SOC 2 controls
61 controls held for SOC 2 (AICPA). Edition: the AICPA 2017 Trust Services Criteria with the revised points of focus. Place a control statement and the reader picks the closest text here and the closest matches in the other frameworks. Open SOC 2 on the standards site.
| Code | Control | Domain | |
|---|---|---|---|
| SOC2-A1.1 | A1.1 Managing processing capacity | A - Availability | open |
| SOC2-A1.2 | A1.2 Environmental protection, backup and recovery infrastructure | A - Availability | open |
| SOC2-A1.3 | A1.3 Testing recovery plan procedures | A - Availability | open |
| SOC2-C1.1 | C1.1 Identifying and maintaining confidential information | C - Confidentiality | open |
| SOC2-C1.2 | C1.2 Disposing of confidential information | C - Confidentiality | open |
| SOC2-CC1.1 | CC1.1 Commitment to integrity and ethical values (COSO principle 1) | CC - Common Criteria (Security) | open |
| SOC2-CC1.2 | CC1.2 Board independence and oversight of internal control (COSO principle 2) | CC - Common Criteria (Security) | open |
| SOC2-CC1.3 | CC1.3 Structures, reporting lines, authorities and responsibilities (COSO principle 3) | CC - Common Criteria (Security) | open |
| SOC2-CC1.4 | CC1.4 Attracting, developing and retaining competent people (COSO principle 4) | CC - Common Criteria (Security) | open |
| SOC2-CC1.5 | CC1.5 Accountability for internal control responsibilities (COSO principle 5) | CC - Common Criteria (Security) | open |
| SOC2-CC2.1 | CC2.1 Relevant, quality information to support internal control (COSO principle 13) | CC - Common Criteria (Security) | open |
| SOC2-CC2.2 | CC2.2 Internal communication of objectives and control responsibilities (COSO principle 14) | CC - Common Criteria (Security) | open |
| SOC2-CC2.3 | CC2.3 Communication with external parties about internal control (COSO principle 15) | CC - Common Criteria (Security) | open |
| SOC2-CC3.1 | CC3.1 Objectives specified clearly enough to assess risk (COSO principle 6) | CC - Common Criteria (Security) | open |
| SOC2-CC3.2 | CC3.2 Identifying and analysing risks to objectives (COSO principle 7) | CC - Common Criteria (Security) | open |
| SOC2-CC3.3 | CC3.3 Considering fraud risk (COSO principle 8) | CC - Common Criteria (Security) | open |
| SOC2-CC3.4 | CC3.4 Identifying and assessing significant changes (COSO principle 9) | CC - Common Criteria (Security) | open |
| SOC2-CC4.1 | CC4.1 Ongoing and separate evaluations of control (COSO principle 16) | CC - Common Criteria (Security) | open |
| SOC2-CC4.2 | CC4.2 Evaluating and communicating control deficiencies (COSO principle 17) | CC - Common Criteria (Security) | open |
| SOC2-CC5.1 | CC5.1 Selecting control activities that mitigate risk (COSO principle 10) | CC - Common Criteria (Security) | open |
| SOC2-CC5.2 | CC5.2 General controls over technology (COSO principle 11) | CC - Common Criteria (Security) | open |
| SOC2-CC5.3 | CC5.3 Deploying controls through policies and procedures (COSO principle 12) | CC - Common Criteria (Security) | open |
| SOC2-CC6.1 | CC6.1 Logical access security over protected information assets | CC - Common Criteria (Security) | open |
| SOC2-CC6.2 | CC6.2 Registering and authorising users before issuing credentials | CC - Common Criteria (Security) | open |
| SOC2-CC6.3 | CC6.3 Role-based access, least privilege and segregation of duties | CC - Common Criteria (Security) | open |
