Data transmission and movement controls
Summary
The entity restricts the transmission, movement, and removal of information to authorised internal and external users and processes, and protects it during transmission, movement, or removal.
Read the full official text: https://www.aicpa-cima.com/resources/download/2022-trust-services-criteria
← Criterion CC6.6
Boundary protection against external threats
Criterion CC6.8 →
Malicious software prevention and detection
Track SOC 2 criterion CC6.7 as evidence
eurocompliant maps this obligation to a checklist task and the evidence that satisfies it, alongside every other framework you follow.
Start free trial