Security Questionnaire Mapper
Clause text

SOC 2 (Trust Services Criteria): the clauses the register cites

The 12 SOC 2 (Trust Services Criteria) clauses that questions are placed on, each with the evidence an assessor asks for and where answers usually fall short.

The criteria text is not held in full here, so it is not quoted: each criterion is named by its code and title, with the evidence an assessor usually asks for.

12 clauses

the families they anchor
SOC 2 A1.2 Environmental protections, data backups, and recovery infrastructure support availability

Named, not quoted: the criteria text is not held in full here.

Evidence an assessor expects: Evidence of environmental protections at the facilities in scope, covering fire detection and suppression, power continuity, cooling and water detection, with testing and maintenance records; The backup configuration showing scope, frequency and retention against the recovery point objective; Evidence of protection of backup data, including encryption, access restriction and an immutable or offline copy; Evidence of the recovery infrastructure, including alternative processing capability and its readiness; Evidence these are authorised, approved, maintained and monitored, including who approved the design
Where answers usually fall short: Backups configured with failures reported and never investigated, so gaps in the backup set are unknown; Backups reachable using production credentials, so a single compromise destroys both
Source: SOC 2 (Trust Services Criteria)
SOC 2 A1.3 Recovery plan procedures support system recovery from failures

Named, not quoted: the criteria text is not held in full here.

Evidence an assessor expects: The recovery test plan for the period, showing scope, scenario, participants and the objectives being tested; Test results recording what was recovered, the time taken and whether the recovery objectives were met; Evidence of actual restoration of data from backup, verified for completeness and integrity, not only that a job reported success; Records of issues identified during testing and evidence of their remediation; Evidence of the frequency of testing and that it covers the systems within the availability commitment
Where answers usually fall short: Testing limited to a walkthrough or a single file restore, which does not test the recovery plan procedures the criterion names; Restore performed with no verification the recovered data was complete and usable
Source: SOC 2 (Trust Services Criteria)
SOC 2 CC3.2 COSO principle 7: Identifies risks and analyzes to determine how managed

Named, not quoted: the criteria text is not held in full here.

Evidence an assessor expects: The risk assessment covering the entity, its subsidiaries, divisions and operating units, and relevant external factors; The risk register with likelihood, impact, analysis and the determined response for each risk; Evidence of the involvement of appropriate levels of management in the assessment; Evidence of the frequency of assessment and of reassessment when conditions changed; Evidence risk responses were implemented, with owners and completion status
Where answers usually fall short: Risk register produced annually as a compliance artefact with no evidence it drove any decision; Analysis reduced to a colour rating with no reasoning recorded behind likelihood or impact
Source: SOC 2 (Trust Services Criteria)
SOC 2 CC4.1 COSO principle 16: Selects and develops ongoing and separate evaluations

Named, not quoted: the criteria text is not held in full here.

Evidence an assessor expects: The plan for ongoing and separate evaluations, showing scope, type, frequency and who performs them; Results of evaluations performed in the period, such as internal audit reports, control self assessments, vulnerability assessments and penetration tests; Evidence evaluators are objective and knowledgeable, and independent of the activity evaluated; Evidence a baseline understanding of the control system exists and is used to scope evaluations; Evidence of the mix and rate of change, showing evaluations are adjusted as risk changes
Where answers usually fall short: Only one annual assessment performed, with no ongoing evaluation between times; Evaluations performed by the people who operate the controls, so objectivity fails
Source: SOC 2 (Trust Services Criteria)
SOC 2 CC5.3 COSO principle 12: Deploys control activities through policies and procedures

Named, not quoted: the criteria text is not held in full here.

Evidence an assessor expects: Policies establishing what is expected and the procedures putting them into action, with owners and approval evidence; Evidence responsibility and accountability for executing each procedure is established with competent personnel; Evidence procedures are performed timely, with records showing when each was performed during the period; Evidence corrective action is taken where a procedure identifies an issue; Evidence policies and procedures are reassessed periodically and updated as needed
Where answers usually fall short: Policy exists with no corresponding procedure, so nothing tells anyone how to perform the control; Procedures performed irregularly with records showing large gaps in the period
Source: SOC 2 (Trust Services Criteria)
SOC 2 CC6.1 Implements logical access security software, infrastructure and architectures over protected information assets

Named, not quoted: the criteria text is not held in full here.

