SOC 2
C - Confidentiality

SOC 2 SOC2-C1.1: C1.1 Identifying and maintaining confidential information

Confidential information is identified and kept in line with the organisation's confidentiality objectives. Points of focus: procedures define confidential information and identify and designate it when received or created, and set how long it is kept; it is protected from erasure or destruction during that period; and, added in 2022, it is kept no longer than the identified purpose needs unless a law or regulation requires otherwise.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 217 controls across 33 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

PCI DSS 4.0 · 30 controls

  • 1.2.4 1.2.4 Accurate data-flow diagram for account data
  • 1.4.5 1.4.5 Internal IP and routing disclosure limited
  • 10.1.1 10.1.1 Requirement 10 policies and procedures maintained and in use
  • 10.1.2 10.1.2 Roles for logging and monitoring assigned and understood
  • 12.5.1 12.5.1 Inventory of in-scope system components
  • 3.3.1.1 3.3.1.1 Full track data not retained after authorization
  • 3.3.2 3.3.2 Pre-authorization SAD stored electronically is strongly encrypted
  • 3.3.3 3.3.3 Issuer SAD storage limited, justified and encrypted
  • 3.5.1 3.5.1 Stored PAN rendered unreadable
  • 3.5.1.1 3.5.1.1 PAN hashes are keyed cryptographic hashes
  • 3.5.1.2 3.5.1.2 Disk or partition encryption only on removable media
  • 3.5.1.3 3.5.1.3 Disk encryption access independent of OS authentication
  • 3.6.1.4 3.6.1.4 Cryptographic keys kept in fewest locations
  • 3.7.2 3.7.2 Secure distribution of cryptographic keys
  • 3.7.3 3.7.3 Secure storage of cryptographic keys
  • 4.2.1.1 4.2.1.1 Inventory of trusted transmission keys and certificates
  • 4.2.2 4.2.2 PAN secured when sent by end-user messaging
  • 6.5.5 6.5.5 No live PANs in pre-production
  • 8.3.2 8.3.2 Authentication factors unreadable with strong cryptography
  • 9.2.4 9.2.4 Locking of consoles in sensitive areas
  • 9.4.1.1 9.4.1.1 Secure storage location for offline backups
  • 9.4.2 9.4.2 Classification of media by data sensitivity
  • 9.4.3 9.4.3 Securing media sent outside the facility
  • 9.4.5 9.4.5 Inventory logs of electronic media
  • 9.4.5.1 9.4.5.1 Annual inventories of electronic media
  • 3.2.1 3.2.1 Data retention and disposal minimise stored account data
  • 3.3.1 3.3.1 SAD not retained after authorization, even encrypted
  • 3.4.1 3.4.1 PAN masked on display except for authorized roles
  • 3.7.1 3.7.1 Generation of strong cryptographic keys
  • 7.2.4 7.2.4 User accounts and privileges reviewed every six months

NIST SP 800-53 Rev 5 · 19 controls

FedRAMP High · 18 controls

  • AC-11(1) Device Lock | Pattern-hiding Displays (AC-11(1))
  • AC-17(2) Protection of Confidentiality and Integrity Using Encryption
  • AC-22 Publicly Accessible Content
  • AU-9 Protection of Audit Information
  • CM-12 Information Location (CM-12)
  • CM-12(1) Information Location | Automated Tools to Support Information Location (CM-12(1))
  • CP-9(8) System Backup | Cryptographic Protection (CP-9(8))
  • MP-3 Media Marking
  • MP-4 Media Storage
  • MP-5 Media Transport
  • MP-6 Media Sanitization
  • RA-2 Security Categorization
  • SA-9(5) External System Services | Processing, Storage, and Service Location (SA-9(5))
  • SC-13 Cryptographic Protection
  • SC-28 Protection of Information at Rest
  • SC-28(1) Cryptographic Protection
  • SC-8(1) Cryptographic Protection
  • SI-11 Error Handling

FedRAMP Moderate · 18 controls

  • AC-11(1) Device Lock | Pattern-hiding Displays (AC-11(1))
  • AC-17(2) Protection of Confidentiality and Integrity Using Encryption
  • AC-22 Publicly Accessible Content
  • AU-9 Protection of Audit Information
  • CM-12 Information Location (CM-12)
  • CM-12(1) Information Location | Automated Tools to Support Information Location (CM-12(1))
  • CP-9(8) System Backup | Cryptographic Protection (CP-9(8))
  • MP-3 Media Marking
  • MP-4 Media Storage
  • MP-5 Media Transport
  • MP-6 Media Sanitization
  • RA-2 Security Categorization
  • SA-9(5) External System Services | Processing, Storage, and Service Location (SA-9(5))
  • SC-13 Cryptographic Protection
  • SC-28 Protection of Information at Rest
  • SC-28(1) Cryptographic Protection
  • SC-8(1) Cryptographic Protection
  • SI-11 Error Handling

CIS Controls v8 · 17 controls

  • CIS-1.1 Establish and Maintain Detailed Enterprise Asset Inventory
  • CIS-11.3 Protect Recovery Data
  • CIS-14.4 Train Workforce on Data Handling Best Practices
  • CIS-14.5 Train Workforce Members on Causes of Unintentional Data Exposure
  • CIS-3.1 Establish and Maintain a Data Management Process
  • CIS-3.10 Encrypt Sensitive Data in Transit
  • CIS-3.11 Encrypt Sensitive Data at Rest
  • CIS-3.12 Segment Data Processing and Storage Based on Sensitivity
  • CIS-3.13 Deploy a Data Loss Prevention Solution
  • CIS-3.2 Establish and Maintain a Data Inventory
  • CIS-3.3 Configure Data Access Control Lists
  • CIS-3.6 Encrypt Data on End-User Devices
  • CIS-3.7 Establish and Maintain a Data Classification Scheme
  • CIS-3.8 Document Data Flows
  • CIS-3.9 Encrypt Data on Removable Media
  • CIS-4.12 Separate Enterprise Workspaces on Mobile End-User Devices
  • CIS-8.3 Ensure Adequate Audit Log Storage

