Oh no! No description found. But not to worry. Read from Tasks below how to advance this topic.
SOC 2 framework specifies how organizations should protect customer data from e.g. unauthorized access, security incidents or other vulnerabilities. It is developed by the American Institute of Certified Public Accountants (AICPA).
SOC 2 framework specifies how organizations should protect customer data from e.g. unauthorized access, security incidents or other vulnerabilities. It is developed by the American Institute of Certified Public Accountants (AICPA).
SOC 2 includes 5 different requirement sets: security, availability, processing integrity, confidentiality and privacy. A SOC 2 audit can be carried out related to one or all of these criteria. Each criteria has specific requirements that the company needs to comply with by implementing controls.
Below you'll find all of the requirements of this framework. In Cyberday, we map all requirement to global tasks, making multi-compliance management easy. Do it once, and see the progress across all frameworks!
COSO Principle 1: The entity demonstrates a commitment to integrity and ethical values.
Points of focus:
- Sets the Tone at the Top
- Establishes Standards of Conduct
- Evaluates Adherence to Standards of Conduct
- Addresses Deviations in a Timely Manner
- Considers Contractors and Vendor Employees in Demonstrating Its Commitment
















COSO Principle 2: The board of directors demonstrates independence from management and exercises oversight of the development and performance of internal control.
Points of focus:
- Establishes Oversight Responsibilities
- Applies Relevant Expertise
- Operates Independently
- Supplements Board Expertise




COSO Principle 3: Management establishes, with board oversight, structures, reporting lines, and appropriate authorities and responsibilities in the pursuit of objectives.
Points of focus:
- Considers All Structures of the Entity
- Establishes Reporting Lines
- Defines, Assigns, and Limits Authorities and Responsibilities
- Addresses Specific Requirements When Defining Authorities and Responsibilities
- Considers Interactions With External Parties When Establishing Structures, Reporting Lines, Authorities, and Responsibilities












COSO Principle 4: The entity demonstrates a commitment to attract, develop, and retain competent individuals in alignment with objectives.
Points of focus:
- Establishes Policies and Practices
- Evaluates Competence and Addresses Shortcomings
- Attracts, Develops, and Retains Individuals
- Plans and Prepares for Succession
- Considers the Background of Individuals
- Considers the Technical Competency of Individuals
- Provides Training to Maintain Technical Competencies




















COSO Principle 5: The entity holds individuals accountable for their internal control responsibilities in the pursuit of objectives.
Points of focus:
- Enforces Accountability Through Structures, Authorities, and Responsibilities
- Establishes Performance Measures, Incentives, and Rewards
- Evaluates Performance Measures, Incentives, and Rewards for Ongoing Relevance
- Considers Excessive Pressures
- Evaluates Performance and Rewards or Disciplines Individuals
















COSO Principle 13: The entity obtains or generates and uses relevant, quality information to support the functioning of internal control.
Points of focus:
- Identifies Information Requirements
- Captures Internal and External Sources of Data
- Processes Relevant Data Into Information
- Maintains Quality Throughout Processing
















COSO Principle 14: The entity internally communicates information, including objectives and responsibilities for internal control, necessary to support the functioning of internal control.
Points of focus:
- Communicates Internal Control Information
- Communicates With the Board of Directors
- Provides Separate Communication Lines
- Selects Relevant Method of Communication
- Communicates Responsibilities
- Communicates Information on Reporting Failures, Incidents, Concerns, and Other Matters
- Communicates Objectives and Changes to Objectives
- Communicates Information to Improve Security Knowledge and Awareness
- Communicates Information About System Operation and Boundaries
- Communicates System Objectives
- Communicates System Changes
































COSO Principle 15: The entity communicates with external parties regarding matters affecting the functioning of internal control.
Points of focus:
- Communicates to External Parties
- Enables Inbound Communications
- Communicates With the Board of Directors
- Provides Separate Communication Lines
- Selects Relevant Method of Communication
- Communicates Objectives Related to Confidentiality and Changes to Objectives
- Communicates Objectives Related to Privacy and Changes to Objectives
- Communicates Information About System Operation and Boundaries
- Communicates System Objectives
- Communicates System Responsibilities
- Communicates Information on Reporting System Failures, Incidents, Concerns, and Other Matters




























