC2-CC1.2 in SOC 2 (the AICPA 2017 Trust Services Criteria with the revised points of focus). All SOC 2 controls held. Open SOC 2 on the standards site.
The control as we hold it
CC1.2 Board independence and oversight of internal control (COSO principle 2). A governing body that is independent of management oversees how internal control is designed and how it performs. Points of focus: the board accepts defined oversight duties; it keeps and periodically reviews the skills it needs to question management and act; enough members are independent and objective; and where it lacks expertise in any of the five trust services categories (security, availability, confidentiality, processing integrity, privacy) it adds it through a committee or outside advisers.
Reviewed and closest counterparts in the other frameworks
Reviewed rows come from a released pair; a closest match is the nearest held text and is not a reviewed row.
NIST SP 800-53 Rev 5
- NIST800-CA-7 CA-7 Continuous Monitoring (closest match)
- NIST800-PM-2 PM-2 Information Security Program Leadership Role (closest match)
- NIST800-PM-9 PM-9 Risk Management Strategy (closest match)
- NIST800-PM-19 PM-19 Privacy Program Leadership Role (closest match)
- NIST800-PM-24 PM-24 Data Integrity Board (closest match)
- NIST800-PM-29 PM-29 Risk Management Program Leadership Roles (closest match)
- NIST800-PT-8 PT-8 Computer Matching Requirements (closest match)
What an auditor commonly asks for
General guidance for this control area (domain: CC - Common Criteria (Security)), in our words, not a statement of the standard and not binding on an assessor.
- the board or management oversight record
- the risk assessment and its treatment
- the access-review and change-approval records
- the monitoring, logging and incident records