SOC 2
CC - Common Criteria (Security)

SOC 2 SOC2-CC2.3: CC2.3 Communication with external parties about internal control (COSO principle 15)

The organisation communicates with outside parties on matters that affect how internal control functions. Points of focus: relevant, timely information reaches shareholders, partners, regulators, customers and other external parties; open channels let customers, suppliers, auditors and regulators provide input; findings from external assessments reach the board; separate confidential channels exist; the method reflects timing, audience and legal or fiduciary expectations; confidentiality and privacy objectives and their changes are communicated to users, vendors and partners in engagements covering those categories; and at system level, external users are told how the system works, its objectives, their responsibilities and how to report failures, incidents and complaints. The 2022 revision adds, for privacy engagements, telling customers, third parties, data subjects and others how to report a suspected privacy incident.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 101 controls across 30 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • NIST-CSF-GV.OC-02 Internal and external stakeholders are understood, and their needs and expectations regarding cybersecurity risk management are understood and considered
  • NIST-CSF-GV.OC-03 Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed
  • NIST-CSF-GV.RM-05 Lines of communication across the organization are established for cybersecurity risks, including risks from suppliers and other third parties
  • NIST-CSF-GV.SC-02 Cybersecurity roles and responsibilities for suppliers, customers, and partners are established, communicated, and coordinated internally and externally
  • NIST-CSF-GV.SC-08 Relevant suppliers and other third parties are included in incident planning, response, and recovery activities
  • NIST-CSF-RC.CO-03 Recovery activities and progress in restoring operational capabilities are communicated to designated internal and external stakeholders
  • NIST-CSF-RS.CO-02 Internal and external stakeholders are notified of incidents
  • NIST-CSF-RS.CO-03 Information is shared with designated internal and external stakeholders

PCI DSS 4.0 · 8 controls

  • 11.4.7 11.4.7 Multi-tenant providers support customer penetration testing
  • 12.1.1 12.1.1 Overall information security policy established and disseminated
  • 12.8.2 12.8.2 TPSP contracts acknowledging account data responsibility
  • 12.8.4 12.8.4 Annual monitoring of TPSP compliance status
  • 12.8.5 12.8.5 Responsibility allocation between entity and TPSPs
  • 12.9.2 12.9.2 TPSP support for customer information requests
  • 3.7.9 3.7.9 Key guidance for service provider customers
  • 8.3.10 8.3.10 Service provider customer password guidance

ISO/IEC 42001:2023 · 7 controls

  • 4.2 Understanding the needs and expectations of interested parties
  • 7.4 Communication
  • A.10.4 Customers
  • A.8 Information for interested parties of AI systems
  • A.8.2 System documentation and information for users
  • A.8.3 External reporting
  • A.8.5 Information for interested parties

NIST SP 800-53 Rev 5 · 6 controls

C5 (Germany) · 5 controls

  • C5-OIS-05 Contact with Relevant Government Agencies and Interest Groups
  • C5-OPS-21 Involvement of Cloud Customers in the Event of Incidents
  • C5-PI-02 Contractual agreements for the provision of data
  • C5-PSS-01 Guidelines and Recommendations for Cloud Customers
  • C5-PSS-03 Online Register of Known Vulnerabilities

FedRAMP High · 5 controls

  • IR-6 Incident Reporting
  • IR-6(3) Incident Reporting | Supply Chain Coordination (IR-6(3))
  • RA-5(11) Vulnerability Monitoring and Scanning | Public Disclosure Program (RA-5(11))
  • SA-9 External System Services
  • SI-5 Security Alerts, Advisories, and Directives

FedRAMP Moderate · 5 controls

  • IR-6 Incident Reporting
  • IR-6(3) Incident Reporting | Supply Chain Coordination (IR-6(3))
  • RA-5(11) Vulnerability Monitoring and Scanning | Public Disclosure Program (RA-5(11))
  • SA-9 External System Services
  • SI-5 Security Alerts, Advisories, and Directives

ISO 27001:2022 · 5 controls

  • 5.20 Addressing information security within supplier agreements
  • 5.22 Monitoring, review and change management of supplier services
  • 5.31 Legal, statutory, regulatory and contractual requirements
  • 5.5 Contact with authorities
  • 5.6 Contact with special interest groups

ISO 27002:2022 · 5 controls

  • 5.1 Policies for information security
  • 5.14 Information transfer
  • 5.31 Legal, statutory, regulatory and contractual requirements
  • 5.5 Contact with authorities
  • 5.6 Contact with special interest groups

ISO 27701:2019 · 5 controls

  • 5.2.2 Understanding the needs and expectations of interested parties
  • 5.5.4 Communication
  • 6.15.1 Compliance with legal and contractual requirements
  • 8.2.5 Customer obligations
  • 8.5.6 Disclosure of subcontractors used to process PII

ISO 22301:2019 · 4 controls

  • 4.2 Understanding the needs and expectations of interested parties
  • 4.2.2 Legal and regulatory requirements
  • 7.4 Communication
  • 8.4.3 Warning and communication
  • CPS220-19 APRA Notification of Framework Breach within 10 Business Days
  • CPS220-20 Annual Board Risk Management Declaration
  • CPS220-P52 Submission of Appetite Statement, Business Plan and Strategy to APRA
  • MYHR-ENF-1 Mandatory data breach notification
  • MYHR-REG-10 Notification when eligibility or registration conditions can no longer be met
  • MYHR-REG-11 Ensuring required information is given to the System Operator

EU AI Act · 3 controls

  • EUAI-Art.20 Corrective actions and duty of information
  • EUAI-Art.21 Cooperation with competent authorities
  • EUAI-Art.87 Reporting of infringements and protection of reporting persons

NIST SP 800-171 Rev 3 · 3 controls

  • 03.06.02 Incident Monitoring, Reporting, and Response Assistance
  • 03.14.03 Security Alerts, Advisories, and Directives
  • 03.16.03 External System Services
  • CPS230-P33 APRA Notification of Operational Risk Incidents within 72 Hours
  • CPS230-P59 APRA Notification of Service Agreements and Offshoring
  • CFTC-SS-19 Prompt Notification to the Commission
  • CFTC-SS-32 Timely Advance Notice of Material Planned Changes

CIS Controls v8 · 2 controls

  • CIS-16.2 Establish and Maintain a Process to Accept and Address Software Vulnerabilities
  • CIS-17.2 Establish and Maintain Contact Information for Reporting Security Incidents

CMMC 2.0 · 2 controls

DORA · 2 controls

GDPR · 2 controls

NIS2 Directive · 2 controls

  • Art.21.2.d Supply chain security, covering the relationship with each direct supplier and service provider
  • Art.23.2 Tell affected service recipients about significant cyber threats and the remedies open to them

NIST SP 800-161 Rev 1 · 2 controls

AICPA SOC 3 · 1 control

  • SOC3-COMMS Communication

APRA CPS 234 · 1 control

  • CPS234-36 APRA Notification of Material Control Weakness within 10 Business Days
  • SAFE-AEO-D Consultation, Co-operation and Communication

HIPAA Security Rule · 1 control

NIST SP 800-218 · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in CC - Common Criteria (Security)

You are reading one control. How much of SOC 2 have you already done?

SOC 2 SOC2-CC2.3 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of SOC 2 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 49 of 61 SOC 2 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 193 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 101 it maps to, and the evidence behind each claim, over MCP and REST.