SOC2

SOC 2 Trust Services Criteria

Deep dives on the five Trust Services Criteria and the COSO-based Common Criteria (CC1–CC9) that anchor every SOC 2. Back to SOC 2: The Complete Guide.

SOC 2 Trust Services Criteria
Loading advertisement...
10

Deep dives on the five Trust Services Criteria and the COSO-based Common Criteria (CC1–CC9) that anchor every SOC 2. ← Back to SOC 2: The Complete Guide

The five criteria

The Common Criteria (CC1–CC9, COSO components)

Area

Guide

CC1 Control Environment

Control Environment: Tone at the Top

CC2 Communication & Information

Information & Communication

CC3 Risk Assessment

Risk Assessment Process

CC4 Monitoring Activities

Monitoring Activities

CC5 Control Activities

Control Activities

How the criteria work

Guide

What you'll learn

SOC 2 Common Criteria: Universal Requirements

The mandatory CC baseline in every report

SOC 2 Additional Criteria: Optional Categories

When to add Availability/PI/Confidentiality/Privacy

SOC 2 Control Objectives

Defining expected outcomes

SOC 2 Control Design

Creating effective controls (Type I focus)

SOC 2 Operating Effectiveness

Demonstrating consistent performance (Type II)

Resources: TSC Mapping Template · Control Matrix / RACI

Frequently asked questions

Which criteria are mandatory?

Only Security (the Common Criteria).

What do CC1–CC5 map to?

The five COSO components / 17 principles.

10

About the author

Cybersecurity Expert

Satish Kumar writes about cybersecurity, offensive security, and practical defense strategies on PentesterWorld.

Related Articles

Comments (0)

No comments yet. Be the first to share your thoughts!