SOC 2
CC - Common Criteria (Security)

SOC 2 SOC2-CC1.3: CC1.3 Structures, reporting lines, authorities and responsibilities (COSO principle 3)

Management, overseen by the board, sets up the structures, reporting lines and authority needed to pursue objectives. Points of focus: every structure is considered, including business units, legal entities, locations and outsourced providers; reporting lines are designed so authority can be exercised and information can flow; authority and responsibility are delegated with segregation of duties where needed; requirements for security, availability, confidentiality, privacy and processing integrity shape how roles are defined; and the need to interact with and oversee external parties is built into the structure. The 2022 revision adds, for privacy engagements, that legal and contractual privacy obligations shape how structures, reporting lines and authority are set up.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 97 controls across 31 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

PCI DSS 4.0 · 13 controls

  • 1.1.2 1.1.2 Requirement 1 roles and responsibilities assigned
  • 11.1.2 11.1.2 Roles for security testing assigned and understood
  • 12.1.1 12.1.1 Overall information security policy established and disseminated
  • 12.1.2 12.1.2 Security policy reviewed annually and updated as needed
  • 12.1.4 12.1.4 Executive ownership of information security formally assigned
  • 2.1.2 2.1.2 Requirement 2 roles and responsibilities assigned
  • 4.1.2 4.1.2 Requirement 4 roles and responsibilities assigned
  • 5.1.2 5.1.2 Requirement 5 roles and responsibilities assigned
  • 6.1.2 6.1.2 Requirement 6 roles and responsibilities assigned
  • 7.1.2 7.1.2 Requirement 7 roles and responsibilities assigned
  • 9.1.2 9.1.2 Requirement 9 roles and responsibilities assigned
  • 3.1.2 3.1.2 Assigned duties for Requirement 3 activities
  • 8.1.2 8.1.2 Requirement 8 roles and responsibilities assigned

NIST SP 800-53 Rev 5 · 11 controls

ISO 27701:2019 · 10 controls

  • 5.2 Context of the organization
  • 5.2.1 Understanding the organization and its context
  • 5.3 Leadership
  • 5.3.1 Leadership and commitment
  • 5.3.3 Organizational roles, responsibilities and authorities
  • 6.2.1 Management direction for information security
  • 6.3 Organization of information security
  • 6.3.1 Internal organization
  • 6.5.1 Responsibility for assets
  • 6.9.1 Operational procedures and responsibilities

ISO/IEC 42001:2023 · 9 controls

  • 4.1 Understanding the organization and its context
  • 4.4 AI management system
  • 5.1 Leadership and commitment
  • 5.3 Roles, responsibilities and authorities
  • 6.2 AI objectives and planning to achieve them
  • 7.1 Resources
  • A.3 Internal organization
  • A.3.2 AI roles and responsibilities
  • A.4.2 Resource documentation

ISO 22301:2019 · 7 controls

  • 4.1 Understanding the organization and its context
  • 4.2.1 General
  • 4.4 Business continuity management system
  • 5.1 Leadership and commitment
  • 5.3 Roles, responsibilities and authorities
  • 7.1 Resources
  • 8.3.4 Resource requirements
  • NIST-CSF-GV.OC-01 The organizational mission is understood and informs cybersecurity risk management
  • NIST-CSF-GV.OC-04 Critical objectives, capabilities, and services that external stakeholders depend on or expect from the organization are understood and communicated
  • NIST-CSF-GV.RM-04 Strategic direction that describes appropriate risk response options is established and communicated
  • NIST-CSF-GV.RM-05 Lines of communication across the organization are established for cybersecurity risks, including risks from suppliers and other third parties
  • NIST-CSF-GV.RR-01 Organizational leadership is responsible and accountable for cybersecurity risk and fosters a culture that is risk-aware, ethical, and continually improving
  • NIST-CSF-GV.RR-02 Roles, responsibilities, and authorities related to cybersecurity risk management are established, communicated, understood, and enforced
  • NIST-CSF-GV.SC-02 Cybersecurity roles and responsibilities for suppliers, customers, and partners are established, communicated, and coordinated internally and externally
  • CPS220-10 Designated Risk Management Function
  • CPS220-P23 Minimum Contents of the Risk Management Framework
  • CPS220-P40 Chief Risk Officer Reporting Lines and Board Access
  • CPS220-P43 Designated Compliance Function

ISO 27001:2022 · 3 controls

  • 5.2 Information security roles and responsibilities
  • 5.3 Segregation of duties
  • 5.4 Management responsibilities

ISO 27002:2022 · 3 controls

  • 5.2 Information security roles and responsibilities
  • 5.3 Segregation of duties
  • 5.4 Management responsibilities

NIST SP 800-181 · 3 controls

  • CPS230-14 Board Setting of Senior Manager Roles and Responsibilities
  • CPS230-9 Management of the Full Range of Operational Risks

C5 (Germany) · 2 controls

CIS Controls v8 · 2 controls

  • CIS-17.1 Designate Personnel to Manage Incident Handling
  • CIS-17.5 Assign Key Roles and Responsibilities

DORA · 2 controls

AICPA SOC 3 · 1 control

  • SOC3-CONTROL-ENV Control Environment
  • ANSSI-HYG-39 Designate an Information System Security Officer and Make the Role Known

APRA CPS 234 · 1 control

  • CPS234-14 Definition of Information Security Roles and Responsibilities
  • SEC11-BP08 Build a program that embeds security ownership in workload teams
  • AUCDR-IS-STEP1 Step 1 - Define and implement security governance for CDR data
  • GS-1 Align organization roles, responsibilities and accountabilities
  • CFTC-SS-2 Enterprise Risk Management and Governance Category

EU AI Act · 1 control

FedRAMP High · 1 control

  • PS-9 Position Descriptions (PS-9)

FedRAMP Moderate · 1 control

  • PS-9 Position Descriptions (PS-9)

HIPAA Security Rule · 1 control

NIS2 Directive · 1 control

  • Art.20.1 Management body approves the cybersecurity risk-management measures and oversees their implementation
  • 161R1-PM-2 Information Security Program Leadership Role

NIST SP 800-218 · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in CC - Common Criteria (Security)

You are reading one control. How much of SOC 2 have you already done?

SOC 2 SOC2-CC1.3 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of SOC 2 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 49 of 61 SOC 2 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 193 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 97 it maps to, and the evidence behind each claim, over MCP and REST.