SOC 1 (SSAE 18 / ISAE 3402)
Control objectives and controls: design, operation, deviations and change – SOC 1 (SSAE 18 / ISAE 3402)

SOC 1 (SSAE 18 / ISAE 3402) C.2: SOC 1 C.2 Controls suitably designed: risks identified and the controls, if operating effectively, giving reasonable assurance the objectives are achieved

For each objective the risks that threaten it have been identified and the described controls, provided they operate effectively, would give reasonable assurance that the risks will not stop the objective from being met; the auditor assesses design by understanding management's risk process, evaluating the linkage of controls to risks including risks from each class of transactions and the risks IT poses to user entities, and determining the controls are implemented.

Maintained by Gerard BlokdykControl text last updated

Other controls in Control objectives and controls: design, operation, deviations and change – SOC 1 (SSAE 18 / ISAE 3402)

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.