SOC2-P6.2 P6.2 Record of authorised disclosures
SOC2-P6.2 in SOC 2 (the AICPA 2017 Trust Services Criteria with the revised points of focus). All SOC 2 controls held. Open SOC 2 on the standards site.
The control as we hold it
P6.2 Record of authorised disclosures. A full, correct and up-to-date log of authorised disclosures of personal information is created and kept. Point of focus: the record of authorised disclosures is maintained completely, accurately and promptly.
Reviewed and closest counterparts in the other frameworks
Reviewed rows come from a released pair; a closest match is the nearest held text and is not a reviewed row.
HIPAA Security Rule
- 164.310(d)(2)(iii) Accountability (Addressable) (closest match)
- 164.316(b)(1) Documentation (Standard) (closest match)
NIST SP 800-53 Rev 5
- NIST800-AT-4 AT-4 Training Records (closest match)
- NIST800-PM-21 PM-21 Accounting of Disclosures (closest match)
- NIST800-PT-6 PT-6 System of Records Notice (closest match)
- NIST800-PT-8 PT-8 Computer Matching Requirements (closest match)
What an auditor commonly asks for
General guidance for this control area (domain: P - Privacy), in our words, not a statement of the standard and not binding on an assessor.
- the privacy notice and its change log
- the consent and preference records
- the data-subject request log with resolution
- the retention and disposal records