Skip to content
Permalink
Branch: master
Find file Copy path
Find file Copy path
Fetching contributors…
Cannot retrieve contributors at this time
212 lines (212 sloc) 9.47 KB
{
"standard": "SOC 2",
"version": "TSC Security",
"webLink": "https://www.aicpa.org/content/dam/aicpa/interestareas/frc/assuranceadvisoryservices/downloadabledocuments/trust-services-criteria.pdf",
"domains": [
{
"title": "Control Environment",
"controls": [
{
"ref": "CC1.1",
"title": "COSO Principle 1",
"summary": "The entity demonstrates a commitment to integrity and ethical values."
},
{
"ref": "CC1.2",
"title": "COSO Principle 2",
"summary": "The board of directors demonstrates independence from management and exercises oversight of the development and performance of internal control."
},
{
"ref": "CC1.3",
"title": "COSO Principle 3",
"summary": "Management establishes, with board oversight, structures, reporting lines, and appropriate authorities and responsibilities in the pursuit of objectives."
},
{
"ref": "CC1.4",
"title": "COSO Principle 4",
"summary": "The entity demonstrates a commitment to attract, develop, and retain competent individuals in alignment with objectives."
},
{
"ref": "CC1.5",
"title": "COSO Principle 5",
"summary": "The entity holds individuals accountable for their internal control responsibilities in the pursuit of objectives."
}
]
},
{
"title": "Communication And Information",
"controls": [
{
"ref": "CC2.1",
"title": "COSO Principle 13",
"summary": "The entity obtains or generates and uses relevant, quality information to support the functioning of internal control."
},
{
"ref": "CC2.2",
"title": "COSO Principle 14",
"summary": "The entity internally communicates information, including objectives and responsibilities for internal control, necessary to support the functioning of internal control."
},
{
"ref": "CC2.3",
"title": "COSO Principle 15",
"summary": "The entity communicates with external parties regarding matters affecting the functioning of internal control."
}
]
},
{
"title": "Risk Assessment",
"controls": [
{
"ref": "CC3.1",
"title": "COSO Principle 6",
"summary": "The entity specifies objectives with sufficient clarity to enable the identification and assessment of risks relating to objectives."
},
{
"ref": "CC3.2",
"title": "COSO Principle 7",
"summary": "The entity identifies risks to the achievement of its objectives across the entity and analyzes risks as a basis for determining how the risks should be managed."
},
{
"ref": "CC3.4",
"title": "COSO Principle 9",
"summary": "The entity identifies and assesses changes that could significantly impact the system of internal control."
}
]
},
{
"title": "Monitoring Activities",
"controls": [
{
"ref": "CC4.1",
"title": "COSO Principle 16",
"summary": "The entity selects, develops, and performs ongoing and/or separate evaluations to ascertain whether the components of internal control are present and functioning."
},
{
"ref": "CC4.2",
"title": "COSO Principle 17",
"summary": "The entity evaluates and communicates internal control deficiencies in a timely manner to those parties responsible for taking corrective action, including senior management and the board of directors, as appropriate."
}
]
},
{
"title": "Control Activities",
"controls": [
{
"ref": "CC5.1",
"title": "COSO Principle 10",
"summary": "The entity selects and develops control activities that contribute to the mitigation of risks to the achievement of objectives to acceptable levels."
},
{
"ref": "CC5.2",
"title": "COSO Principle 11",
"summary": "The entity also selects and develops general control activities over technology to support the achievement of objectives."
},
{
"ref": "CC5.3",
"title": "COSO Principle 12",
"summary": "The entity deploys control activities through policies that establish what is expected and in procedures that put policies into action."
}
]
},
{
"title": "Logical And Physical Access Controls",
"controls": [
{
"ref": "CC6.1",
"title": "CC6.1",
"summary": "The entity implements logical access security software, infrastructure, and architectures over protected information assets to protect them from security events to meet the entity's objectives."
},
{
"ref": "CC6.2",
"title": "CC6.2",
"summary": "Prior to issuing system credentials and granting system access, the entity registers and authorizes new internal and external users whose access is administered by the entity. For those users whose access is administered by the entity, user system credentials are removed when user access is no longer authorized."
},
{
"ref": "CC6.3",
"title": "CC6.3",
"summary": "The entity authorizes, modifies, or removes access to data, software, functions, and other protected information assets based on roles, responsibilities, or the system design and changes, giving consideration to the concepts of least privilege and segregation of duties, to meet the entity’s objectives."
},
{
"ref": "CC6.4",
"title": "CC6.4",
"summary": "The entity restricts physical access to facilities and protected information assets (for example, data center facilities, back-up media storage, and other sensitive locations) to authorized personnel to meet the entity’s objectives."
},
{
"ref": "CC6.5",
"title": "CC6.5",
"summary": "The entity discontinues logical and physical protections over physical assets only after the ability to read or recover data and software from those assets has been diminished and is no longer required to meet the entity’s objectives."
},
{
"ref": "CC6.6",
"title": "CC6.6",
"summary": "The entity implements logical access security measures to protect against threats from sources outside its system boundaries."
},
{
"ref": "CC6.7",
"title": "CC6.7",
"summary": "The entity restricts the transmission, movement, and removal of information to authorized internal and external users and processes, and protects it during transmission, movement, or removal to meet the entity’s objectives."
},
{
"ref": "CC6.8",
"title": "CC6.8",
"summary": "The entity implements controls to prevent or detect and act upon the introduction of unauthorized or malicious software to meet the entity’s objectives."
}
]
},
{
"title": "System Operations",
"controls": [
{
"ref": "CC7.1",
"title": "CC7.1",
"summary": "To meet its objectives, the entity uses detection and monitoring procedures to identify (1) changes to configurations that result in the introduction of new vulnerabilities, and (2) susceptibilities to newly discovered vulnerabilities."
},
{
"ref": "CC7.2",
"title": "CC7.2",
"summary": "The entity monitors system components and the operation of those components for anomalies that are indicative of malicious acts, natural disasters, and errors affecting the entity's ability to meet its objectives; anomalies are analyzed to determine whether they represent security events."
},
{
"ref": "CC7.3",
"title": "CC7.3",
"summary": "The entity evaluates security events to determine whether they could or have resulted in a failure of the entity to meet its objectives (security incidents) and, if so, takes actions to prevent or address such failures."
},
{
"ref": "CC7.4",
"title": "CC7.4",
"summary": "The entity responds to identified security incidents by executing a defined incident response program to understand, contain, remediate, and communicate security incidents, as appropriate."
},
{
"ref": "CC7.5",
"title": "CC7.5",
"summary": "The entity identifies, develops, and implements activities to recover from identified security incidents."
}
]
},
{
"title": "Change Management",
"controls": [
{
"ref": "CC8.1",
"title": "CC8.1",
"summary": "The entity authorizes, designs, develops or acquires, configures, documents, tests, approves, and implements changes to infrastructure, data, software, and procedures to meet its objectives."
}
]
},
{
"title": "Risk Mitigation",
"controls": [
{
"ref": "CC9.1",
"title": "CC9.1",
"summary": "The entity identifies, selects, and develops risk mitigation activities for risks arising from potential business disruptions."
},
{
"ref": "CC9.2",
"title": "CC9.2",
"summary": "The entity assesses and manages risks associated with vendors and business partners."
}
]
}
]
}
You can’t perform that action at this time.