FintastIQTrust Center
LoginBook a Consultation
Framework

SOC 2 Trust Services Criteria (Security, Availability, Confidentiality, Processing Integrity)

Version: 2017 TSC with revised points of focus (2022)

The AICPA Trust Services Criteria a CPA firm tests in a SOC 2 examination: the common criteria for security plus the additional criteria for availability, confidentiality, and processing integrity. Applies to service organizations whose customers rely on the controls over systems they operate on the customer's behalf.

Official source

Summary

Where we stand

Controls
55%
Evidence
5%
Policies
13%

38 of 43 clauses mapped to adopted controls

As of (just now)

Percentages are over clauses mapped to at least one adopted control. Unmapped clauses are listed below and never count as passing. A known gap is a clause that applies to us and that no control covers yet.

Clauses

Clause-by-clause readiness

ClauseTitleControlsEvidencePoliciesLast tested
CC1 Control environment
CC1.1Commitment to integrity and ethical values (COSO Principle 1)
Controls: PEOPLE-02, PEOPLE-04, PEOPLE-07, PEOPLE-15
PassingNot currentNot approved(4 mo ago)
CC1.2Board independence and oversight (COSO Principle 2)
Controls: BIZ-11, BIZ-12
PassingNot currentApprovedNot yet
CC1.3Organizational structure, reporting lines, and authority (COSO Principle 3)
Controls: BIZ-15, PEOPLE-08, PEOPLE-09
Not passingNot currentNot approvedNot yet
CC1.4Commitment to competence (COSO Principle 4)
Controls: APP-01, PEOPLE-01, PEOPLE-05, PEOPLE-06, PEOPLE-08
Not passingNot currentNot approved(8 h ago)
CC1.5Accountability for internal control (COSO Principle 5)
Controls: PEOPLE-05, PEOPLE-07
PassingNot currentNot approved(29 d ago)
CC2 Communication and information
CC2.1Relevant, quality information (COSO Principle 13)
Controls: IT-05
PassingNot currentNot approvedNot yet
CC2.2Internal communication (COSO Principle 14)
Controls: BIZ-12, BIZ-13, BIZ-14, IT-01, PEOPLE-04, PEOPLE-06
Not passingNot currentNot approved(8 h ago)
CC2.3External communication (COSO Principle 15)
Controls: CUST-01, CUST-02, CUST-03, CUST-04, LEGAL-01
Not passingNot currentApproved(4 mo ago)
CC3 Risk assessment
CC3.1Objectives specified with clarity (COSO Principle 6)
Controls: BIZ-04
PassingNot currentNot approvedNot yet
CC3.2Risk identification and analysis (COSO Principle 7)
Controls: BIZ-04, BIZ-05, VEND-03
PassingNot currentNot approved(4 mo ago)
CC3.3Fraud risk assessment (COSO Principle 8)
Controls: BIZ-06
PassingCurrentNot approved(4 mo ago)
CC3.4Assessment of significant change (COSO Principle 9)
Controls: BIZ-04, PDP-14
PassingNot currentNot approved(4 mo ago)
CC4 Monitoring activities
CC4.1Ongoing and separate evaluations (COSO Principle 16)
Controls: BIZ-08, MON-04
Not passingNot currentNot approved(8 h ago)
CC4.2Evaluation and communication of deficiencies (COSO Principle 17)
Controls: BIZ-08, BIZ-09, BIZ-12
PassingNot currentApprovedNot yet
CC5 Control activities
CC5.1Selection and development of control activities (COSO Principle 10)
Controls: BIZ-07, BIZ-15
PassingNot currentNot approvedNot yet
CC5.2General controls over technology (COSO Principle 11)
Controls: BIZ-07, PDP-01, PDP-02
PassingNot currentNot approved(23 d ago)
CC5.3Policies and procedures (COSO Principle 12)
