| @@ -1,85 +1,93 @@ |
| 1 | 1 | # SOC 2 — Trust Services Criteria (AICPA, 2017 with 2022 revised points of focus). |
| 2 | 2 | # |
| 3 | 3 | # The full Common Criteria (the "Security" category every SOC 2 report covers) |
| 4 | | # plus the Availability category. A control's full code is "SOC2:<id>", matching |
| 5 | | # the codes audit-report rulesets cite. |
| 4 | # plus the Availability, Confidentiality, Processing Integrity, and Privacy |
| 5 | # categories. A control's full code is "SOC2:<id>", matching the codes |
| 6 | # audit-report rulesets cite. |
| 7 | # |
| 8 | # COPYRIGHT: The Trust Services Criteria are copyright AICPA. The `title` fields |
| 9 | # below are our own short-form paraphrases used as labels — not the normative |
| 10 | # criteria text. Only the criterion identifiers (e.g. CC6.1) are reproduced. For |
| 11 | # the authoritative wording and points of focus, consult the AICPA TSC. These |
| 12 | # control-to-signal mappings are the maintainers' interpretation and are not |
| 13 | # reviewed or endorsed by the AICPA. See ../../MAPPING.md. |
| 6 | 14 | framework: SOC2 |
| 7 | 15 | name: SOC 2 (Trust Services Criteria) |
| 8 | 16 | version: "2017 (rev. 2022)" |
| 9 | 17 | coverage: complete |
| 10 | | source: AICPA Trust Services Criteria |
| 18 | source: AICPA Trust Services Criteria (identifiers only; titles paraphrased) |
| 11 | 19 | controls: |
| 12 | 20 | # CC1 — Control Environment |
| 13 | | - {id: CC1.1, family: Control Environment, title: "The entity demonstrates a commitment to integrity and ethical values."} |
| 14 | | - {id: CC1.2, family: Control Environment, title: "The board of directors demonstrates independence and exercises oversight of internal control."} |
| 15 | | - {id: CC1.3, family: Control Environment, title: "Management establishes structures, reporting lines, and appropriate authorities and responsibilities."} |
| 16 | | - {id: CC1.4, family: Control Environment, title: "The entity demonstrates a commitment to attract, develop, and retain competent individuals."} |
| 17 | | - {id: CC1.5, family: Control Environment, title: "The entity holds individuals accountable for their internal control responsibilities."} |
| 21 | - {id: CC1.1, family: Control Environment, title: "Commitment to integrity and ethical values"} |
| 22 | - {id: CC1.2, family: Control Environment, title: "Board independence and internal-control oversight"} |
| 23 | - {id: CC1.3, family: Control Environment, title: "Structures, reporting lines, and authorities established"} |
| 24 | - {id: CC1.4, family: Control Environment, title: "Commitment to attracting and retaining competent people"} |
| 25 | - {id: CC1.5, family: Control Environment, title: "Accountability for internal-control responsibilities"} |
| 18 | 26 | # CC2 — Communication and Information |
| 19 | | - {id: CC2.1, family: Communication and Information, title: "The entity obtains or generates relevant, quality information to support internal control."} |
| 20 | | - {id: CC2.2, family: Communication and Information, title: "The entity internally communicates information, including objectives and responsibilities for internal control."} |
| 21 | | - {id: CC2.3, family: Communication and Information, title: "The entity communicates with external parties about matters affecting internal control."} |
| 27 | - {id: CC2.1, family: Communication and Information, title: "Relevant, quality information supporting internal control"} |
| 28 | - {id: CC2.2, family: Communication and Information, title: "Internal communication of control objectives and duties"} |
| 29 | - {id: CC2.3, family: Communication and Information, title: "External communication on internal-control matters"} |
| 22 | 30 | # CC3 — Risk Assessment |
| 23 | | - {id: CC3.1, family: Risk Assessment, title: "The entity specifies objectives with sufficient clarity to enable identification of risks."} |
| 24 | | - {id: CC3.2, family: Risk Assessment, title: "The entity identifies and analyzes risks to the achievement of its objectives."} |
| 25 | | - {id: CC3.3, family: Risk Assessment, title: "The entity considers the potential for fraud in assessing risks."} |
| 26 | | - {id: CC3.4, family: Risk Assessment, title: "The entity identifies and assesses changes that could significantly affect internal control."} |
| 31 | - {id: CC3.1, family: Risk Assessment, title: "Objectives specified clearly enough to identify risk"} |
| 32 | - {id: CC3.2, family: Risk Assessment, title: "Identification and analysis of risks to objectives"} |
| 33 | - {id: CC3.3, family: Risk Assessment, title: "Fraud potential considered in risk assessment"} |
| 34 | - {id: CC3.4, family: Risk Assessment, title: "Assessment of changes affecting internal control"} |
| 27 | 35 | # CC4 — Monitoring Activities |
