United States
SOC 2
SOC 2 is the AICPA's Trust Services Criteria framework used in service-organization audits. It covers the Common Criteria (security) and, where in scope, Availability, Confidentiality, and Processing Integrity, spanning control environment, access control, system operations, change management, and risk mitigation.
43 criterions
Commitment to integrity and ethical values
The entity demonstrates a commitment to integrity and ethical values.
Board independence and oversight
The board of directors demonstrates independence from management and exercises oversight of the development and performance of internal control.
Organisational structure, authority, and responsibility
Management establishes, with board oversight, structures, reporting lines, and appropriate authorities and responsibilities in the pursuit of objectives.
Commitment to competence
The entity demonstrates a commitment to attract, develop, and retain competent individuals in alignment with objectives.
Accountability for internal control responsibilities
The entity holds individuals accountable for their internal control responsibilities in the pursuit of objectives.
Quality information supporting internal control
The entity obtains or generates and uses relevant, quality information to support the functioning of internal control.
Internal communication
The entity internally communicates information, including objectives and responsibilities for internal control, necessary to support the functioning of internal control.
Communication with external parties
The entity communicates with external parties regarding matters affecting the functioning of internal control.
Objectives specified with clarity
The entity specifies objectives with sufficient clarity to enable the identification and assessment of risks relating to objectives.
Risk identification and analysis
The entity identifies risks to the achievement of its objectives across the entity and analyses risks as a basis for determining how the risks should be managed.
Fraud risk consideration
The entity considers the potential for fraud in assessing risks to the achievement of objectives.
Identifying and assessing changes
The entity identifies and assesses changes that could significantly impact the system of internal control.
Ongoing and separate evaluations
The entity selects, develops, and performs ongoing and/or separate evaluations to ascertain whether the components of internal control are present and functioning.
Evaluating and communicating deficiencies
The entity evaluates and communicates internal control deficiencies in a timely manner to those responsible for taking corrective action.
Control activities mitigating risk
The entity selects and develops control activities that contribute to the mitigation of risks to the achievement of objectives to acceptable levels.
General controls over technology
The entity also selects and develops general control activities over technology to support the achievement of objectives.
Deployment through policies and procedures
The entity deploys control activities through policies that establish what is expected and procedures that put policies into action.
Logical access security
The entity implements logical access security software, infrastructure, and architectures over protected information assets to protect them from security events.
User registration, authorisation, and de-provisioning
Prior to issuing system credentials and granting system access, the entity registers and authorises new internal and external users, and removes access when it is no longer required.
Role-based access and least privilege
The entity authorises, modifies, or removes access to data, software, functions, and other protected information assets based on roles, responsibilities, and the principle of least privilege.
Physical access restriction
The entity restricts physical access to facilities and protected information assets to authorised personnel.
Decommissioning protections
The entity discontinues logical and physical protections over physical assets only after the ability to read or recover data has been diminished, and is no longer required to meet objectives.
Boundary protection against external threats
The entity implements logical access security measures to protect against threats from sources outside its system boundaries.
Data transmission and movement controls
The entity restricts the transmission, movement, and removal of information to authorised internal and external users and processes, and protects it during transmission, movement, or removal.
Malicious software prevention and detection
The entity implements controls to prevent or detect and act upon the introduction of unauthorised or malicious software.
Vulnerability detection and monitoring
The entity uses detection and monitoring procedures to identify changes to configurations that result in the introduction of new vulnerabilities, and susceptibilities to newly discovered vulnerabilities.
Monitoring for security events
The entity monitors system components and the operation of controls to detect anomalies that are indicative of malicious acts, natural disasters, or errors affecting the entity's ability to meet its objectives.
Evaluating security events
The entity evaluates security events to determine whether they could or did result in a failure to meet objectives, and, if so, takes actions to prevent or address such failures.
Incident response
The entity responds to identified security incidents by executing a defined incident response programme to understand, contain, remediate, and communicate security incidents, as appropriate.
Recovery from security incidents
The entity identifies, develops, and implements activities to recover from identified security incidents.
Change authorisation and testing
The entity authorises, designs, develops or acquires, configures, documents, tests, approves, and implements changes to infrastructure, data, software, and procedures to meet its objectives.
Business disruption risk mitigation
The entity identifies, develops, and implements activities to mitigate risk arising from potential business disruptions.
Vendor and business partner risk management
The entity assesses and manages risks associated with vendors and business partners.
Capacity management
The entity maintains, monitors, and evaluates current processing capacity and use of system components to manage capacity demand and to enable the implementation of additional capacity to help meet its objectives.
Environmental protections and backup infrastructure
The entity authorises, designs, develops or acquires, implements, operates, approves, maintains, and monitors environmental protections, software, data backup processes, and recovery infrastructure to meet its objectives.
Recovery plan testing
The entity tests recovery plan procedures supporting system recovery to meet its objectives.
Identifying and maintaining confidential information
The entity identifies and maintains confidential information to meet its objectives related to confidentiality.
Disposal of confidential information
The entity disposes of confidential information to meet its objectives related to confidentiality.
Processing integrity objectives and system requirements
The entity obtains or generates, uses, and communicates relevant, quality information regarding the objectives related to processing integrity to support the use of the entity's products and services.
Input completeness, accuracy, and timeliness
The entity implements policies and procedures over system inputs, including controls over completeness and accuracy, to result in products, services, and reporting to meet the entity's objectives.
Processing completeness, accuracy, and timeliness
The entity implements policies and procedures over system processing to result in products, services, and reporting to meet the entity's objectives.
Output completeness, accuracy, and timeliness
The entity implements policies and procedures to make available or deliver output completely, accurately, and timely in accordance with specifications to meet the entity's objectives.
Storage completeness, accuracy, and timeliness
The entity implements policies and procedures to store inputs, items in processing, and outputs completely, accurately, and timely in accordance with system specifications to meet the entity's objectives.
Turn SOC 2 into tracked tasks
eurocompliant maps these obligations to checklists and evidence, so you can prove compliance instead of re-reading the text.
Start free trial