Frameworks / SOC 2 / SOC2-C1.1 SOC 2 SOC2-C1.1: C1.1 Identifying and maintaining confidential information Confidential information is identified and kept in line with the organisation's confidentiality objectives. Points of focus: procedures define confidential information and identify and designate it when received or created, and set how long it is kept; it is protected from erasure or destruction during that period; and, added in 2022, it is kept no longer than the identified purpose needs unless a law or regulation requires otherwise.
Maintained by Gerard Blokdyk · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 217 controls across 33 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
1.2.4 1.2.4 Accurate data-flow diagram for account data 1.4.5 1.4.5 Internal IP and routing disclosure limited 10.1.1 10.1.1 Requirement 10 policies and procedures maintained and in use 10.1.2 10.1.2 Roles for logging and monitoring assigned and understood 12.5.1 12.5.1 Inventory of in-scope system components 3.3.1.1 3.3.1.1 Full track data not retained after authorization 3.3.2 3.3.2 Pre-authorization SAD stored electronically is strongly encrypted 3.3.3 3.3.3 Issuer SAD storage limited, justified and encrypted 3.5.1 3.5.1 Stored PAN rendered unreadable 3.5.1.1 3.5.1.1 PAN hashes are keyed cryptographic hashes 3.5.1.2 3.5.1.2 Disk or partition encryption only on removable media 3.5.1.3 3.5.1.3 Disk encryption access independent of OS authentication 3.6.1.4 3.6.1.4 Cryptographic keys kept in fewest locations 3.7.2 3.7.2 Secure distribution of cryptographic keys 3.7.3 3.7.3 Secure storage of cryptographic keys 4.2.1.1 4.2.1.1 Inventory of trusted transmission keys and certificates 4.2.2 4.2.2 PAN secured when sent by end-user messaging 6.5.5 6.5.5 No live PANs in pre-production 8.3.2 8.3.2 Authentication factors unreadable with strong cryptography 9.2.4 9.2.4 Locking of consoles in sensitive areas 9.4.1.1 9.4.1.1 Secure storage location for offline backups 9.4.2 9.4.2 Classification of media by data sensitivity 9.4.3 9.4.3 Securing media sent outside the facility 9.4.5 9.4.5 Inventory logs of electronic media 9.4.5.1 9.4.5.1 Annual inventories of electronic media 3.2.1 3.2.1 Data retention and disposal minimise stored account data 3.3.1 3.3.1 SAD not retained after authorization, even encrypted 3.4.1 3.4.1 PAN masked on display except for authorized roles 3.7.1 3.7.1 Generation of strong cryptographic keys 7.2.4 7.2.4 User accounts and privileges reviewed every six months AC-11(1) Device Lock | Pattern-hiding Displays (AC-11(1)) AC-17(2) Protection of Confidentiality and Integrity Using Encryption AC-22 Publicly Accessible Content AU-9 Protection of Audit Information CM-12 Information Location (CM-12) CM-12(1) Information Location | Automated Tools to Support Information Location (CM-12(1)) CP-9(8) System Backup | Cryptographic Protection (CP-9(8)) MP-3 Media Marking MP-4 Media Storage MP-5 Media Transport MP-6 Media Sanitization RA-2 Security Categorization SA-9(5) External System Services | Processing, Storage, and Service Location (SA-9(5)) SC-13 Cryptographic Protection SC-28 Protection of Information at Rest SC-28(1) Cryptographic Protection SC-8(1) Cryptographic Protection SI-11 Error Handling AC-11(1) Device Lock | Pattern-hiding Displays (AC-11(1)) AC-17(2) Protection of Confidentiality and Integrity Using Encryption AC-22 Publicly Accessible Content AU-9 Protection of Audit Information CM-12 Information Location (CM-12) CM-12(1) Information Location | Automated Tools to Support Information Location (CM-12(1)) CP-9(8) System Backup | Cryptographic Protection (CP-9(8)) MP-3 Media Marking MP-4 Media Storage MP-5 Media Transport MP-6 Media Sanitization RA-2 Security Categorization SA-9(5) External System Services | Processing, Storage, and Service Location (SA-9(5)) SC-13 Cryptographic Protection SC-28 Protection of Information at Rest SC-28(1) Cryptographic Protection SC-8(1) Cryptographic Protection SI-11 Error Handling CIS-1.1 Establish and Maintain Detailed Enterprise Asset Inventory CIS-11.3 Protect Recovery Data CIS-14.4 Train Workforce on Data Handling Best Practices CIS-14.5 Train Workforce Members on Causes of Unintentional Data Exposure CIS-3.1 Establish and Maintain a Data Management Process CIS-3.10 Encrypt Sensitive Data in Transit CIS-3.11 Encrypt Sensitive Data at Rest CIS-3.12 Segment Data Processing and Storage Based on Sensitivity CIS-3.13 Deploy a Data