COSO Principle 6: The entity specifies objectives with sufficient clarity to enable the identification and assessment of risks relating to objectives.
Points of focus:
Operations Objectives:
- Reflects Management's Choices
- Considers Tolerances for Risk
- Includes Operations and Financial Performance Goals
- Forms a Basis for Committing of Resources
External Financial Reporting Objectives:
- Complies With Applicable Accounting Standards
- Considers Materiality
- Reflects Entity Activities
External Nonfinancial Reporting Objectives:
- Complies With Externally Established Frameworks
- Considers the Required Level of Precision
- Reflects Entity Activities
Internal Reporting Objectives:
- Reflects Management's Choices
- Considers the Required Level of Precision
- Reflects Entity Activities
Compliance Objectives:
- Reflects External Laws and Regulations
- Considers Tolerances for Risk
- Establishes Sub- objectives to Support Objectives




















COSO Principle 7: The entity identifies risks to the achievement of its objectives across the entity and analyzes risks as a basis for determining how the risks should be managed.
Points of focus:
- Includes Entity, Subsidiary, Division, Operating Unit, and Functional Levels
- Analyzes Internal and External Factors
- Involves Appropriate Levels of Management
- Estimates Significance of Risks Identified
- Determines How to Respond to Risks
- Identifies and Assesses Criticality of Information Assets and Identifies Threats and Vulnerabilities
- Analyzes Threats and Vulnerabilities From Vendors, Business Partners, and Other Parties
- Considers the Significance of the Risk
























COSO Principle 8: The entity considers the potential for fraud in assessing risks to the achievement of objectives.
Points of focus:
- Considers Various Types of Fraud
- Assesses Incentives and Pressures
- Assesses Opportunities
- Assesses Attitudes and Rationalizations
- Considers the Risks Related to the Use of IT and Access to Information




COSO Principle 9: The entity identifies and assesses changes that could significantly impact the system of internal control.
Points of focus:
- Assesses Changes in the External Environment
- Assesses Changes in the Business Model
- Assesses Changes in Leadership
- Assess Changes in Systems and Technology
- Assess Changes in Vendor and Business Partner Relationships
























COSO Principle 16: The entity selects, develops, and performs ongoing and/or separate evaluations to ascertain whether the components of internal control are present and functioning.
Points of focus:
- Considers a Mix of Ongoing and Separate Evaluations
- Considers Rate of Change
- Establishes Baseline Understanding
- Uses Knowledgeable Personnel
- Integrates With Business Processes
- Adjusts Scope and Frequency
- Objectively Evaluates
- Considers Different Types of Ongoing and Separate Evaluations




























COSO Principle 17: The entity evaluates and communicates internal control deficiencies in a timely manner to those parties responsible for taking corrective action, including senior management and the board of directors, as appropriate.
Points of focus:
- Assesses Results
- Communicates Deficiencies
- Monitors Corrective Action












COSO Principle 10: The entity selects and develops control activities that contribute to the mitigation of risks to the achievement of objectives to acceptable levels.
Points of focus:
- Integrates With Risk Assessment
- Considers Entity- Specific Factors
- Determines Relevant Business Processes
- Evaluates a Mix of Control Activity Types
- Considers at What Level Activities Are Applied
- Addresses Segregation of Duties
















Explore our comprehensive resources and improve your security with the themes of this framework.
Discover specific ways our platform streamlines your ISO 27001 compliance process, from automated controls to audit preparation.
Explore use caseTake our comprehensive assessment to identify gaps in your current implementation and get personalized recommendations.
Start assessmentDive deeper with our articles, case studies, and expert insights on framework implementation.
Read articleGet a concise overview of all requirements, controls, and implementation steps in our quick guide.
Get the guideSee how the overlap and differences with any other framework to optimize your compliance strategy.
Compare frameworkParticipate in expert-led sessions covering implementation strategies, common pitfalls, and best practices for compliance.
Register for webinarParticipate in expert-led sessions covering implementation strategies, common pitfalls, and best practices for compliance.
Register for webinarUnderstand the basics of cyber security frameworks with our comprehensive guide.
Read the articleWhen building an ISMS, it's important to understand the different levels of information hierarchy. Here's how Cyberday is structured.
Sets the overall compliance standard or regulation your organization needs to follow.
Break down the framework into specific obligations that must be met.
Concrete actions and activities your team carries out to satisfy each requirement.
Documented rules and practices that are created and maintained as a result of completing tasks.
