Framework
SOC 2 (TSC)
AICPA SOC 2 Trust Services Criteria (2017, rev. 2022)
61 requirements · 51 connected unified controls
Open SOC 2 (TSC) in the mapRequirements and control mappings
“Full” and “Partial” describe the catalog mapping to a unified control. A partial mapping includes the remaining requirement. These mappings do not establish an organization’s implementation or certification.
Common Criteria (Security)
Availability
| Requirement | Unified control and mapping |
|---|---|
| A1.1The entity maintains, monitors, and evaluates current processing capacity and use of system components (infrastructure, data, and software) to manage capacity demand and to enable the implementation of additional capacity to help meet its objectives. | |
| A1.2The entity authorizes, designs, develops or acquires, implements, operates, approves, maintains, and monitors environmental protections, software, data back-up processes, and recovery infrastructure to meet its objectives. | UC-BCDR-03 — Back up data and verify restorabilityPartial Remaining requirement: environmental protections and recovery-infrastructure operation satisfied by companion controls |
| A1.3The entity tests recovery plan procedures supporting system recovery to meet its objectives. |
Confidentiality
| Requirement | Unified control and mapping |
|---|---|
| C1.1The entity identifies and maintains confidential information to meet the entity's objectives related to confidentiality. | UC-ASSET-03 — Classify, prioritize, and label information and assetsPartial Remaining requirement: also requires retaining and protecting confidential information per commitments |
| C1.2The entity disposes of confidential information to meet the entity's objectives related to confidentiality. |