CO-Backup-1 | Backup Execution | 0 |
CO-Backup-2 | Backup Restoration Testing | 0 |
CO-Backup-3 | Backup Offsite Storage and Encryption | 0 |
CO-ChangeMgmt-1 | Change Authorization and Approval | 0 |
CO-ChangeMgmt-2 | Change Testing | 0 |
CO-ChangeMgmt-3 | Segregation of Duties in Change Deployment | 2 |
CO-ChangeMgmt-4 | Emergency Change Management | 0 |
CO-ChangeMgmt-5 | Infrastructure and Database Change Control | 3 |
CO-ComputerOps-1 | Job Scheduling and Monitoring | 0 |
CO-ComputerOps-2 | Problem and Incident Management | 0 |
CO-ComputerOps-3 | Capacity and Performance Monitoring | 0 |
CO-DataIntegrity-1 | Data Input and Processing Integrity | 0 |
CO-DataIntegrity-2 | Interface and File Transfer Controls | 0 |
CO-Incident-1 | Incident Response Plan | 0 |
CO-Incident-2 | Security Incident Detection and Response | 0 |
CO-LogicalAccess-1 | User Access Provisioning | 1 |
CO-LogicalAccess-2 | User Access Termination | 0 |
CO-LogicalAccess-3 | Periodic User Access Review | 0 |
CO-LogicalAccess-4 | Privileged Access Management | 1 |
CO-LogicalAccess-5 | Password and Authentication Configuration | 0 |
CO-LogicalAccess-6 | Multi-Factor Authentication | 0 |
CO-LogicalAccess-7 | Segregation of Duties in Financial Systems | 2 |
CO-Monitoring-1 | Security Event Logging | 0 |
CO-Monitoring-2 | Intrusion Detection and Alerting | 0 |
CO-Monitoring-3 | Vulnerability Management | 0 |
CO-NewDev-1 | System Development Life Cycle (SDLC) | 0 |
CO-NewDev-2 | Secure Coding and Code Review | 1 |
CO-Other-1 | Risk Assessment for ICFR | 4 |
CO-PhysicalAccess-1 | Data Center Physical Access Restriction | 0 |
CO-PhysicalAccess-2 | Physical Access Review | 0 |
CO-Vendor-1 | Subservice Organization Monitoring | 0 |
CO-Vendor-2 | Complementary User Entity Controls (CUEC) Communication | 0 |
A.1 | SOC 1 A.1 Engage an independent service auditor under AT-C 320 or ISAE 3402, choose type 1 or type 2, and define the system, the services and the period or date | 0 |
A.2 | SOC 1 A.2 Accept responsibility for the description and the assertion, including their completeness, accuracy and method of presentation | 0 |
A.3 | SOC 1 A.3 Have a reasonable basis for the assertion | 0 |
A.4 | SOC 1 A.4 Select the criteria and state them in the assertion | 0 |
A.5 | SOC 1 A.5 Specify the control objectives in the description and name any party that specified them | 0 |
A.6 | SOC 1 A.6 Identify the risks that threaten the control objectives and design, implement and document controls that achieve them | 0 |
A.7 | SOC 1 A.7 Provide the written assertion with the description to user entities | 0 |
A.8 | SOC 1 A.8 Give the service auditor all relevant information and unrestricted access to people | 0 |
B.1 | SOC 1 B.1 Describe the types of services provided and the classes of transactions processed | 0 |
B.10 | SOC 1 B.10 Describe the other relevant aspects of the control environment, risk assessment, information and communication, control activities and monitoring | 0 |
B.11 | SOC 1 B.11 In a type 2 report, describe the relevant changes to the system during the period | 0 |
B.12 | SOC 1 B.12 Omit and distort nothing relevant, while writing for the common needs of a broad range of user entities | 0 |
B.2 | SOC 1 B.2 Describe the procedures by which transactions are initiated, authorised, recorded, processed, corrected and reported | 0 |
B.3 | SOC 1 B.3 Describe the information and records used in performing the procedures | 0 |
B.4 | SOC 1 B.4 Describe how the system captures and addresses significant events and conditions other than transactions | 0 |
B.5 | SOC 1 B.5 Describe the process used to prepare reports and other information for user entities | 0 |
B.6 | SOC 1 B.6 Describe the subservice organisations used and whether the carve-out or the inclusive method applies | 0 |
B.7 | SOC 1 B.7 State the control objectives and the controls designed to achieve them | 0 |
B.8 | SOC 1 B.8 Identify the complementary user entity controls assumed in the design of the service organisation's controls | 0 |
B.9 | SOC 1 B.9 Identify the complementary subservice organisation controls assumed under the carve-out method | 0 |
C.1 | SOC 1 C.1 Control objectives that are reasonable in the circumstances and relevant to user entities' financial reporting | 0 |
C.2 | SOC 1 C.2 Controls suitably designed: risks identified and the controls, if operating effectively, giving reasonable assurance the objectives are achieved | 0 |
C.3 | SOC 1 C.3 Controls implemented and, in a type 2 report, operating effectively throughout the period | 0 |
C.4 | SOC 1 C.4 Deviations investigated, explained and remediated, with fraud and noncompliance assessed for their effect | 0 |
C.5 | SOC 1 C.5 Information produced by the service organisation that the auditor relies on is accurate, complete and sufficiently precise | 0 |
C.6 | SOC 1 C.6 Internal audit reports and regulatory examination reports relating to the services made available | 0 |
C.7 | SOC 1 C.7 Changes to controls during the period managed so that superseded controls can be tested and the changes described | 0 |
D.1 | SOC 1 D.1 Management's written assertion in the form Exhibit B illustrates | 0 |
D.10 | SOC 1 D.10 Use of the report by user entities and their auditors, and the user entity's own complementary controls | 0 |
D.2 | SOC 1 D.2 Written representations, including disclosure of noncompliance, fraud, design deficiencies and subsequent events; refusal is a scope limitation | 0 |
D.3 | SOC 1 D.3 Subsequent events up to the report date disclosed | 0 |
D.4 | SOC 1 D.4 Other information provided by the service organisation kept consistent with the description and clearly outside the opinion | 0 |
D.5 | SOC 1 D.5 The report package: the service auditor's report, management's assertion, the description, the objectives with the controls, tests and results, and other information | 0 |
D.6 | SOC 1 D.6 Restricted use: the report is intended solely for user entities, their auditors and the service organisation's management | 0 |
D.7 | SOC 1 D.7 Modified opinions: their grounds and what a qualified, adverse or disclaimed opinion means for the service organisation and its user entities | 0 |
D.8 | SOC 1 D.8 Communication of noncompliance, fraud or uncorrected misstatements that may affect user entities | 0 |
D.9 | SOC 1 D.9 Bridge letters between report periods | 0 |
OBJECTIVE-AREAS | The control objective areas service organisations set in practice, read from the held reports; not leaves, because each organisation sets its own | 0 |
PART-A | Engagement scope and the service organisation's responsibilities | 0 |
PART-B | The description of the system (the description criteria) | 0 |
PART-C | Control objectives and controls: design, operation, deviations and change | 0 |
PART-D | The assertion, representations, the report package and its use | 0 |
REPORT | What a SOC 1 report is: the examination under AT-C 320 and ISAE 3402, its lineage from SAS 70 and SSAE 16, and what is held | 0 |
SOC-FAMILY | SOC 1 against SOC 2 and SOC 3, type 1 against type 2, and the combined SOC 1 and ISAE 3402 report | 0 |