SOC 2 Trust Services Criteria (Security, Availability, Confidentiality, Processing Integrity)
Version: 2017 TSC with revised points of focus (2022)
The AICPA Trust Services Criteria a CPA firm tests in a SOC 2 examination: the common criteria for security plus the additional criteria for availability, confidentiality, and processing integrity. Applies to service organizations whose customers rely on the controls over systems they operate on the customer's behalf.
Where we stand
Controls
55%
Evidence
5%
Policies
13%
38 of 43 clauses mapped to adopted controls
As of (just now)
Percentages are over clauses mapped to at least one adopted control. Unmapped clauses are listed below and never count as passing. A known gap is a clause that applies to us and that no control covers yet.
Clause-by-clause readiness
| Clause | Title | Controls | Evidence | Policies | Last tested |
|---|---|---|---|---|---|
| CC1 Control environment | |||||
| CC1.1 | Commitment to integrity and ethical values (COSO Principle 1) Controls: PEOPLE-02, PEOPLE-04, PEOPLE-07, PEOPLE-15 | Passing | Not current | Not approved | (4 mo ago) |
| CC1.2 | Board independence and oversight (COSO Principle 2) Controls: BIZ-11, BIZ-12 | Passing | Not current | Approved | Not yet |
| CC1.3 | Organizational structure, reporting lines, and authority (COSO Principle 3) Controls: BIZ-15, PEOPLE-08, PEOPLE-09 | Not passing | Not current | Not approved | Not yet |
| CC1.4 | Commitment to competence (COSO Principle 4) Controls: APP-01, PEOPLE-01, PEOPLE-05, PEOPLE-06, PEOPLE-08 | Not passing | Not current | Not approved | (8 h ago) |
| CC1.5 | Accountability for internal control (COSO Principle 5) Controls: PEOPLE-05, PEOPLE-07 | Passing | Not current | Not approved | (29 d ago) |
| CC2 Communication and information | |||||
| CC2.1 | Relevant, quality information (COSO Principle 13) Controls: IT-05 | Passing | Not current | Not approved | Not yet |
| CC2.2 | Internal communication (COSO Principle 14) Controls: BIZ-12, BIZ-13, BIZ-14, IT-01, PEOPLE-04, PEOPLE-06 | Not passing | Not current | Not approved | (8 h ago) |
| CC2.3 | External communication (COSO Principle 15) Controls: CUST-01, CUST-02, CUST-03, CUST-04, LEGAL-01 | Not passing | Not current | Approved | (4 mo ago) |
| CC3 Risk assessment | |||||
| CC3.1 | Objectives specified with clarity (COSO Principle 6) Controls: BIZ-04 | Passing | Not current | Not approved | Not yet |
| CC3.2 | Risk identification and analysis (COSO Principle 7) Controls: BIZ-04, BIZ-05, VEND-03 | Passing | Not current | Not approved | (4 mo ago) |
| CC3.3 | Fraud risk assessment (COSO Principle 8) Controls: BIZ-06 | Passing | Current | Not approved | (4 mo ago) |
| CC3.4 | Assessment of significant change (COSO Principle 9) Controls: BIZ-04, PDP-14 | Passing | Not current | Not approved | (4 mo ago) |
| CC4 Monitoring activities | |||||
| CC4.1 | Ongoing and separate evaluations (COSO Principle 16) Controls: BIZ-08, MON-04 | Not passing | Not current | Not approved | (8 h ago) |
| CC4.2 | Evaluation and communication of deficiencies (COSO Principle 17) Controls: BIZ-08, BIZ-09, BIZ-12 | Passing | Not current | Approved | Not yet |
| CC5 Control activities | |||||
| CC5.1 | Selection and development of control activities (COSO Principle 10) Controls: BIZ-07, BIZ-15 | Passing | Not current | Not approved | Not yet |
| CC5.2 | General controls over technology (COSO Principle 11) Controls: BIZ-07, PDP-01, PDP-02 | Passing | Not current | Not approved | (23 d ago) |
| CC5.3 | Policies and procedures (COSO Principle 12) Controls: BIZ-14, IT-01, PEOPLE-04 | Passing | Not current | Not approved | (4 mo ago) |
| CC6 Logical and physical access controls | |||||
