SOC 2 (2017 TSC): the evidence behind every control
61 controls. For each, the artefacts auditors ask for, which ones a system already holds, and the first move to stop evidencing it by periodic review.
A - Availability
A1.1Maintains capacity to meet availability commitments moderateA1.2Environmental protections, data backups, and recovery infrastructure support availability hardA1.3Recovery plan procedures support system recovery from failures hardC - Confidentiality
C1.1Confidential information is identified and protected during receipt, processing, storage hardC1.2Confidential information is disposed of securely hardCC - Common Criteria (Security)
CC1.1COSO principle 1: Demonstrates commitment to integrity and ethical values hardCC1.2COSO principle 2: Board exercises oversight responsibility hardCC1.3COSO principle 3: Management establishes structures, reporting lines, and authorities hardCC1.4COSO principle 4: Demonstrates commitment to attract and retain competent individuals hardCC1.5COSO principle 5: Holds individuals accountable for internal control responsibilities hardCC2.1COSO principle 13: Obtains and generates relevant, quality information hardCC2.2COSO principle 14: Internally communicates information including objectives and responsibilities hardCC2.3COSO principle 15: Communicates with external parties regarding matters affecting controls hardCC3.1COSO principle 6: Specifies objectives to identify and assess risks hardCC3.2COSO principle 7: Identifies risks and analyzes to determine how managed hardCC3.3COSO principle 8: Considers potential for fraud hardCC3.4COSO principle 9: Identifies and assesses changes that could impact internal controls hardCC4.1COSO principle 16: Selects and develops ongoing and separate evaluations hardCC4.2COSO principle 17: Evaluates and communicates deficiencies in a timely manner hardCC5.1COSO principle 10: Selects and develops control activities to mitigate risks hardCC5.2COSO principle 11: Selects and develops general controls over technology hardCC5.3COSO principle 12: Deploys control activities through policies and procedures hardCC6.1Implements logical access security software, infrastructure and architectures over protected information assets moderateCC6.2Prior to granting access, registration and authorization processes are established hardCC6.3Role-based access and least privilege are enforced hardCC6.4Restricts physical access to facilities and protected information assets (for example, data center facilities, back-up media storage, and other sensitive locations) to authorized personnel to meet the entity's objectives moderateCC6.5Discontinues logical and physical protections over physical assets only after the ability to read or recover data and software from those assets has been diminished and is no longer required to meet the entity's hardCC6.6Measures against threats outside system boundaries are implemented moderateCC6.7Transmission of data is restricted to authorized users easyCC6.8Controls to prevent or detect unauthorized or malicious software hardCC7.1Detection and monitoring procedures for security events are in place moderateCC7.2Monitors system components for anomalies indicating malicious acts moderateCC7.3Evaluates security events to determine incident status hardCC7.4Responds to identified security incidents through defined procedures hardCC7.5Identifies the root cause of security incidents hardCC8.1Change management processes are in place hardCC9.1Identifies, selects and develops risk mitigation activities hardCC9.2Risk mitigation activities include assessment of vendor and business partner controls hardP - Privacy
P1.1Privacy notice provides clear notice about privacy practices hardP2.1Consent is obtained for the collection, use, and disclosure of personal information hardP3.1Personal information is collected consistent with privacy commitments hardP3.2Explicit consent is obtained for sensitive personal information hardP4.1Personal information is used for purposes identified in privacy commitments hardP4.2Personal information is retained for only as long as needed easyP4.3Personal information is securely disposed of hardP5.1Personal information is accessed only by authorized personnel hardP5.2Corrections to personal information are processed timely hardP6.1Personal information is disclosed to third parties only as committed hardP6.2Records of personal information disclosures are maintained moderateP6.3Creates and retains a complete, accurate, and timely record of detected or reported unauthorized disclosures (including breaches) of personal information to meet the entity's objectives related to privacy. The following point of focus, which hardP6.4Obtains privacy commitments from vendors and other third parties who have access to personal information to meet the entity's objectives related to privacy. The entity assesses those parties' compliance on a periodic and as-needed hardP6.5Obtains commitments from vendors and other third parties with access to personal information to notify the entity in the event of actual or suspected unauthorized disclosures of personal information. Such notifications are reported to hardP6.6Provides notification of breaches and incidents to affected data subjects, regulators, and others to meet the entity's objectives related to privacy hardP6.7Provides data subjects with an accounting of the personal information held and disclosure of the data subjects' personal information, upon the data subjects' request, to meet the entity's objectives related to privacy hardP7.1Personal information collected is limited to what is necessary and relevant hardP8.1Inquiries, complaints, and disputes regarding personal information are addressed hardPI - Processing Integrity
PI1.1Obtains or generates and uses relevant quality information to support processing integrity hardPI1.2System inputs are complete, accurate, and processed in a timely manner hardPI1.3System processing is complete, valid, accurate, timely, and authorized hardPI1.4System outputs are complete, valid, accurate, timely, and distributed moderatePI1.5Inputs are processed completely, accurately, and timely for stored data hard