| 28 | | - {id: CC4.1, family: Monitoring Activities, title: "The entity selects, develops, and performs ongoing and separate evaluations of internal control."} |
| 29 | | - {id: CC4.2, family: Monitoring Activities, title: "The entity evaluates and communicates internal control deficiencies in a timely manner."} |
| 36 | - {id: CC4.1, family: Monitoring Activities, title: "Ongoing and separate evaluations of internal control"} |
| 37 | - {id: CC4.2, family: Monitoring Activities, title: "Timely evaluation and reporting of control deficiencies"} |
| 30 | 38 | # CC5 — Control Activities |
| 31 | | - {id: CC5.1, family: Control Activities, title: "The entity selects and develops control activities that mitigate risks to acceptable levels."} |
| 32 | | - {id: CC5.2, family: Control Activities, title: "The entity selects and develops general control activities over technology."} |
| 33 | | - {id: CC5.3, family: Control Activities, title: "The entity deploys control activities through policies and procedures."} |
| 39 | - {id: CC5.1, family: Control Activities, title: "Control activities selected to mitigate risk"} |
| 40 | - {id: CC5.2, family: Control Activities, title: "General technology controls developed"} |
| 41 | - {id: CC5.3, family: Control Activities, title: "Control activities deployed via policies and procedures"} |
| 34 | 42 | # CC6 — Logical and Physical Access Controls |
| 35 | | - {id: CC6.1, family: Logical and Physical Access Controls, title: "The entity implements logical access security software, infrastructure, and architectures over protected assets."} |
| 36 | | - {id: CC6.2, family: Logical and Physical Access Controls, title: "The entity registers and authorizes new users before granting access, and removes access when appropriate."} |
| 37 | | - {id: CC6.3, family: Logical and Physical Access Controls, title: "The entity authorizes, modifies, or removes access based on roles and least privilege."} |
| 38 | | - {id: CC6.4, family: Logical and Physical Access Controls, title: "The entity restricts physical access to facilities and protected information assets."} |
| 39 | | - {id: CC6.5, family: Logical and Physical Access Controls, title: "The entity discontinues logical and physical protections over assets only after the ability to read data has been removed."} |
| 40 | | - {id: CC6.6, family: Logical and Physical Access Controls, title: "The entity implements logical access security measures against threats from outside its system boundaries."} |
| 41 | | - {id: CC6.7, family: Logical and Physical Access Controls, title: "The entity restricts the transmission, movement, and removal of information to authorized users and processes."} |
| 42 | | - {id: CC6.8, family: Logical and Physical Access Controls, title: "The entity implements controls to prevent or detect and act upon unauthorized or malicious software."} |
| 43 | - {id: CC6.1, family: Logical and Physical Access Controls, title: "Logical access security over protected assets"} |
| 44 | - {id: CC6.2, family: Logical and Physical Access Controls, title: "User registration, authorization, and deprovisioning"} |
| 45 | - {id: CC6.3, family: Logical and Physical Access Controls, title: "Role- and least-privilege-based access management"} |
| 46 | - {id: CC6.4, family: Logical and Physical Access Controls, title: "Physical access restricted to facilities and assets"} |
| 47 | - {id: CC6.5, family: Logical and Physical Access Controls, title: "Protections removed only after data made unreadable"} |
| 48 | - {id: CC6.6, family: Logical and Physical Access Controls, title: "Perimeter defenses against external threats"} |
| 49 | - {id: CC6.7, family: Logical and Physical Access Controls, title: "Restricted transmission and removal of information"} |
| 50 | - {id: CC6.8, family: Logical and Physical Access Controls, title: "Prevention and detection of unauthorized software"} |
| 43 | 51 | # CC7 — System Operations |
| 44 | | - {id: CC7.1, family: System Operations, title: "The entity uses detection and monitoring procedures to identify configuration changes and new vulnerabilities."} |
| 45 | | - {id: CC7.2, family: System Operations, title: "The entity monitors system components for anomalies indicative of malicious acts or errors."} |
| 46 | | - {id: CC7.3, family: System Operations, title: "The entity evaluates security events to determine whether they could or did result in a failure to meet objectives."} |
| 47 | | - {id: CC7.4, family: System Operations, title: "The entity responds to identified security incidents through a defined program."} |
| 48 | | - {id: CC7.5, family: System Operations, title: "The entity identifies, develops, and implements activities to recover from security incidents."} |
