SOC 2 (Type I & II)
Developed by the AICPA, SOC 2 evaluates the extent to which an organization complies with one or more of the five Trust Services Criteria (TSC).
Framework Requirements & Categories
Detailed breakdown of the highly precise, accurate control domains defined by SOC 2 (Type I & II).
CC1: Control Environment
The organization demonstrates a commitment to integrity and ethical values.
CC2: Communication and Information
The organization obtains or generates and uses relevant, quality information.
CC3: Risk Assessment
The organization specifies objectives with sufficient clarity to enable the identification and assessment of risks.
CC4: Monitoring Activities
The organization selects, develops, and performs ongoing and/or separate evaluations.
CC5: Control Activities
The organization selects and develops control activities that contribute to the mitigation of risks.
CC6: Logical and Physical Access
Controls to prevent unauthorized access, detect anomalies, and secure infrastructure.
CC7: System Operations
Monitoring system operations, managing incidents, and vulnerability management.
CC8: Change Management
Processes for authorizing, designing, testing, and approving changes.
CC9: Risk Mitigation
Business disruption mitigation and vendor management.
