Framework
Full specification

SOC 2

Oh no! No description found. But not to worry. Read from Tasks below how to advance this topic.

SOC 2 framework specifies how organizations should protect customer data from e.g. unauthorized access, security incidents or other vulnerabilities. It is developed by the American Institute of Certified Public Accountants (AICPA).

SOC 2 framework specifies how organizations should protect customer data from e.g. unauthorized access, security incidents or other vulnerabilities. It is developed by the American Institute of Certified Public Accountants (AICPA).

SOC 2 includes 5 different requirement sets: security, availability, processing integrity, confidentiality and privacy. A SOC 2 audit can be carried out related to one or all of these criteria. Each criteria has specific requirements that the company needs to comply with by implementing controls.

Tasks
76
Scope
USA
Here's what
SOC 2
requires and how to comply.

Below you'll find all of the requirements of this framework. In Cyberday, we map all requirement to global tasks, making multi-compliance management easy. Do it once, and see the progress across all frameworks!

Requirements
P3.2: Additional measures when processing requires explicit consent
P4.1: Limiting use of personal information to purposes according to objectives related to privacy
P4.2: Retention of personal information according to objectives related to privacy
P4.3: Secure disposal of personal information
P5.1: Granting access to stored personal data
P5.2: Correction of personal information
P6.1: Disclosure of personal information to third parties with consent of the data subjects
P6.2: Record of authorized disclosures of personal information
P6.3: Record of unauthorized disclosures of personal information
P6.4: Obtaining privacy commitments from third parties and assesment of compliance
P6.5: Notification of unauthorized disclosure of personal information from third parties
P6.6: Notification about breaches and incidents to affected data subjects
P6.7: Providing an accounting of personal information upon data subjects' request
P7.1: Collection and maintainment of accurate and relevant personal information
P8.1: Periodic monitoring of privacy compliance
CC6.1a: Identification and listing of assets
SOC 2
learning hub

Explore our comprehensive resources and improve your security with the themes of this framework.

How Cyberday helps with
SOC 2

Discover specific ways our platform streamlines your ISO 27001 compliance process, from automated controls to audit preparation.

Explore use case
Free
SOC 2
assessment

Take our comprehensive assessment to identify gaps in your current implementation and get personalized recommendations.

Start assessment
Read more about
SOC 2

Dive deeper with our articles, case studies, and expert insights on framework implementation.

Read article
Guide to compliance

Get a concise overview of all requirements, controls, and implementation steps in our quick guide.

Get the guide
Framework comparison

See how the overlap and differences with any other framework to optimize your compliance strategy.

Compare framework
Join a live
SOC 2
webinar

Participate in expert-led sessions covering implementation strategies, common pitfalls, and best practices for compliance.

Register for webinar
Join our live webinars

Participate in expert-led sessions covering implementation strategies, common pitfalls, and best practices for compliance.

Register for webinar
What are frameworks?

Understand the basics of cyber security frameworks with our comprehensive guide.

Read the article

The ISMS component hierachy

When building an ISMS, it's important to understand the different levels of information hierarchy. Here's how Cyberday is structured.

Framework

Sets the overall compliance standard or regulation your organization needs to follow.

Requirements

Break down the framework into specific obligations that must be met.

Tasks

Concrete actions and activities your team carries out to satisfy each requirement.

Policies

Documented rules and practices that are created and maintained as a result of completing tasks.

Never duplicate effort. Do it once - improve compliance across frameworks.

Reach multi-framework compliance in the simplest possible way
Security frameworks tend to share the same core requirements - like risk management, backup, malware, personnel awareness or access management.
Cyberday maps all frameworks’ requirements into shared tasks - one single plan that improves all frameworks’ compliance.
Do it once - we automatically apply it to all current and future frameworks.