SOC2-CC2.1 CC2.1 Relevant, quality information to support internal control (COSO principle 13)
SOC2-CC2.1 in SOC 2 (the AICPA 2017 Trust Services Criteria with the revised points of focus). All SOC 2 controls held. Open SOC 2 on the standards site.
The control as we hold it
CC2.1 Relevant, quality information to support internal control (COSO principle 13). The organisation obtains or produces relevant, good-quality information and uses it so internal control can function. Points of focus: there is a process to decide what information the control components and objectives need; systems capture data from inside and outside the organisation; relevant data is turned into information; and that information stays produced on time, kept up to date, correct and whole, reachable when needed, secured, capable of verification and kept, and is reviewed for relevance. The 2022 revision adds five points: internal and external data flows are documented and used in control.
Reviewed and closest counterparts in the other frameworks
Reviewed rows come from a released pair; a closest match is the nearest held text and is not a reviewed row.
HIPAA Security Rule
- 164.308(a)(1)(ii)(A) Risk Analysis (Required) (closest match)
- 164.308(a)(7)(ii)(E) Applications and Data Criticality Analysis (Addressable) (closest match)
- 164.312(b) Audit Controls (Standard) (closest match)
- 164.316(a) Policies and Procedures (Standard) (closest match)
NIST SP 800-53 Rev 5
- NIST800-CA-3 CA-3 Information Exchange (closest match)
- NIST800-PM-6 PM-6 Measures of Performance (closest match)
- NIST800-PM-22 PM-22 Personally Identifiable Information Quality Management (closest match)
- NIST800-PM-31 PM-31 Continuous Monitoring Strategy (closest match)
- NIST800-SA-5 SA-5 System Documentation (closest match)
- NIST800-SC-16 SC-16 Transmission of Security and Privacy Attributes (closest match)
- NIST800-SI-18 SI-18 Personally Identifiable Information Quality Operations (closest match)
What an auditor commonly asks for
General guidance for this control area (domain: CC - Common Criteria (Security)), in our words, not a statement of the standard and not binding on an assessor.
- the board or management oversight record
- the risk assessment and its treatment
- the access-review and change-approval records
- the monitoring, logging and incident records