Loss Prevention Solution CIS-3.2 Establish and Maintain a Data Inventory CIS-3.3 Configure Data Access Control Lists CIS-3.6 Encrypt Data on End-User Devices CIS-3.7 Establish and Maintain a Data Classification Scheme CIS-3.8 Document Data Flows CIS-3.9 Encrypt Data on Removable Media CIS-4.12 Separate Enterprise Workspaces on Mobile End-User Devices CIS-8.3 Ensure Adequate Audit Log Storage 5.10 Acceptable use of information and other associated assets 5.12 Classification of information 5.13 Labelling of information 5.14 Information transfer 5.23 Information security for use of cloud services 5.33 Protection of records 5.9 Inventory of information and other associated assets 6.6 Confidentiality or non-disclosure agreements 6.7 Remote working 7.10 Storage media 7.9 Security of assets off-premises 8.1 User end point devices 8.11 Data masking 8.12 Data leakage prevention 8.13 Information backup 8.24 Use of cryptography 8.33 Test information 5.10 Acceptable use of information and other associated assets 5.12 Classification of information 5.13 Labelling of information 5.14 Information transfer 5.20 Addressing information security within supplier agreements 5.32 Intellectual property rights 5.33 Protection of records 5.9 Inventory of information and other associated assets 6.6 Confidentiality or non-disclosure agreements 6.7 Remote working 7.9 Security of assets off-premises 8.1 User endpoint devices 8.11 Data masking 8.12 Data leakage prevention 8.24 Use of cryptography 8.33 Test information 6.10 Communications security 6.10.2 Information transfer 6.5.1 Responsibility for assets 6.5.2 Information classification 6.7.1 Cryptographic controls 7.4.9 PII transmission controls 8.4.3 PII transmission controls C5-AM-06 Asset Classification and Labelling C5-CRY-03 Encryption of sensitive data for storage C5-HR-06 Confidentiality agreements C5-IDM-07 Access to cloud customer data C5-OPS-24 Separation of Datasets in the Cloud Infrastructure C5-PSS-12 Locations of Data Processing and Storage NIST-CSF-ID.AM-05 Assets are prioritized based on classification, criticality, resources, and impact on the mission NIST-CSF-ID.AM-07 Inventories of data and corresponding metadata for designated data types are maintained NIST-CSF-PR.DS-01 The confidentiality, integrity, and availability of data-at-rest are protected NIST-CSF-PR.DS-02 The confidentiality, integrity, and availability of data-in-transit are protected NIST-CSF-PR.DS-10 The confidentiality, integrity, and availability of data-in-use are protected SEC07-BP01 Understand your data classification scheme SEC07-BP02 Apply data protection controls based on data sensitivity SEC07-BP03 Automate identification and classification SEC07-BP04 Define scalable data lifecycle management ASBv3-DP-1 Discover, classify, and label sensitive data ASBv3-GS-3 Define and implement data protection strategy ASBv3-LT-6 Configure log storage retention DP-4 Enable data at rest encryption by default AUCDR-IS-STEP2 Step 2 - Define the boundaries of the CDR data environment AUCDR-PS-12 Privacy Safeguard 12 - Security of CDR data and destruction or de-identification of redundant CDR data MYHR-CUD-2 Prohibition on unauthorised collection, use and disclosure MYHR-CUD-4 Records not held or taken outside Australia 8.4 AI system impact assessment A.7 Data for AI systems SOC3-CONFID Confidentiality ANSSI-HYG-04 Identify the Most Sensitive Information and Servers and Maintain a Network Diagram CPS230-P27 Comprehensive Assessment of the Operational Risk Profile ASD37-27 Outbound data loss prevention (Very Good) AEO-9 Information Exchange, Access and Confidentiality CFTC-SS-37 Protection of Swap Data Repository Data EUAI-Art.59 Further processing of personal data for developing certain AI systems in the public interest in the AI regulatory sandbox 7.5.3 Control of documented information 3.14.5e Review Persistent Storage and Remove CUI No Longer Needed Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in C - Confidentiality You are reading one control. How much of SOC 2 have you already done? SOC 2 SOC2-C1.1 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of SOC 2 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 49 of 61 SOC 2 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 193 were rejected on the NIST SP 800-53 Rev 5 pair alone.
Query this from an agent The graph holds this control, the 217 it maps to, and the evidence behind each claim, over MCP and REST.