Catalog / SOC 2

SOC 2 AICPA Trust Services Criteria

The Common Criteria that appear in every SOC 2, plus Availability, Confidentiality, Processing Integrity and Privacy where you commit to them. Tests are split into suitability of design and operating effectiveness for Type II.

9
domains
61
controls
116
tests the agent runs

Control catalog

Common Criteria — Control Environment & Risk (CC1–CC5)

CCA · 17 controls
  • CC1.1

    Commitment to integrity and ethical values

    The entity demonstrates a commitment to integrity and ethical values.

  • CC1.2

    Board independence and oversight

    The board of directors demonstrates independence from management and exercises oversight of the development and performance of internal control.

  • CC1.3

    Structures, reporting lines, authorities and responsibilities

    Management establishes, with board oversight, structures, reporting lines, and appropriate authorities and responsibilities in the pursuit of objectives.

  • CC1.4

    Commitment to competence

    The entity demonstrates a commitment to attract, develop, and retain competent individuals in alignment with objectives.

  • CC1.5

    Accountability

    The entity holds individuals accountable for their internal control responsibilities in the pursuit of objectives.

  • CC2.1

    Quality information for internal control

    The entity obtains or generates and uses relevant, quality information to support the functioning of internal control.

  • CC2.2

    Internal communication

    The entity internally communicates information, including objectives and responsibilities for internal control, necessary to support the functioning of internal control.

  • CC2.3

    External communication

    The entity communicates with external parties regarding matters affecting the functioning of internal control.

  • CC3.1

    Objectives specified for risk assessment

    The entity specifies objectives with sufficient clarity to enable the identification and assessment of risks relating to objectives.

  • CC3.2

    Risk identification and analysis

    The entity identifies risks to the achievement of its objectives and analyzes risks as a basis for determining how they should be managed.

  • CC3.3

    Fraud risk

    The entity considers the potential for fraud in assessing risks to the achievement of objectives.

  • CC3.4

    Changes affecting internal control

    The entity identifies and assesses changes that could significantly impact the system of internal control.

  • CC4.1

    Evaluations of internal control

    The entity selects, develops, and performs ongoing and/or separate evaluations to ascertain whether the components of internal control are present and functioning.

  • CC4.2

    Communication of deficiencies

    The entity evaluates and communicates internal control deficiencies in a timely manner to those parties responsible for taking corrective action.

  • CC5.1

    Control activities that mitigate risk

    The entity selects and develops control activities that contribute to the mitigation of risks to the achievement of objectives to acceptable levels.

  • CC5.2

    Technology general controls

    The entity also selects and develops general control activities over technology to support the achievement of objectives.

  • CC5.3

    Policies and procedures

    The entity deploys control activities through policies that establish what is expected and in procedures that put policies into action.

Common Criteria — Logical & Physical Access (CC6)

CC6 · 8 controls
  • CC6.1

    Logical access security architecture

    The entity implements logical access security software, infrastructure, and architectures over protected information assets to protect them from security events.

  • CC6.2

    User registration and authorisation

    Prior to issuing system credentials, the entity registers and authorizes new internal and external users whose access is administered by the entity.

  • CC6.3

    Access modification and removal

    The entity authorizes, modifies, or removes access to data, software, functions, and other protected information assets based on roles, responsibilities, or the system design and changes, giving consideration to the concepts of least privilege and segregation of duties.

  • CC6.4

    Physical access

    The entity restricts physical access to facilities and protected information assets to authorized personnel.

  • CC6.5

    Disposal of assets and data

    The entity discontinues logical and physical protections over physical assets only after the ability to read or recover data and software from those assets has been diminished and is no longer required to achieve the entity's objectives.

  • CC6.6

    External threat protection

    The entity implements logical access security measures to protect against threats from sources outside its system boundaries.

  • CC6.7

    Restricting information transmission and movement

    The entity restricts the transmission, movement, and removal of information to authorized internal and external users and processes, and protects it during transmission, movement, or removal.

  • CC6.8

    Prevention and detection of unauthorised software

    The entity implements controls to prevent or detect and act upon the introduction of unauthorized or malicious software.

Common Criteria — System Operations (CC7)

CC7 · 5 controls
  • CC7.1

    Detection of configuration changes and vulnerabilities

    To meet its objectives, the entity uses detection and monitoring procedures to identify changes to configurations that result in the introduction of new vulnerabilities, and susceptibilities to newly discovered vulnerabilities.

  • CC7.2

    Monitoring for anomalies

    The entity monitors system components and the operation of those components for anomalies that are indicative of malicious acts, natural disasters, and errors affecting the entity's ability to meet its objectives; anomalies are analyzed to determine whether they represent security events.

  • CC7.3

    Evaluation of security events

    The entity evaluates security events to determine whether they could or have resulted in a failure of the entity to meet its objectives (security incidents) and, if so, takes actions to prevent or address such failures.

  • CC7.4

    Incident response

    The entity responds to identified security incidents by executing a defined incident response program to understand, contain, remediate, and communicate security incidents, as appropriate.

  • CC7.5

    Recovery from identified security incidents

    The entity identifies, develops, and implements activities to recover from identified security incidents.

Common Criteria — Change Management (CC8)

CC8 · 1 controls
  • CC8.1

    Change management

    The entity authorizes, designs, develops or acquires, configures, documents, tests, approves, and implements changes to infrastructure, data, software, and procedures to meet its objectives.