Controls: BIZ-14, IT-01, PEOPLE-04
PassingNot currentNot approved(4 mo ago)
CC6 Logical and physical access controls
CC6.1Logical access security architecture
Controls: CLOUD-03, CLOUD-06, DATA-01, DATA-02, DATA-06, IAM-01, IAM-02, IAM-03, IAM-05, IAM-06, IAM-08, IT-02, IT-04, IT-05
Not passingNot currentNot approved(8 h ago)
CC6.2User registration, authorization, and removal
Controls: IAM-01, IAM-07, IAM-09, PEOPLE-03
Not passingCurrentNot approved(8 h ago)
CC6.3Role-based access and least privilege
Controls: IAM-04, IAM-05, IAM-06, IAM-07, IAM-09, PDP-05
Not passingNot currentNot approved(29 d ago)
CC6.4Physical access restrictions
Controls: PHYS-01
PassingNot currentNot approvedNot yet
CC6.5Secure disposal of assets
Controls: DATA-05
PassingNot currentNot approvedNot yet
CC6.6Protection against external threats
Controls: CLOUD-03, CLOUD-04, IAM-02
Not passingNot currentNot approved(8 h ago)
CC6.7Data transmission and movement
Controls: CLOUD-01, DATA-03, DATA-06
Not passingNot currentNot approved(8 h ago)
CC6.8Unauthorized and malicious software
Controls: IT-03
Not passingNot currentApproved(8 h ago)
CC7 System operations
CC7.1Vulnerability and configuration monitoring
Controls: APP-02, CLOUD-02, CLOUD-04, CLOUD-05, IT-03, MON-04, MON-05, MON-06
Not passingNot currentNot approved(8 h ago)
CC7.2Anomaly and security event monitoring
Controls: MON-01, MON-02, MON-03
Not passingNot currentNot approved(3 mo ago)
CC7.3Security event evaluation
Controls: BIZ-02, BIZ-03, MON-03
Not passingNot currentNot approved(8 h ago)
CC7.4Incident response
Controls: BIZ-02, BIZ-03, BIZ-21
PassingNot currentNot approved(8 h ago)
CC7.5Incident recovery
Controls: BIZ-02, DATA-12, DATA-15
PassingNot currentNot approved(29 d ago)
CC8 Change management
CC8.1Change authorization, testing, and approval
Controls: APP-01, APP-02, CLOUD-02, CLOUD-06, PDP-01, PDP-02, PDP-03, PDP-04, PDP-05, PDP-06, PDP-14
Not passingNot currentNot approved(8 h ago)
CC9 Risk mitigation
CC9.1Business disruption risk mitigation
Controls: BIZ-01, BIZ-10
Not passingNot currentNot approved(3 mo ago)
CC9.2Vendor and business partner risk management
Controls: VEND-01, VEND-02, VEND-03, VEND-04
Not passingNot currentNot approved(8 h ago)
A1 Additional criteria for availability
A1.1Capacity managementUnmappedUnmappedUnmappedNot yet
A1.2Environmental protections, backup, and recovery infrastructure
Controls: BIZ-01, DATA-12, DATA-13, DATA-14
PassingNot currentNot approved(29 d ago)
A1.3Recovery plan testing
Controls: BIZ-20, DATA-15
PassingNot currentNot approvedNot yet
C1 Additional criteria for confidentiality
C1.1Identification and protection of confidential information
Controls: DATA-01, DATA-02, DATA-03, PEOPLE-02
PassingNot currentNot approved(8 h ago)
C1.2Disposal of confidential information
Controls: DATA-04, DATA-05
PassingNot currentNot approvedNot yet
PI1 Additional criteria for processing integrity
PI1.1Processing specifications and data definitions
Controls: CUST-03
PassingNot currentApprovedNot yet
PI1.2System input controlsUnmappedUnmappedUnmappedNot yet
PI1.3System processing controlsUnmappedUnmappedUnmappedNot yet
PI1.4System output controlsUnmappedUnmappedUnmappedNot yet
PI1.5Storage of inputs, in-process items, and outputsUnmappedUnmappedUnmappedNot yet