Catalog / SOC 2
SOC 2 AICPA Trust Services Criteria
The Common Criteria that appear in every SOC 2, plus Availability, Confidentiality, Processing Integrity and Privacy where you commit to them. Tests are split into suitability of design and operating effectiveness for Type II.
- 9
- domains
- 61
- controls
- 116
- tests the agent runs
Control catalog
Common Criteria — Control Environment & Risk (CC1–CC5)
-
CC1.1Commitment to integrity and ethical values
The entity demonstrates a commitment to integrity and ethical values.
-
CC1.2Board independence and oversight
The board of directors demonstrates independence from management and exercises oversight of the development and performance of internal control.
-
CC1.3Structures, reporting lines, authorities and responsibilities
Management establishes, with board oversight, structures, reporting lines, and appropriate authorities and responsibilities in the pursuit of objectives.
-
CC1.4Commitment to competence
The entity demonstrates a commitment to attract, develop, and retain competent individuals in alignment with objectives.
-
CC1.5Accountability
The entity holds individuals accountable for their internal control responsibilities in the pursuit of objectives.
-
CC2.1Quality information for internal control
The entity obtains or generates and uses relevant, quality information to support the functioning of internal control.
-
CC2.2Internal communication
The entity internally communicates information, including objectives and responsibilities for internal control, necessary to support the functioning of internal control.
-
CC2.3External communication
The entity communicates with external parties regarding matters affecting the functioning of internal control.
-
CC3.1Objectives specified for risk assessment
The entity specifies objectives with sufficient clarity to enable the identification and assessment of risks relating to objectives.
-
CC3.2Risk identification and analysis
The entity identifies risks to the achievement of its objectives and analyzes risks as a basis for determining how they should be managed.
-
CC3.3Fraud risk
The entity considers the potential for fraud in assessing risks to the achievement of objectives.
-
CC3.4Changes affecting internal control
The entity identifies and assesses changes that could significantly impact the system of internal control.
-
CC4.1Evaluations of internal control
The entity selects, develops, and performs ongoing and/or separate evaluations to ascertain whether the components of internal control are present and functioning.
-
CC4.2Communication of deficiencies
The entity evaluates and communicates internal control deficiencies in a timely manner to those parties responsible for taking corrective action.
-
CC5.1Control activities that mitigate risk
The entity selects and develops control activities that contribute to the mitigation of risks to the achievement of objectives to acceptable levels.
-
CC5.2Technology general controls
The entity also selects and develops general control activities over technology to support the achievement of objectives.
-
CC5.3Policies and procedures
The entity deploys control activities through policies that establish what is expected and in procedures that put policies into action.
Common Criteria — Logical & Physical Access (CC6)
-
CC6.1Logical access security architecture
The entity implements logical access security software, infrastructure, and architectures over protected information assets to protect them from security events.
-
CC6.2User registration and authorisation
Prior to issuing system credentials, the entity registers and authorizes new internal and external users whose access is administered by the entity.
-
CC6.3Access modification and removal
The entity authorizes, modifies, or removes access to data, software, functions, and other protected information assets based on roles, responsibilities, or the system design and changes, giving consideration to the concepts of least privilege and segregation of duties.
-
CC6.4Physical access
The entity restricts physical access to facilities and protected information assets to authorized personnel.
-
CC6.5Disposal of assets and data
The entity discontinues logical and physical protections over physical assets only after the ability to read or recover data and software from those assets has been diminished and is no longer required to achieve the entity's objectives.
-
CC6.6External threat protection
The entity implements logical access security measures to protect against threats from sources outside its system boundaries.
-
CC6.7Restricting information transmission and movement
The entity restricts the transmission, movement, and removal of information to authorized internal and external users and processes, and protects it during transmission, movement, or removal.
-
CC6.8Prevention and detection of unauthorised software
The entity implements controls to prevent or detect and act upon the introduction of unauthorized or malicious software.
Common Criteria — System Operations (CC7)
-
CC7.1Detection of configuration changes and vulnerabilities
To meet its objectives, the entity uses detection and monitoring procedures to identify changes to configurations that result in the introduction of new vulnerabilities, and susceptibilities to newly discovered vulnerabilities.
-
CC7.2Monitoring for anomalies
The entity monitors system components and the operation of those components for anomalies that are indicative of malicious acts, natural disasters, and errors affecting the entity's ability to meet its objectives; anomalies are analyzed to determine whether they represent security events.
-
CC7.3Evaluation of security events
The entity evaluates security events to determine whether they could or have resulted in a failure of the entity to meet its objectives (security incidents) and, if so, takes actions to prevent or address such failures.
-
CC7.4Incident response
The entity responds to identified security incidents by executing a defined incident response program to understand, contain, remediate, and communicate security incidents, as appropriate.
-
CC7.5Recovery from identified security incidents
The entity identifies, develops, and implements activities to recover from identified security incidents.
Common Criteria — Change Management (CC8)
-
CC8.1Change management
The entity authorizes, designs, develops or acquires, configures, documents, tests, approves, and implements changes to infrastructure, data, software, and procedures to meet its objectives.