Common Criteria — Risk Mitigation (CC9)

CC9 · 2 controls
  • CC9.1

    Risk mitigation activities

    The entity identifies, selects, and develops risk mitigation activities for risks arising from potential business disruptions.

  • CC9.2

    Vendor and business partner risk

    The entity assesses and manages risks associated with vendors and business partners.

Availability

A1 · 3 controls
  • A1.1

    Capacity management

    The entity maintains, monitors, and evaluates current processing capacity and use of system components to manage capacity demand and to enable the implementation of additional capacity to help meet its objectives.

  • A1.2

    Environmental protections, backup and recovery

    The entity authorizes, designs, develops or acquires, implements, operates, approves, maintains, and monitors environmental protections, software, data backup processes, and recovery infrastructure to meet its objectives.

  • A1.3

    Recovery testing

    The entity tests recovery plan procedures supporting system recovery to meet its objectives.

Confidentiality

C1 · 2 controls
  • C1.1

    Identification and maintenance of confidential information

    The entity identifies and maintains confidential information to meet the entity's objectives related to confidentiality.

  • C1.2

    Disposal of confidential information

    The entity disposes of confidential information to meet the entity's objectives related to confidentiality.

Processing Integrity

PI1 · 5 controls
  • PI1.1

    Information about processing objectives

    The entity obtains or generates, uses, and communicates relevant, quality information regarding the objectives related to processing, including definitions of data processed and product and service specifications, to support the use of products and services.

  • PI1.2

    Completeness and accuracy of inputs

    The entity implements policies and procedures over system inputs, including controls over completeness and accuracy, to result in products, services, and reporting to meet the entity's objectives.

  • PI1.3

    Completeness and accuracy of processing

    The entity implements policies and procedures over system processing to result in products, services, and reporting to meet the entity's objectives.

  • PI1.4

    Completeness and accuracy of outputs

    The entity implements policies and procedures to make available or deliver output completely, accurately, and timely in accordance with specifications to meet the entity's objectives.

  • PI1.5

    Storage of inputs and outputs

    The entity implements policies and procedures to store inputs, items in processing, and outputs completely, accurately, and timely in accordance with system specifications to meet the entity's objectives.

Privacy

P · 18 controls
  • P1.1

    Notice of privacy practices

    The entity provides notice to data subjects about its privacy practices to meet the entity's objectives related to privacy.

  • P2.1

    Choice and consent

    The entity communicates choices available regarding the collection, use, retention, disclosure, and disposal of personal information to the data subjects, and the consequences of failing to provide consent.

  • P3.1

    Collection consistent with objectives

    Personal information is collected consistent with the entity's objectives related to privacy.

  • P3.2

    Explicit consent for sensitive information

    For information requiring explicit consent, the entity communicates the need for such consent as well as the consequences of failure to provide consent for the request for personal information and obtains the consent prior to the collection of the information to meet the entity's objectives related to privacy.

  • P4.1

    Use of personal information

    The entity limits the use of personal information to the purposes identified in the entity's objectives related to privacy.

  • P4.2

    Retention of personal information

    The entity retains personal information consistent with the entity's objectives related to privacy.

  • P4.3

    Disposal of personal information

    The entity securely disposes of personal information to meet the entity's objectives related to privacy.

  • P5.1

    Data subject access

    The entity grants identified and authenticated data subjects the ability to access their stored personal information for review and, upon request, provides physical or electronic copies of that information to data subjects to meet the entity's objectives related to privacy.

  • P5.2

    Correction of personal information

    The entity corrects, amends, or appends personal information based on information provided by data subjects and communicates such information to third parties, as committed or required, to meet the entity's objectives related to privacy.

  • P6.1

    Disclosure to third parties

    The entity discloses personal information to third parties with the explicit consent of data subjects, and such consent is obtained prior to disclosure to meet the entity's objectives related to privacy.

  • P6.2

    Record of authorised disclosures

    The entity creates and retains a complete, accurate, and timely record of authorized disclosures of personal information to meet the entity's objectives related to privacy.

  • P6.3

    Record of unauthorised disclosures

    The entity creates and retains a complete, accurate, and timely record of detected or reported unauthorized disclosures of personal information to meet the entity's objectives related to privacy.

  • P6.4

    Third-party commitments

    The entity obtains privacy commitments from vendors and other third parties who have access to personal information to meet the entity's objectives related to privacy.

  • P6.5

    Third-party unauthorised disclosure notification

    The entity obtains commitments from vendors and other third parties with access to personal information to notify the entity in the event of actual or suspected unauthorized disclosures of personal information.

  • P6.6

    Notification of unauthorised disclosure

    The entity provides notification of breaches and incidents to affected data subjects, regulators, and others to meet the entity's objectives related to privacy.

  • P6.7

    Accounting of disclosures on request

    The entity provides data subjects with an accounting of the personal information held and disclosure of the data subjects' personal information, upon the data subjects' request, to meet the entity's objectives related to privacy.

  • P7.1

    Quality of personal information

    The entity collects and maintains accurate, up-to-date, complete, and relevant personal information to meet the entity's objectives related to privacy.

  • P8.1

    Privacy complaint handling and compliance monitoring

    The entity implements a process for receiving, addressing, resolving, and communicating the resolution of inquiries, complaints, and disputes from data subjects and others and periodically monitors compliance to meet the entity's objectives related to privacy.

See SOC 2 tested against your evidence.