SOC2-A1.1 | Maintains capacity to meet availability commitments | 51 |
SOC2-A1.2 | Environmental protections, data backups, and recovery infrastructure support availability | 81 |
SOC2-A1.3 | Recovery plan procedures support system recovery from failures | 80 |
SOC2-C1.1 | Confidential information is identified and protected during receipt, processing, storage | 37 |
SOC2-C1.2 | Confidential information is disposed of securely | 28 |
SOC2-CC1.1 | COSO principle 1: Demonstrates commitment to integrity and ethical values | 24 |
SOC2-CC1.2 | COSO principle 2: Board exercises oversight responsibility | 23 |
SOC2-CC1.3 | COSO principle 3: Management establishes structures, reporting lines, and authorities | 34 |
SOC2-CC1.4 | COSO principle 4: Demonstrates commitment to attract and retain competent individuals | 38 |
SOC2-CC1.5 | COSO principle 5: Holds individuals accountable for internal control responsibilities | 32 |
SOC2-CC2.1 | COSO principle 13: Obtains and generates relevant, quality information | 29 |
SOC2-CC2.2 | COSO principle 14: Internally communicates information including objectives and responsibilities | 33 |
SOC2-CC2.3 | COSO principle 15: Communicates with external parties regarding matters affecting controls | 33 |
SOC2-CC3.1 | COSO principle 6: Specifies objectives to identify and assess risks | 29 |
SOC2-CC3.2 | COSO principle 7: Identifies risks and analyzes to determine how managed | 40 |
SOC2-CC3.3 | COSO principle 8: Considers potential for fraud | 17 |
SOC2-CC3.4 | COSO principle 9: Identifies and assesses changes that could impact internal controls | 33 |
SOC2-CC4.1 | COSO principle 16: Selects and develops ongoing and separate evaluations | 40 |
SOC2-CC4.2 | COSO principle 17: Evaluates and communicates deficiencies in a timely manner | 128 |
SOC2-CC5.1 | COSO principle 10: Selects and develops control activities to mitigate risks | 31 |
SOC2-CC5.2 | COSO principle 11: Selects and develops general controls over technology | 34 |
SOC2-CC5.3 | COSO principle 12: Deploys control activities through policies and procedures | 32 |
SOC2-CC6.1 | Implements logical access security software, infrastructure and architectures over protected information assets | 51 |
SOC2-CC6.2 | Prior to granting access, registration and authorization processes are established | 61 |
SOC2-CC6.3 | Role-based access and least privilege are enforced | 93 |
SOC2-CC6.4 | Restricts physical access to facilities and protected information assets (for example, data center facilities, back-up media storage, and other sensitive locations) to authorized p | 28 |
SOC2-CC6.5 | Discontinues logical and physical protections over physical assets only after the ability to read or recover data and software from those assets has been diminished and is no longe | 26 |
SOC2-CC6.6 | Measures against threats outside system boundaries are implemented | 33 |
SOC2-CC6.7 | Transmission of data is restricted to authorized users | 33 |
SOC2-CC6.8 | Controls to prevent or detect unauthorized or malicious software | 36 |
SOC2-CC7.1 | Detection and monitoring procedures for security events are in place | 38 |
SOC2-CC7.2 | Monitors system components for anomalies indicating malicious acts | 37 |
SOC2-CC7.3 | Evaluates security events to determine incident status | 34 |
SOC2-CC7.4 | Responds to identified security incidents through defined procedures | 155 |
SOC2-CC7.5 | Identifies the root cause of security incidents | 91 |
SOC2-CC8.1 | Change management processes are in place | 58 |
SOC2-CC9.1 | Identifies, selects and develops risk mitigation activities | 36 |
SOC2-CC9.2 | Risk mitigation activities include assessment of vendor and business partner controls | 38 |
SOC2-P1.1 | Privacy notice provides clear notice about privacy practices | 16 |
SOC2-P2.1 | Consent is obtained for the collection, use, and disclosure of personal information | 13 |
SOC2-P3.1 | Personal information is collected consistent with privacy commitments | 68 |
SOC2-P3.2 | Explicit consent is obtained for sensitive personal information | 13 |
SOC2-P4.1 | Personal information is used for purposes identified in privacy commitments | 17 |
SOC2-P4.2 | Personal information is retained for only as long as needed | 23 |
SOC2-P4.3 | Personal information is securely disposed of | 76 |
SOC2-P5.1 | Personal information is accessed only by authorized personnel | 24 |
SOC2-P5.2 | Corrections to personal information are processed timely | 12 |
SOC2-P6.1 | Personal information is disclosed to third parties only as committed | 60 |
SOC2-P6.2 | Records of personal information disclosures are maintained | 24 |
SOC2-P6.3 | Creates and retains a complete, accurate, and timely record of detected or reported unauthorized disclosures (including breaches) of personal information to meet the entity's objec | 26 |
SOC2-P6.4 | Obtains privacy commitments from vendors and other third parties who have access to personal information to meet the entity's objectives related to privacy. The entity assesses tho | 27 |
SOC2-P6.5 | Obtains commitments from vendors and other third parties with access to personal information to notify the entity in the event of actual or suspected unauthorized disclosures of pe | 24 |
SOC2-P6.6 | Provides notification of breaches and incidents to affected data subjects, regulators, and others to meet the entity's objectives related to privacy | 29 |
SOC2-P6.7 | Provides data subjects with an accounting of the personal information held and disclosure of the data subjects' personal information, upon the data subjects' request, to meet the e | 11 |
SOC2-P7.1 | Personal information collected is limited to what is necessary and relevant | 15 |
SOC2-P8.1 | Inquiries, complaints, and disputes regarding personal information are addressed | 14 |
SOC2-PI1.1 | Obtains or generates and uses relevant quality information to support processing integrity | 18 |
SOC2-PI1.2 | System inputs are complete, accurate, and processed in a timely manner | 14 |
SOC2-PI1.3 | System processing is complete, valid, accurate, timely, and authorized | 16 |
SOC2-PI1.4 | System outputs are complete, valid, accurate, timely, and distributed | 13 |
SOC2-PI1.5 | Inputs are processed completely, accurately, and timely for stored data | 17 |