Clause text
SOC 2 (Trust Services Criteria): the clauses the register cites
The 12 SOC 2 (Trust Services Criteria) clauses that questions are placed on, each with the evidence an assessor asks for and where answers usually fall short.
The criteria text is not held in full here, so it is not quoted: each criterion is named by its code and title, with the evidence an assessor usually asks for.
SOC 2 A1.2 Environmental protections, data backups, and recovery infrastructure support availability
Named, not quoted: the criteria text is not held in full here.
Evidence an assessor expects: Evidence of environmental protections at the facilities in scope, covering fire detection and suppression, power continuity, cooling and water detection, with testing and maintenance records; The backup configuration showing scope, frequency and retention against the recovery point objective; Evidence of protection of backup data, including encryption, access restriction and an immutable or offline copy; Evidence of the recovery infrastructure, including alternative processing capability and its readiness; Evidence these are authorised, approved, maintained and monitored, including who approved the designWhere answers usually fall short: Backups configured with failures reported and never investigated, so gaps in the backup set are unknown; Backups reachable using production credentials, so a single compromise destroys bothSource: SOC 2 (Trust Services Criteria) SOC 2 A1.3 Recovery plan procedures support system recovery from failures
Named, not quoted: the criteria text is not held in full here.
Evidence an assessor expects: The recovery test plan for the period, showing scope, scenario, participants and the objectives being tested; Test results recording what was recovered, the time taken and whether the recovery objectives were met; Evidence of actual restoration of data from backup, verified for completeness and integrity, not only that a job reported success; Records of issues identified during testing and evidence of their remediation; Evidence of the frequency of testing and that it covers the systems within the availability commitmentWhere answers usually fall short: Testing limited to a walkthrough or a single file restore, which does not test the recovery plan procedures the criterion names; Restore performed with no verification the recovered data was complete and usableSource: SOC 2 (Trust Services Criteria) SOC 2 CC3.2 COSO principle 7: Identifies risks and analyzes to determine how managed
Named, not quoted: the criteria text is not held in full here.
Evidence an assessor expects: The risk assessment covering the entity, its subsidiaries, divisions and operating units, and relevant external factors; The risk register with likelihood, impact, analysis and the determined response for each risk; Evidence of the involvement of appropriate levels of management in the assessment; Evidence of the frequency of assessment and of reassessment when conditions changed; Evidence risk responses were implemented, with owners and completion statusWhere answers usually fall short: Risk register produced annually as a compliance artefact with no evidence it drove any decision; Analysis reduced to a colour rating with no reasoning recorded behind likelihood or impactSource: SOC 2 (Trust Services Criteria) SOC 2 CC4.1 COSO principle 16: Selects and develops ongoing and separate evaluations
Named, not quoted: the criteria text is not held in full here.
Evidence an assessor expects: The plan for ongoing and separate evaluations, showing scope, type, frequency and who performs them; Results of evaluations performed in the period, such as internal audit reports, control self assessments, vulnerability assessments and penetration tests; Evidence evaluators are objective and knowledgeable, and independent of the activity evaluated; Evidence a baseline understanding of the control system exists and is used to scope evaluations; Evidence of the mix and rate of change, showing evaluations are adjusted as risk changesWhere answers usually fall short: Only one annual assessment performed, with no ongoing evaluation between times; Evaluations performed by the people who operate the controls, so objectivity failsSource: SOC 2 (Trust Services Criteria) SOC 2 CC5.3 COSO principle 12: Deploys control activities through policies and procedures
Named, not quoted: the criteria text is not held in full here.
Evidence an assessor expects: Policies establishing what is expected and the procedures putting them into action, with owners and approval evidence; Evidence responsibility and accountability for executing each procedure is established with competent personnel; Evidence procedures are performed timely, with records showing when each was performed during the period; Evidence corrective action is taken where a procedure identifies an issue; Evidence policies and procedures are reassessed periodically and updated as neededWhere answers usually fall short: Policy exists with no corresponding procedure, so nothing tells anyone how to perform the control; Procedures performed irregularly with records showing large gaps in the periodSource: SOC 2 (Trust Services Criteria) SOC 2 CC6.1 Implements logical access security software, infrastructure and architectures over protected information assets
Named, not quoted: the criteria text is not held in full here.
Evidence an assessor expects: Inventory of information assets with classification and owner; Access control software configuration and the rule sets that enforce it; Joiner, mover and leaver records showing credential issue and removal for people, infrastructure and software; Network segmentation design with firewall or ACL rule review evidence; Register of points of access used by outside entities and the data that flows through eachWhere answers usually fall short: Physical access evidence offered against a criterion that is logical only, which belongs at CC6.4; Asset inventory incomplete, so unmanaged systems sit outside the access control rule setsSource: SOC 2 (Trust Services Criteria) SOC 2 CC6.2 Prior to granting access, registration and authorization processes are established
Named, not quoted: the criteria text is not held in full here.