ISO 27001:2022 · 17 controls

  • 5.10 Acceptable use of information and other associated assets
  • 5.12 Classification of information
  • 5.13 Labelling of information
  • 5.14 Information transfer
  • 5.23 Information security for use of cloud services
  • 5.33 Protection of records
  • 5.9 Inventory of information and other associated assets
  • 6.6 Confidentiality or non-disclosure agreements
  • 6.7 Remote working
  • 7.10 Storage media
  • 7.9 Security of assets off-premises
  • 8.1 User end point devices
  • 8.11 Data masking
  • 8.12 Data leakage prevention
  • 8.13 Information backup
  • 8.24 Use of cryptography
  • 8.33 Test information

ISO 27002:2022 · 16 controls

  • 5.10 Acceptable use of information and other associated assets
  • 5.12 Classification of information
  • 5.13 Labelling of information
  • 5.14 Information transfer
  • 5.20 Addressing information security within supplier agreements
  • 5.32 Intellectual property rights
  • 5.33 Protection of records
  • 5.9 Inventory of information and other associated assets
  • 6.6 Confidentiality or non-disclosure agreements
  • 6.7 Remote working
  • 7.9 Security of assets off-premises
  • 8.1 User endpoint devices
  • 8.11 Data masking
  • 8.12 Data leakage prevention
  • 8.24 Use of cryptography
  • 8.33 Test information

HIPAA Security Rule · 12 controls

NIST SP 800-66 Rev 2 · 10 controls

CMMC 2.0 · 8 controls

ISO 27701:2019 · 7 controls

  • 6.10 Communications security
  • 6.10.2 Information transfer
  • 6.5.1 Responsibility for assets
  • 6.5.2 Information classification
  • 6.7.1 Cryptographic controls
  • 7.4.9 PII transmission controls
  • 8.4.3 PII transmission controls

C5 (Germany) · 6 controls

  • C5-AM-06 Asset Classification and Labelling
  • C5-CRY-03 Encryption of sensitive data for storage
  • C5-HR-06 Confidentiality agreements
  • C5-IDM-07 Access to cloud customer data
  • C5-OPS-24 Separation of Datasets in the Cloud Infrastructure
  • C5-PSS-12 Locations of Data Processing and Storage
  • NIST-CSF-ID.AM-05 Assets are prioritized based on classification, criticality, resources, and impact on the mission
  • NIST-CSF-ID.AM-07 Inventories of data and corresponding metadata for designated data types are maintained
  • NIST-CSF-PR.DS-01 The confidentiality, integrity, and availability of data-at-rest are protected
  • NIST-CSF-PR.DS-02 The confidentiality, integrity, and availability of data-in-transit are protected
  • NIST-CSF-PR.DS-10 The confidentiality, integrity, and availability of data-in-use are protected
  • SEC07-BP01 Understand your data classification scheme
  • SEC07-BP02 Apply data protection controls based on data sensitivity
  • SEC07-BP03 Automate identification and classification
  • SEC07-BP04 Define scalable data lifecycle management
  • ASBv3-DP-1 Discover, classify, and label sensitive data
  • ASBv3-GS-3 Define and implement data protection strategy
  • ASBv3-LT-6 Configure log storage retention
  • DP-4 Enable data at rest encryption by default

NIST SP 800-171 Rev 3 · 3 controls

  • AUCDR-IS-STEP2 Step 2 - Define the boundaries of the CDR data environment
  • AUCDR-PS-12 Privacy Safeguard 12 - Security of CDR data and destruction or de-identification of redundant CDR data
  • MYHR-CUD-2 Prohibition on unauthorised collection, use and disclosure
  • MYHR-CUD-4 Records not held or taken outside Australia

ISO/IEC 42001:2023 · 2 controls

  • 8.4 AI system impact assessment
  • A.7 Data for AI systems

NIST SP 800-161 Rev 1 · 2 controls

AICPA SOC 3 · 1 control

  • SOC3-CONFID Confidentiality
  • ANSSI-HYG-04 Identify the Most Sensitive Information and Servers and Maintain a Network Diagram
  • CPS230-P27 Comprehensive Assessment of the Operational Risk Profile

APRA CPS 234 · 1 control

  • ASD37-27 Outbound data loss prevention (Very Good)
  • AEO-9 Information Exchange, Access and Confidentiality
  • CFTC-SS-37 Protection of Swap Data Repository Data

DORA · 1 control

EU AI Act · 1 control

  • EUAI-Art.59 Further processing of personal data for developing certain AI systems in the public interest in the AI regulatory sandbox

GDPR · 1 control

ISO 22301:2019 · 1 control

  • 7.5.3 Control of documented information

NIST SP 800-172 · 1 control

  • 3.14.5e Review Persistent Storage and Remove CUI No Longer Needed

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in C - Confidentiality

You are reading one control. How much of SOC 2 have you already done?

SOC 2 SOC2-C1.1 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of SOC 2 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 49 of 61 SOC 2 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 193 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 217 it maps to, and the evidence behind each claim, over MCP and REST.