logo

Database

SOC2®

Last updated: 2024/02/08
logo

These reports are intended to meet the needs of a broad range of users that need detailed information and assurance about the controls at a service organization relevant to security, availability, and processing integrity of the systems used by the organization to process users' data, as well as the confidentiality and privacy of the information processed by these systems. The version used in this section is 2017 Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy (last revisions made in March 2020).

Control-Requirement Mapping

DefinitionRequirements
CC2_3. Communication and information
CC5_1. Control activities
CC5_2. Control activities
CC6_1. Logical and physical access controls
CC6_2. Logical and physical access controls
CC6_3. Logical and physical access controls
CC6_4. Logical and physical access controls
CC6_5. Logical and physical access controls
CC6_6. Logical and physical access controls
CC6_7. Logical and physical access controls
CC6_8. Logical and physical access controls
C1_1. Additional criteria for confidentiality
C1_2. Additional criteria for confidentiality
P1_1. Additional criteria for privacy (related to notice and communication of objectives related to privacy)
P2_1. Additional criteria for privacy (related to choice and consent)
P3_1. Additional criteria for privacy (related to collection)
P3_2. Additional criteria for privacy (related to collection)
P4_1. Additional criteria for privacy (related to use, retention, and disposal)
P4_2. Additional criteria for privacy (related to use, retention, and disposal)
P4_3. Additional criteria for privacy (related to use, retention, and disposal)
P5_2. Additional criteria for privacy (related to access)
P6_1. Additional criteria for privacy (related to disclosure and notification)
P6_2. Additional criteria for privacy (related to disclosure and notification)
P6_3. Additional criteria for privacy (related to disclosure and notification)
P6_5. Additional criteria for privacy (related to disclosure and notification)