Evidence an assessor expects: Inventory of information assets with classification and owner; Access control software configuration and the rule sets that enforce it; Joiner, mover and leaver records showing credential issue and removal for people, infrastructure and software; Network segmentation design with firewall or ACL rule review evidence; Register of points of access used by outside entities and the data that flows through each
Where answers usually fall short: Physical access evidence offered against a criterion that is logical only, which belongs at CC6.4; Asset inventory incomplete, so unmanaged systems sit outside the access control rule sets
Source: SOC 2 (Trust Services Criteria)
SOC 2 CC6.2 Prior to granting access, registration and authorization processes are established

Named, not quoted: the criteria text is not held in full here.

Evidence an assessor expects: The registration and authorisation procedure that must complete before credentials are issued, for internal and external users; Authorisation records for users provisioned in the period, showing the requester, the approver and the access requested; Evidence credentials were issued only after authorisation, with dates supporting the sequence; Evidence of removal of access when access is no longer authorised, with the interval between the trigger and the removal; Evidence covering users whose access is administered by the entity on behalf of a customer, where that applies
Where answers usually fall short: Access granted first and approved retrospectively, which reverses the order the criterion requires; Approval by the requester's peer or by the person implementing the change, so no independent authorisation exists
Source: SOC 2 (Trust Services Criteria)
SOC 2 CC7.1 Detection and monitoring procedures for security events are in place

Named, not quoted: the criteria text is not held in full here.

Evidence an assessor expects: Defined configuration standards or baselines and evidence of monitoring for changes that introduce new vulnerabilities; Vulnerability scanning results for the period, including scope, frequency and whether scanning is authenticated; Evidence of monitoring for newly discovered vulnerabilities affecting the technologies in use; Records of deviations detected, the assessment of them and the remediation taken; Evidence the monitoring covers infrastructure, applications and cloud configuration
Where answers usually fall short: Configuration monitored at build only, so drift introduced afterwards is never detected; Scanning performed quarterly against an environment that changes daily
Source: SOC 2 (Trust Services Criteria)
SOC 2 CC7.2 Monitors system components for anomalies indicating malicious acts

Named, not quoted: the criteria text is not held in full here.

Evidence an assessor expects: The monitoring design for system components and their operation, showing what constitutes anomalous behaviour; Detection rules or analytics deployed, and evidence of the tuning applied over time; Evidence of the sources monitored, covering infrastructure, applications, identity and, where applicable, physical and environmental conditions; Records of anomalies detected during the period and of the analysis performed to determine whether they represent a security event; Evidence of the coverage of the monitoring against the components in the system description
Where answers usually fall short: Logs collected without any detection logic applied, so anomalies are only visible in hindsight; Monitoring covers malicious acts and omits natural disaster and error, both of which the criterion names
Source: SOC 2 (Trust Services Criteria)
SOC 2 CC7.4 Responds to identified security incidents through defined procedures

Named, not quoted: the criteria text is not held in full here.

Evidence an assessor expects: Incident response program naming roles, escalation paths and the use of external resources; Incident tickets carrying detection, containment, eradication and recovery timestamps; Severity assessment and containment strategy record for individual incidents; Remediation records tying each incident to closure of the underlying vulnerability; Records of communication to affected parties and, where privacy is in scope, to data subjects and regulators
Where answers usually fall short: A response plan exists but no incident record shows it was followed; Containment recorded while the vulnerability that allowed the incident stays open
Source: SOC 2 (Trust Services Criteria)
SOC 2 CC8.1 Change management processes are in place

Named, not quoted: the criteria text is not held in full here.

Evidence an assessor expects: The change management process covering infrastructure, data, software and procedures, including the emergency change route; Change records for the period showing design, development or acquisition, configuration, documentation, testing, approval and implementation; Evidence of segregation between those who develop, approve and implement changes; Testing evidence per change proportionate to its risk, including security testing where relevant; Evidence of rollback capability and of post implementation verification
Where answers usually fall short: Emergency changes used routinely, with retrospective approval that is never withheld; Approval and implementation performed by the same person, so the approval is not independent
Source: SOC 2 (Trust Services Criteria)
SOC 2 CC9.2 Risk mitigation activities include assessment of vendor and business partner controls

Named, not quoted: the criteria text is not held in full here.

Evidence an assessor expects: The vendor and business partner inventory, with risk tiering based on data access and criticality; Due diligence records performed before engagement, at the depth the tier requires; Contractual commitments covering confidentiality, security requirements, incident notification and the right to assess; Evidence of ongoing monitoring, such as review of assurance reports with complementary user entity control consideration, and follow up on exceptions noted in them; Evidence of termination handling, including return or deletion of data and revocation of access
Where answers usually fall short: Assurance reports collected and filed with no review of the exceptions or of the complementary user entity controls they assume the entity performs; Inventory covering vendors known to procurement, missing services engaged directly by teams
Source: SOC 2 (Trust Services Criteria)