| CC6.1 | Logical access security architecture Controls: CLOUD-03, CLOUD-06, DATA-01, DATA-02, DATA-06, IAM-01, IAM-02, IAM-03, IAM-05, IAM-06, IAM-08, IT-02, IT-04, IT-05 | Not passing | Not current | Not approved | (8 h ago) |
| CC6.2 | User registration, authorization, and removal Controls: IAM-01, IAM-07, IAM-09, PEOPLE-03 | Not passing | Current | Not approved | (8 h ago) |
| CC6.3 | Role-based access and least privilege Controls: IAM-04, IAM-05, IAM-06, IAM-07, IAM-09, PDP-05 | Not passing | Not current | Not approved | (29 d ago) |
| CC6.4 | Physical access restrictions Controls: PHYS-01 | Passing | Not current | Not approved | Not yet |
| CC6.5 | Secure disposal of assets Controls: DATA-05 | Passing | Not current | Not approved | Not yet |
| CC6.6 | Protection against external threats Controls: CLOUD-03, CLOUD-04, IAM-02 | Not passing | Not current | Not approved | (8 h ago) |
| CC6.7 | Data transmission and movement Controls: CLOUD-01, DATA-03, DATA-06 | Not passing | Not current | Not approved | (8 h ago) |
| CC6.8 | Unauthorized and malicious software Controls: IT-03 | Not passing | Not current | Approved | (8 h ago) |
| CC7 System operations | |||||
| CC7.1 | Vulnerability and configuration monitoring Controls: APP-02, CLOUD-02, CLOUD-04, CLOUD-05, IT-03, MON-04, MON-05, MON-06 | Not passing | Not current | Not approved | (8 h ago) |
| CC7.2 | Anomaly and security event monitoring Controls: MON-01, MON-02, MON-03 | Not passing | Not current | Not approved | (3 mo ago) |
| CC7.3 | Security event evaluation Controls: BIZ-02, BIZ-03, MON-03 | Not passing | Not current | Not approved | (8 h ago) |
| CC7.4 | Incident response Controls: BIZ-02, BIZ-03, BIZ-21 | Passing | Not current | Not approved | (8 h ago) |
| CC7.5 | Incident recovery Controls: BIZ-02, DATA-12, DATA-15 | Passing | Not current | Not approved | (29 d ago) |
| CC8 Change management | |||||
| CC8.1 | Change authorization, testing, and approval Controls: APP-01, APP-02, CLOUD-02, CLOUD-06, PDP-01, PDP-02, PDP-03, PDP-04, PDP-05, PDP-06, PDP-14 | Not passing | Not current | Not approved | (8 h ago) |
| CC9 Risk mitigation | |||||
| CC9.1 | Business disruption risk mitigation Controls: BIZ-01, BIZ-10 | Not passing | Not current | Not approved | (3 mo ago) |
| CC9.2 | Vendor and business partner risk management Controls: VEND-01, VEND-02, VEND-03, VEND-04 | Not passing | Not current | Not approved | (8 h ago) |
| A1 Additional criteria for availability | |||||
| A1.1 | Capacity management | Unmapped | Unmapped | Unmapped | Not yet |
| A1.2 | Environmental protections, backup, and recovery infrastructure Controls: BIZ-01, DATA-12, DATA-13, DATA-14 | Passing | Not current | Not approved | (29 d ago) |
| A1.3 | Recovery plan testing Controls: BIZ-20, DATA-15 | Passing | Not current | Not approved | Not yet |
| C1 Additional criteria for confidentiality | |||||
| C1.1 | Identification and protection of confidential information Controls: DATA-01, DATA-02, DATA-03, PEOPLE-02 | Passing | Not current | Not approved | (8 h ago) |
| C1.2 | Disposal of confidential information Controls: DATA-04, DATA-05 | Passing | Not current | Not approved | Not yet |
| PI1 Additional criteria for processing integrity | |||||
| PI1.1 | Processing specifications and data definitions Controls: CUST-03 | Passing | Not current | Approved | Not yet |
| PI1.2 | System input controls | Unmapped | Unmapped | Unmapped | Not yet |
| PI1.3 | System processing controls | Unmapped | Unmapped | Unmapped | Not yet |
| PI1.4 | System output controls | Unmapped | Unmapped | Unmapped | Not yet |
| PI1.5 | Storage of inputs, in-process items, and outputs | Unmapped | Unmapped | Unmapped | Not yet |