| SOC2-CC6.4 | CC6.4 Restricting physical access to facilities and assets | CC - Common Criteria (Security) | open |
| SOC2-CC6.5 | CC6.5 Protecting data on assets until disposal | CC - Common Criteria (Security) | open |
| SOC2-CC6.6 | CC6.6 Protection against threats from outside the system boundary | CC - Common Criteria (Security) | open |
| SOC2-CC6.7 | CC6.7 Restricting and protecting information in transmission, movement and removal | CC - Common Criteria (Security) | open |
| SOC2-CC6.8 | CC6.8 Preventing and detecting unauthorised or malicious software | CC - Common Criteria (Security) | open |
| SOC2-CC7.1 | CC7.1 Detecting configuration changes and new vulnerabilities | CC - Common Criteria (Security) | open |
| SOC2-CC7.2 | CC7.2 Monitoring system components for anomalies | CC - Common Criteria (Security) | open |
| SOC2-CC7.3 | CC7.3 Evaluating security events to identify incidents | CC - Common Criteria (Security) | open |
| SOC2-CC7.4 | CC7.4 Responding to security incidents | CC - Common Criteria (Security) | open |
| SOC2-CC7.5 | CC7.5 Recovering from security incidents | CC - Common Criteria (Security) | open |
| SOC2-CC8.1 | CC8.1 Managing changes to procedures, software, data and infrastructure | CC - Common Criteria (Security) | open |
| SOC2-CC9.1 | CC9.1 Mitigating risks of business disruption | CC - Common Criteria (Security) | open |
| SOC2-CC9.2 | CC9.2 Assessing and managing vendor and business partner risk | CC - Common Criteria (Security) | open |
| SOC2-P1.1 | P1.1 Privacy notice to data subjects | P - Privacy | open |
| SOC2-P2.1 | P2.1 Choice and consent | P - Privacy | open |
| SOC2-P3.1 | P3.1 Collecting personal information consistent with objectives | P - Privacy | open |
| SOC2-P3.2 | P3.2 Explicit consent before collecting information that requires it | P - Privacy | open |
| SOC2-P4.1 | P4.1 Limiting use to identified purposes | P - Privacy | open |
| SOC2-P4.2 | P4.2 Retaining personal information | P - Privacy | open |
| SOC2-P4.3 | P4.3 Securely disposing of personal information | P - Privacy | open |
| SOC2-P5.1 | P5.1 Data subject access | P - Privacy | open |
| SOC2-P5.2 | P5.2 Correction of personal information | P - Privacy | open |
| SOC2-P6.1 | P6.1 Disclosure to third parties with consent | P - Privacy | open |
| SOC2-P6.2 | P6.2 Record of authorised disclosures | P - Privacy | open |
| SOC2-P6.3 | P6.3 Record of unauthorised disclosures and breaches | P - Privacy | open |
| SOC2-P6.4 | P6.4 Privacy commitments from vendors and third parties | P - Privacy | open |
| SOC2-P6.5 | P6.5 Vendor commitments to report unauthorised disclosures | P - Privacy | open |
| SOC2-P6.6 | P6.6 Notifying breaches and incidents | P - Privacy | open |
| SOC2-P6.7 | P6.7 Accounting of personal information held and disclosed | P - Privacy | open |
| SOC2-P7.1 | P7.1 Quality of personal information | P - Privacy | open |
| SOC2-P8.1 | P8.1 Inquiries, complaints, disputes and compliance monitoring | P - Privacy | open |
| SOC2-PI1.1 | PI1.1 Quality information about processing objectives, data definitions and specifications | PI - Processing Integrity | open |
| SOC2-PI1.2 | PI1.2 Controls over system inputs | PI - Processing Integrity | open |
| SOC2-PI1.3 | PI1.3 Controls over system processing | PI - Processing Integrity | open |
| SOC2-PI1.4 | PI1.4 Controls over output delivery | PI - Processing Integrity | open |
| SOC2-PI1.5 | PI1.5 Controls over stored inputs, work in process and outputs | PI - Processing Integrity | open |