Evidence an assessor expects: The registration and authorisation procedure that must complete before credentials are issued, for internal and external users; Authorisation records for users provisioned in the period, showing the requester, the approver and the access requested; Evidence credentials were issued only after authorisation, with dates supporting the sequence; Evidence of removal of access when access is no longer authorised, with the interval between the trigger and the removal; Evidence covering users whose access is administered by the entity on behalf of a customer, where that appliesWhere answers usually fall short: Access granted first and approved retrospectively, which reverses the order the criterion requires; Approval by the requester's peer or by the person implementing the change, so no independent authorisation existsSource: SOC 2 (Trust Services Criteria) SOC 2 CC7.1 Detection and monitoring procedures for security events are in place
Named, not quoted: the criteria text is not held in full here.
Evidence an assessor expects: Defined configuration standards or baselines and evidence of monitoring for changes that introduce new vulnerabilities; Vulnerability scanning results for the period, including scope, frequency and whether scanning is authenticated; Evidence of monitoring for newly discovered vulnerabilities affecting the technologies in use; Records of deviations detected, the assessment of them and the remediation taken; Evidence the monitoring covers infrastructure, applications and cloud configurationWhere answers usually fall short: Configuration monitored at build only, so drift introduced afterwards is never detected; Scanning performed quarterly against an environment that changes dailySource: SOC 2 (Trust Services Criteria) SOC 2 CC7.2 Monitors system components for anomalies indicating malicious acts
Named, not quoted: the criteria text is not held in full here.
Evidence an assessor expects: The monitoring design for system components and their operation, showing what constitutes anomalous behaviour; Detection rules or analytics deployed, and evidence of the tuning applied over time; Evidence of the sources monitored, covering infrastructure, applications, identity and, where applicable, physical and environmental conditions; Records of anomalies detected during the period and of the analysis performed to determine whether they represent a security event; Evidence of the coverage of the monitoring against the components in the system descriptionWhere answers usually fall short: Logs collected without any detection logic applied, so anomalies are only visible in hindsight; Monitoring covers malicious acts and omits natural disaster and error, both of which the criterion namesSource: SOC 2 (Trust Services Criteria) SOC 2 CC7.4 Responds to identified security incidents through defined procedures
Named, not quoted: the criteria text is not held in full here.
Evidence an assessor expects: Incident response program naming roles, escalation paths and the use of external resources; Incident tickets carrying detection, containment, eradication and recovery timestamps; Severity assessment and containment strategy record for individual incidents; Remediation records tying each incident to closure of the underlying vulnerability; Records of communication to affected parties and, where privacy is in scope, to data subjects and regulatorsWhere answers usually fall short: A response plan exists but no incident record shows it was followed; Containment recorded while the vulnerability that allowed the incident stays openSource: SOC 2 (Trust Services Criteria) SOC 2 CC8.1 Change management processes are in place
Named, not quoted: the criteria text is not held in full here.
Evidence an assessor expects: The change management process covering infrastructure, data, software and procedures, including the emergency change route; Change records for the period showing design, development or acquisition, configuration, documentation, testing, approval and implementation; Evidence of segregation between those who develop, approve and implement changes; Testing evidence per change proportionate to its risk, including security testing where relevant; Evidence of rollback capability and of post implementation verificationWhere answers usually fall short: Emergency changes used routinely, with retrospective approval that is never withheld; Approval and implementation performed by the same person, so the approval is not independentSource: SOC 2 (Trust Services Criteria) SOC 2 CC9.2 Risk mitigation activities include assessment of vendor and business partner controls
Named, not quoted: the criteria text is not held in full here.
Evidence an assessor expects: The vendor and business partner inventory, with risk tiering based on data access and criticality; Due diligence records performed before engagement, at the depth the tier requires; Contractual commitments covering confidentiality, security requirements, incident notification and the right to assess; Evidence of ongoing monitoring, such as review of assurance reports with complementary user entity control consideration, and follow up on exceptions noted in them; Evidence of termination handling, including return or deletion of data and revocation of accessWhere answers usually fall short: Assurance reports collected and filed with no review of the exceptions or of the complementary user entity controls they assume the entity performs; Inventory covering vendors known to procurement, missing services engaged directly by teamsSource: SOC 2 (Trust Services Criteria)