Common Criteria — Risk Mitigation (CC9)
-
CC9.1Risk mitigation activities
The entity identifies, selects, and develops risk mitigation activities for risks arising from potential business disruptions.
-
CC9.2Vendor and business partner risk
The entity assesses and manages risks associated with vendors and business partners.
Availability
-
A1.1Capacity management
The entity maintains, monitors, and evaluates current processing capacity and use of system components to manage capacity demand and to enable the implementation of additional capacity to help meet its objectives.
-
A1.2Environmental protections, backup and recovery
The entity authorizes, designs, develops or acquires, implements, operates, approves, maintains, and monitors environmental protections, software, data backup processes, and recovery infrastructure to meet its objectives.
-
A1.3Recovery testing
The entity tests recovery plan procedures supporting system recovery to meet its objectives.
Confidentiality
-
C1.1Identification and maintenance of confidential information
The entity identifies and maintains confidential information to meet the entity's objectives related to confidentiality.
-
C1.2Disposal of confidential information
The entity disposes of confidential information to meet the entity's objectives related to confidentiality.
Processing Integrity
-
PI1.1Information about processing objectives
The entity obtains or generates, uses, and communicates relevant, quality information regarding the objectives related to processing, including definitions of data processed and product and service specifications, to support the use of products and services.
-
PI1.2Completeness and accuracy of inputs
The entity implements policies and procedures over system inputs, including controls over completeness and accuracy, to result in products, services, and reporting to meet the entity's objectives.
-
PI1.3Completeness and accuracy of processing
The entity implements policies and procedures over system processing to result in products, services, and reporting to meet the entity's objectives.
-
PI1.4Completeness and accuracy of outputs
The entity implements policies and procedures to make available or deliver output completely, accurately, and timely in accordance with specifications to meet the entity's objectives.
-
PI1.5Storage of inputs and outputs
The entity implements policies and procedures to store inputs, items in processing, and outputs completely, accurately, and timely in accordance with system specifications to meet the entity's objectives.
Privacy
-
P1.1Notice of privacy practices
The entity provides notice to data subjects about its privacy practices to meet the entity's objectives related to privacy.
-
P2.1Choice and consent
The entity communicates choices available regarding the collection, use, retention, disclosure, and disposal of personal information to the data subjects, and the consequences of failing to provide consent.
-
P3.1Collection consistent with objectives
Personal information is collected consistent with the entity's objectives related to privacy.
-
P3.2Explicit consent for sensitive information
For information requiring explicit consent, the entity communicates the need for such consent as well as the consequences of failure to provide consent for the request for personal information and obtains the consent prior to the collection of the information to meet the entity's objectives related to privacy.
-
P4.1Use of personal information
The entity limits the use of personal information to the purposes identified in the entity's objectives related to privacy.
-
P4.2Retention of personal information
The entity retains personal information consistent with the entity's objectives related to privacy.
-
P4.3Disposal of personal information
The entity securely disposes of personal information to meet the entity's objectives related to privacy.
-
P5.1Data subject access
The entity grants identified and authenticated data subjects the ability to access their stored personal information for review and, upon request, provides physical or electronic copies of that information to data subjects to meet the entity's objectives related to privacy.
-
P5.2Correction of personal information
The entity corrects, amends, or appends personal information based on information provided by data subjects and communicates such information to third parties, as committed or required, to meet the entity's objectives related to privacy.
-
P6.1Disclosure to third parties
The entity discloses personal information to third parties with the explicit consent of data subjects, and such consent is obtained prior to disclosure to meet the entity's objectives related to privacy.
-
P6.2Record of authorised disclosures
The entity creates and retains a complete, accurate, and timely record of authorized disclosures of personal information to meet the entity's objectives related to privacy.
-
P6.3Record of unauthorised disclosures
The entity creates and retains a complete, accurate, and timely record of detected or reported unauthorized disclosures of personal information to meet the entity's objectives related to privacy.
-
P6.4Third-party commitments
The entity obtains privacy commitments from vendors and other third parties who have access to personal information to meet the entity's objectives related to privacy.
-
P6.5Third-party unauthorised disclosure notification
The entity obtains commitments from vendors and other third parties with access to personal information to notify the entity in the event of actual or suspected unauthorized disclosures of personal information.
-
P6.6Notification of unauthorised disclosure
The entity provides notification of breaches and incidents to affected data subjects, regulators, and others to meet the entity's objectives related to privacy.
-
P6.7Accounting of disclosures on request
The entity provides data subjects with an accounting of the personal information held and disclosure of the data subjects' personal information, upon the data subjects' request, to meet the entity's objectives related to privacy.
-
P7.1Quality of personal information
The entity collects and maintains accurate, up-to-date, complete, and relevant personal information to meet the entity's objectives related to privacy.
-
P8.1Privacy complaint handling and compliance monitoring
The entity implements a process for receiving, addressing, resolving, and communicating the resolution of inquiries, complaints, and disputes from data subjects and others and periodically monitors compliance to meet the entity's objectives related to privacy.