United States (AICPA) and international (IAASB); used worldwide by service organisations serving audited user entities

SOC 1 (SSAE 18 / ISAE 3402)

76 controls. 9 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

76 controls 9 frameworks share controls with it United States (AICPA) and international (IAASB); used worldwide by service organisations serving audited user entities verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

There is no implementation kit for this framework yet. The control list and the overlap above are free and complete.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
CO-Backup-1Backup Execution0
CO-Backup-2Backup Restoration Testing0
CO-Backup-3Backup Offsite Storage and Encryption0
CO-ChangeMgmt-1Change Authorization and Approval0
CO-ChangeMgmt-2Change Testing0
CO-ChangeMgmt-3Segregation of Duties in Change Deployment2
CO-ChangeMgmt-4Emergency Change Management0
CO-ChangeMgmt-5Infrastructure and Database Change Control3
CO-ComputerOps-1Job Scheduling and Monitoring0
CO-ComputerOps-2Problem and Incident Management0
CO-ComputerOps-3Capacity and Performance Monitoring0
CO-DataIntegrity-1Data Input and Processing Integrity0
CO-DataIntegrity-2Interface and File Transfer Controls0
CO-Incident-1Incident Response Plan0
CO-Incident-2Security Incident Detection and Response0
CO-LogicalAccess-1User Access Provisioning1
CO-LogicalAccess-2User Access Termination0
CO-LogicalAccess-3Periodic User Access Review0
CO-LogicalAccess-4Privileged Access Management1
CO-LogicalAccess-5Password and Authentication Configuration0
CO-LogicalAccess-6Multi-Factor Authentication0
CO-LogicalAccess-7Segregation of Duties in Financial Systems2
CO-Monitoring-1Security Event Logging0
CO-Monitoring-2Intrusion Detection and Alerting0
CO-Monitoring-3Vulnerability Management0
CO-NewDev-1System Development Life Cycle (SDLC)0
CO-NewDev-2Secure Coding and Code Review1
CO-Other-1Risk Assessment for ICFR4
CO-PhysicalAccess-1Data Center Physical Access Restriction0
CO-PhysicalAccess-2Physical Access Review0
CO-Vendor-1Subservice Organization Monitoring0
CO-Vendor-2Complementary User Entity Controls (CUEC) Communication0
A.1SOC 1 A.1 Engage an independent service auditor under AT-C 320 or ISAE 3402, choose type 1 or type 2, and define the system, the services and the period or date0
A.2SOC 1 A.2 Accept responsibility for the description and the assertion, including their completeness, accuracy and method of presentation0
A.3SOC 1 A.3 Have a reasonable basis for the assertion0
A.4SOC 1 A.4 Select the criteria and state them in the assertion0
A.5SOC 1 A.5 Specify the control objectives in the description and name any party that specified them0
A.6SOC 1 A.6 Identify the risks that threaten the control objectives and design, implement and document controls that achieve them0
A.7SOC 1 A.7 Provide the written assertion with the description to user entities0
A.8SOC 1 A.8 Give the service auditor all relevant information and unrestricted access to people0
B.1SOC 1 B.1 Describe the types of services provided and the classes of transactions processed0
B.10SOC 1 B.10 Describe the other relevant aspects of the control environment, risk assessment, information and communication, control activities and monitoring0
B.11SOC 1 B.11 In a type 2 report, describe the relevant changes to the system during the period0
B.12SOC 1 B.12 Omit and distort nothing relevant, while writing for the common needs of a broad range of user entities0
B.2SOC 1 B.2 Describe the procedures by which transactions are initiated, authorised, recorded, processed, corrected and reported0
B.3SOC 1 B.3 Describe the information and records used in performing the procedures0
B.4SOC 1 B.4 Describe how the system captures and addresses significant events and conditions other than transactions0
B.5SOC 1 B.5 Describe the process used to prepare reports and other information for user entities0
B.6SOC 1 B.6 Describe the subservice organisations used and whether the carve-out or the inclusive method applies0
B.7SOC 1 B.7 State the control objectives and the controls designed to achieve them0
B.8SOC 1 B.8 Identify the complementary user entity controls assumed in the design of the service organisation's controls0
B.9SOC 1 B.9 Identify the complementary subservice organisation controls assumed under the carve-out method0
C.1SOC 1 C.1 Control objectives that are reasonable in the circumstances and relevant to user entities' financial reporting0
C.2SOC 1 C.2 Controls suitably designed: risks identified and the controls, if operating effectively, giving reasonable assurance the objectives are achieved0
C.3SOC 1 C.3 Controls implemented and, in a type 2 report, operating effectively throughout the period0
C.4SOC 1 C.4 Deviations investigated, explained and remediated, with fraud and noncompliance assessed for their effect0
C.5SOC 1 C.5 Information produced by the service organisation that the auditor relies on is accurate, complete and sufficiently precise0
C.6SOC 1 C.6 Internal audit reports and regulatory examination reports relating to the services made available0
C.7SOC 1 C.7 Changes to controls during the period managed so that superseded controls can be tested and the changes described0
D.1SOC 1 D.1 Management's written assertion in the form Exhibit B illustrates0
D.10SOC 1 D.10 Use of the report by user entities and their auditors, and the user entity's own complementary controls0
D.2SOC 1 D.2 Written representations, including disclosure of noncompliance, fraud, design deficiencies and subsequent events; refusal is a scope limitation0
D.3SOC 1 D.3 Subsequent events up to the report date disclosed0
D.4SOC 1 D.4 Other information provided by the service organisation kept consistent with the description and clearly outside the opinion0
D.5SOC 1 D.5 The report package: the service auditor's report, management's assertion, the description, the objectives with the controls, tests and results, and other information0
D.6SOC 1 D.6 Restricted use: the report is intended solely for user entities, their auditors and the service organisation's management0
D.7SOC 1 D.7 Modified opinions: their grounds and what a qualified, adverse or disclaimed opinion means for the service organisation and its user entities0
D.8SOC 1 D.8 Communication of noncompliance, fraud or uncorrected misstatements that may affect user entities0
D.9SOC 1 D.9 Bridge letters between report periods0
OBJECTIVE-AREASThe control objective areas service organisations set in practice, read from the held reports; not leaves, because each organisation sets its own0
PART-AEngagement scope and the service organisation's responsibilities0
PART-BThe description of the system (the description criteria)0
PART-CControl objectives and controls: design, operation, deviations and change0
PART-DThe assertion, representations, the report package and its use0
REPORTWhat a SOC 1 report is: the examination under AT-C 320 and ISAE 3402, its lineage from SAS 70 and SSAE 16, and what is held0
SOC-FAMILYSOC 1 against SOC 2 and SOC 3, type 1 against type 2, and the combined SOC 1 and ISAE 3402 report0

Tell me when SOC 1 (SSAE 18 / ISAE 3402) files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What this page is

A control-level reference for SOC 1 (SSAE 18 / ISAE 3402), drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition