United States (AICPA)

SOC for Cybersecurity

22 controls. 163 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

22 controls 163 frameworks share controls with it United States (AICPA) verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

There is no implementation kit for this framework yet. The control list and the overlap above are free and complete.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
SOC-CY-A1Availability Commitments30
SOC-CY-A2Disaster Recovery43
SOC-CY-C1Confidential Information Protection0
SOC-CY-C2Encryption and Data Protection73
SOC-CY-DC1Nature of Business and Operations50
SOC-CY-DC2Nature of Sensitive Information49
SOC-CY-DC3Cybersecurity Risk Management Objectives50
SOC-CY-DC4Governance Structure50
SOC-CY-DC5Risk Assessment Process69
SOC-CY-DC6Communication and Reporting0
SOC-CY-DC7Control Environment0
SOC-CY-DC8Monitoring of Controls0
SOC-CY-DC9Third-Party Management0
SOC-CY-S1Logical and Physical Access Controls51
SOC-CY-S2System Operations61
SOC-CY-S3Change Management25
SOCCYB-1Identify Function: Asset, Risk, Governance, Business Environment0
SOCCYB-2Protect Function: Access Control, Awareness, Data Security, Processes0
SOCCYB-3Detect Function: Anomalies, Continuous Monitoring, Processes0
SOCCYB-4Respond Function: Planning, Communications, Analysis, Mitigation, Improvements0
SOCCYB-5Recover Function: Recovery Planning, Improvements, Communications0
SOCCYB-6SOC for Cybersecurity Examination Process0

Tell me when SOC for Cybersecurity files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What an auditor will ask you to produce

The artefacts named on the failure modes this framework speaks to.

  • Privacy notice and versioning
  • Choice and consent records
  • Data subject request logs
  • Personal information inventory
  • Confidential information inventory
  • Encryption configuration baselines
  • Encryption and access control records
  • Disposal certificates
  • Contractual confidentiality terms
  • Access logs for sensitive data

How programmes fail on this

Failure modes named by this framework and others. Each opens the full record.

What this page is

A control-level reference for SOC for Cybersecurity, drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition