SOC2-PI1.1 PI1.1 Quality information about processing objectives, data definitions and specifications
SOC2-PI1.1 in SOC 2 (the AICPA 2017 Trust Services Criteria with the revised points of focus). All SOC 2 controls held. Open SOC 2 on the standards site.
The control as we hold it
PI1.1 Quality information about processing objectives, data definitions and specifications. Relevant, good-quality information about processing objectives, including what the processed data means and what products and services are specified to do, is obtained or generated, used and communicated to support use of the products and services. Points of focus: the information specifications needed to use products and services are identified; where data is supplied as part of a service or a reporting obligation, its definition is available to users and covers the population included, the nature of each element, sources, units of measure, accuracy and precision, uncertainty, the date or period.
Reviewed and closest counterparts in the other frameworks
Reviewed rows come from a released pair; a closest match is the nearest held text and is not a reviewed row.
HIPAA Security Rule
- 164.308(a)(1)(ii)(A) Risk Analysis (Required) (closest match)
- 164.308(a)(7)(ii)(A) Data Backup Plan (Required) (closest match)
- 164.312(c)(1) Integrity (Standard) (closest match)
- 164.316(a) Policies and Procedures (Standard) (closest match)
NIST SP 800-53 Rev 5
- NIST800-AU-13 AU-13 Monitoring for Information Disclosure (closest match)
- NIST800-CM-13 CM-13 Data Action Mapping (closest match)
- NIST800-PM-22 PM-22 Personally Identifiable Information Quality Management (closest match)
- NIST800-SI-12 SI-12 Information Management and Retention (closest match)
- NIST800-SI-18 SI-18 Personally Identifiable Information Quality Operations (closest match)
- NIST800-SI-22 SI-22 Information Diversity (closest match)
What an auditor commonly asks for
General guidance for this control area (domain: PI - Processing Integrity), in our words, not a statement of the standard and not binding on an assessor.
- the processing controls and their monitoring
- the validation and completeness records
- the error and exception records