Framework

SOC 1

SOC 1 (SSAE 18 / ISAE 3402) — service-org ICFR control objectives

12 requirements · 7 connected unified controls

Open SOC 1 in the map
Version
SSAE 18 (current AICPA SOC suite)
Published
2016-04 (SSAE 18)
Effective
2017-05-01 (SSAE 18)
Amendments
subsequent SSAE amendments (SSAE 19-22)

Illustrative control-objective taxonomy: SSAE 18 / ISAE 3402 publish no universal SOC 1 control catalog — objectives and controls are defined per service organization in each report.

Requirements and control mappings

“Full” and “Partial” describe the catalog mapping to a unified control. A partial mapping includes the remaining requirement. These mappings do not establish an organization’s implementation or certification.

Typical control objective domains

RequirementUnified control and mapping
SOC1-1Logical access — controls provide reasonable assurance that logical access to applications, data, and infrastructure is restricted to authorized and appropriate users (authentication, authorization, provisioning/deprovisioning, periodic access review, privileged access).
UC-ACCESS-01 — Provision and deprovision accounts through a managed lifecyclePartial

Remaining requirement: authentication, periodic review, and privileged access satisfied by companion unified controls

SOC1-2Change management — controls provide reasonable assurance that changes to applications and infrastructure are authorized, tested, approved, and migrated to production appropriately.
SOC1-3Program development / SDLC — controls provide reasonable assurance that new systems and applications are developed, tested, approved, and implemented in accordance with management's intent.
SOC1-4Computer operations / job scheduling — controls provide reasonable assurance that production batch jobs and scheduled processing are appropriately defined, executed, monitored, and that exceptions/failures are identified and resolved.
SOC1-5Backup and recovery — controls provide reasonable assurance that data is backed up, retained, and recoverable, and that restoration is tested.
SOC1-6Data transmission / interface controls — controls provide reasonable assurance that data transmitted to and from the system and across interfaces is complete, accurate, authorized, and timely.
SOC1-7Data input — controls provide reasonable assurance that transactions and data input into the system are complete, accurate, and authorized.
SOC1-8Data processing — controls provide reasonable assurance that transactions are processed completely, accurately, and in the proper period.
SOC1-9Data output / reporting — controls provide reasonable assurance that output and reports provided to user entities are complete, accurate, and distributed only to authorized recipients.
SOC1-10Physical security and environmental controls — controls provide reasonable assurance that physical access to facilities and data centers is restricted and that environmental protections safeguard systems.
SOC1-11System monitoring and incident management — controls provide reasonable assurance that system performance, security events, and incidents are monitored, identified, and resolved.
SOC1-12Vendor / subservice organization management — controls provide reasonable assurance that subservice organizations relevant to user entities' ICFR are appropriately managed and monitored.