| 52 | - {id: CC7.1, family: System Operations, title: "Detection of configuration changes and vulnerabilities"} |
| 53 | - {id: CC7.2, family: System Operations, title: "Monitoring for anomalies indicating malicious acts"} |
| 54 | - {id: CC7.3, family: System Operations, title: "Evaluation of security events against objectives"} |
| 55 | - {id: CC7.4, family: System Operations, title: "Defined security-incident response program"} |
| 56 | - {id: CC7.5, family: System Operations, title: "Recovery from security incidents"} |
| 49 | 57 | # CC8 — Change Management |
| 50 | | - {id: CC8.1, family: Change Management, title: "The entity authorizes, designs, develops, tests, approves, and implements changes to infrastructure, data, and software."} |
| 58 | - {id: CC8.1, family: Change Management, title: "Change management across infrastructure, data, and software"} |
| 51 | 59 | # CC9 — Risk Mitigation |
| 52 | | - {id: CC9.1, family: Risk Mitigation, title: "The entity identifies, selects, and develops risk mitigation activities for disruptions."} |
| 53 | | - {id: CC9.2, family: Risk Mitigation, title: "The entity assesses and manages risks associated with vendors and business partners."} |
| 60 | - {id: CC9.1, family: Risk Mitigation, title: "Risk-mitigation activities for business disruptions"} |
| 61 | - {id: CC9.2, family: Risk Mitigation, title: "Vendor and business-partner risk management"} |
| 54 | 62 | # Availability category |
| 55 | | - {id: A1.1, family: Availability, title: "The entity maintains, monitors, and evaluates current processing capacity to meet demand."} |
| 56 | | - {id: A1.2, family: Availability, title: "The entity authorizes, designs, and implements environmental protections, backup, and recovery infrastructure."} |
| 57 | | - {id: A1.3, family: Availability, title: "The entity tests recovery plan procedures supporting system recovery."} |
| 63 | - {id: A1.1, family: Availability, title: "Processing-capacity monitoring against demand"} |
| 64 | - {id: A1.2, family: Availability, title: "Environmental protections, backup, and recovery infrastructure"} |
| 65 | - {id: A1.3, family: Availability, title: "Recovery-plan testing"} |
| 58 | 66 | # Confidentiality category |
| 59 | | - {id: C1.1, family: Confidentiality, title: "The entity identifies and maintains confidential information to meet its objectives related to confidentiality."} |
| 60 | | - {id: C1.2, family: Confidentiality, title: "The entity disposes of confidential information to meet its objectives related to confidentiality."} |
| 67 | - {id: C1.1, family: Confidentiality, title: "Identification and safeguarding of confidential information"} |
| 68 | - {id: C1.2, family: Confidentiality, title: "Disposal of confidential information"} |
| 61 | 69 | # Processing Integrity category |
| 62 | | - {id: PI1.1, family: Processing Integrity, title: "The entity obtains or generates, uses, and communicates relevant, quality information about processing objectives, including product and service specifications."} |
| 63 | | - {id: PI1.2, family: Processing Integrity, title: "The entity implements policies and procedures over system inputs, including controls over completeness and accuracy, to meet its objectives."} |
| 64 | | - {id: PI1.3, family: Processing Integrity, title: "The entity implements policies and procedures over system processing to result in products, services, and reporting that meet its objectives."} |
| 65 | | - {id: PI1.4, family: Processing Integrity, title: "The entity implements policies and procedures to make available or deliver output completely, accurately, and in a timely manner to meet its objectives."} |
| 66 | | - {id: PI1.5, family: Processing Integrity, title: "The entity implements policies and procedures to store inputs, items in processing, and outputs completely, accurately, and in a timely manner to meet its objectives."} |
| 70 | - {id: PI1.1, family: Processing Integrity, title: "Quality information about processing objectives and specs"} |
| 71 | - {id: PI1.2, family: Processing Integrity, title: "Input controls for completeness and accuracy"} |
| 72 | - {id: PI1.3, family: Processing Integrity, title: "Processing controls producing objective-meeting output"} |
| 73 | - {id: PI1.4, family: Processing Integrity, title: "Output delivered completely, accurately, and on time"} |
| 74 | - {id: PI1.5, family: Processing Integrity, title: "Storage of inputs, work in process, and outputs"} |
| 67 | 75 | # Privacy category |
| 68 | | - {id: P1.1, family: Privacy, title: "The entity provides notice to data subjects about its privacy practices to meet its objectives related to privacy."} |
| 69 | | - {id: P2.1, family: Privacy, title: "The entity communicates choices about the collection, use, retention, disclosure, and disposal of personal information, and obtains consent, to meet its privacy objectives."} |
