standard
SOC 1
SOC 1 (SSAE 18 / ISAE 3402) — service-org ICFR control objectives
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- category
- soc1
- authority
- framework
Details
- authority
- framework
- version
- SSAE 18 (current AICPA SOC suite)
- publicationDate
- 2016-04 (SSAE 18)
- amendmentState
- subsequent SSAE amendments (SSAE 19-22)
- effectiveDate
- 2017-05-01 (SSAE 18)
- source_url
- Not provided
- reviewed_at
- Not provided
- note
- Illustrative control-objective taxonomy: SSAE 18 / ISAE 3402 publish no universal SOC 1 control catalog — objectives and controls are defined per service organization in each report.
- propositions
Source
No record-specific source URL is provided.
Connections
- SOC1-4 — Computer operations / job scheduling — controls provide reasonable assurance that production batch jobs and scheduled processing are appropriately defined, executed, monitored, and that exceptions/failures are identified and resolved. belongs_to SOC 1
- SOC1-7 — Data input — controls provide reasonable assurance that transactions and data input into the system are complete, accurate, and authorized. belongs_to SOC 1
- SOC1-11 — System monitoring and incident management — controls provide reasonable assurance that system performance, security events, and incidents are monitored, identified, and resolved. belongs_to SOC 1
- SOC1-1 — Logical access — controls provide reasonable assurance that logical access to applications, data, and infrastructure is restricted to authorized and appropriate users (authentication, authorization, provisioning/deprovisioning, periodic access review, privileged access). belongs_to SOC 1
- SOC1-12 — Vendor / subservice organization management — controls provide reasonable assurance that subservice organizations relevant to user entities' ICFR are appropriately managed and monitored. belongs_to SOC 1
- SOC1-5 — Backup and recovery — controls provide reasonable assurance that data is backed up, retained, and recoverable, and that restoration is tested. belongs_to SOC 1
- SOC1-9 — Data output / reporting — controls provide reasonable assurance that output and reports provided to user entities are complete, accurate, and distributed only to authorized recipients. belongs_to SOC 1
- SOC1-8 — Data processing — controls provide reasonable assurance that transactions are processed completely, accurately, and in the proper period. belongs_to SOC 1
- SOC1-10 — Physical security and environmental controls — controls provide reasonable assurance that physical access to facilities and data centers is restricted and that environmental protections safeguard systems. belongs_to SOC 1
- SOC1-6 — Data transmission / interface controls — controls provide reasonable assurance that data transmitted to and from the system and across interfaces is complete, accurate, authorized, and timely. belongs_to SOC 1
- SOC1-3 — Program development / SDLC — controls provide reasonable assurance that new systems and applications are developed, tested, approved, and implemented in accordance with management's intent. belongs_to SOC 1
- SOC1-2 — Change management — controls provide reasonable assurance that changes to applications and infrastructure are authorized, tested, approved, and migrated to production appropriately. belongs_to SOC 1