Objectives are defined precisely enough that risks to them can be identified and assessed. Points of focus: operations objectives reflect management's choices and risk tolerances, include performance goals and guide resource allocation; external financial reporting objectives follow suitable accounting principles, consider materiality and reflect real activity; external non-financial reporting objectives follow applicable laws and recognised frameworks with suitable precision; internal reporting gives management accurate, sufficiently precise information; compliance objectives absorb legal minimums and tolerances; and sub-objectives for security, availability, confidentiality, privacy and processing integrity are set to support the overall objectives.
This control maps to 101 controls across 25 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST-CSF-GV.OC-01 The organizational mission is understood and informs cybersecurity risk management
NIST-CSF-GV.OC-04 Critical objectives, capabilities, and services that external stakeholders depend on or expect from the organization are understood and communicated
NIST-CSF-GV.OV-02 The cybersecurity risk management strategy is reviewed and adjusted to ensure coverage of organizational requirements and risks
NIST-CSF-GV.PO-01 Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced
NIST-CSF-GV.RM-01 Risk management objectives are established and agreed to by organizational stakeholders
NIST-CSF-GV.RM-02 Risk appetite and risk tolerance statements are established, communicated, and maintained
NIST-CSF-GV.RM-03 Cybersecurity risk management activities and outcomes are included in enterprise risk management processes
NIST-CSF-GV.RM-04 Strategic direction that describes appropriate risk response options is established and communicated
NIST-CSF-ID.AM-05 Assets are prioritized based on classification, criticality, resources, and impact on the mission
NIST-CSF-ID.RA-04 Potential impacts and likelihoods of threats exploiting vulnerabilities are identified and recorded
NIST-CSF-ID.RA-09 The authenticity and integrity of hardware and software are assessed prior to acquisition and use
You are reading one control. How much of SOC 2 have you already done?
SOC 2 SOC2-CC3.1 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of SOC 2 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 49 of 61 SOC 2 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 193 were rejected on the NIST SP 800-53 Rev 5 pair alone.