| 70 | | - {id: P3.1, family: Privacy, title: "Personal information is collected consistent with the entity's objectives related to privacy."} |
| 71 | | - {id: P3.2, family: Privacy, title: "For information requiring explicit consent, the entity communicates the need for and obtains consent prior to collection of personal information."} |
| 72 | | - {id: P4.1, family: Privacy, title: "The entity limits the use of personal information to the purposes identified in its objectives related to privacy."} |
| 73 | | - {id: P4.2, family: Privacy, title: "The entity retains personal information consistent with its objectives related to privacy."} |
| 74 | | - {id: P4.3, family: Privacy, title: "The entity securely disposes of personal information to meet its objectives related to privacy."} |
| 75 | | - {id: P5.1, family: Privacy, title: "The entity grants data subjects the ability to access their stored personal information for review and, upon request, provides copies, to meet its privacy objectives."} |
| 76 | | - {id: P5.2, family: Privacy, title: "The entity corrects, amends, or appends personal information based on data subject input and communicates it to third parties, to meet its privacy objectives."} |
| 77 | | - {id: P6.1, family: Privacy, title: "The entity discloses personal information to third parties only with the explicit consent of data subjects and consistent with its privacy objectives."} |
| 78 | | - {id: P6.2, family: Privacy, title: "The entity creates and retains a complete, accurate, and timely record of authorized disclosures of personal information."} |
| 79 | | - {id: P6.3, family: Privacy, title: "The entity creates and retains a complete, accurate, and timely record of detected or reported unauthorized disclosures of personal information."} |
| 80 | | - {id: P6.4, family: Privacy, title: "The entity obtains privacy commitments from vendors and other third parties who have access to personal information, to meet its privacy objectives."} |
| 81 | | - {id: P6.5, family: Privacy, title: "The entity obtains commitments from vendors and third parties to notify it of actual or suspected unauthorized disclosures of personal information."} |
| 82 | | - {id: P6.6, family: Privacy, title: "The entity provides notification of breaches and incidents of unauthorized disclosure of personal information to affected data subjects, regulators, and others."} |
| 83 | | - {id: P6.7, family: Privacy, title: "The entity provides data subjects with an accounting of the personal information held and disclosures made, upon request."} |
| 84 | | - {id: P7.1, family: Privacy, title: "The entity collects and maintains accurate, up-to-date, complete, and relevant personal information to meet its privacy objectives."} |
| 85 | | - {id: P8.1, family: Privacy, title: "The entity implements a process for receiving, addressing, resolving, and communicating the resolution of privacy inquiries, complaints, and disputes."} |
| 76 | - {id: P1.1, family: Privacy, title: "Notice of privacy practices to data subjects"} |
| 77 | - {id: P2.1, family: Privacy, title: "Choice and consent over personal-information handling"} |
| 78 | - {id: P3.1, family: Privacy, title: "Collection consistent with privacy objectives"} |
| 79 | - {id: P3.2, family: Privacy, title: "Explicit consent obtained before collection where required"} |
| 80 | - {id: P4.1, family: Privacy, title: "Use of personal information limited to stated purposes"} |
| 81 | - {id: P4.2, family: Privacy, title: "Retention of personal information per objectives"} |
| 82 | - {id: P4.3, family: Privacy, title: "Secure disposal of personal information"} |
| 83 | - {id: P5.1, family: Privacy, title: "Data-subject access to their personal information"} |
| 84 | - {id: P5.2, family: Privacy, title: "Correction and amendment of personal information"} |
| 85 | - {id: P6.1, family: Privacy, title: "Third-party disclosure only with consent"} |
| 86 | - {id: P6.2, family: Privacy, title: "Record of authorized disclosures"} |
| 87 | - {id: P6.3, family: Privacy, title: "Record of unauthorized disclosures"} |
| 88 | - {id: P6.4, family: Privacy, title: "Privacy commitments obtained from vendors and third parties"} |
| 89 | - {id: P6.5, family: Privacy, title: "Vendor commitments to notify of unauthorized disclosure"} |
| 90 | - {id: P6.6, family: Privacy, title: "Breach notification to affected parties and regulators"} |
| 91 | - {id: P6.7, family: Privacy, title: "Accounting of personal information and disclosures on request"} |
| 92 | - {id: P7.1, family: Privacy, title: "Accuracy and currency of personal information"} |
| 93 | - {id: P8.1, family: Privacy, title: "Handling of privacy inquiries, complaints, and disputes"} |