SOC 2
CC - Common Criteria (Security)

SOC 2 SOC2-CC3.1: CC3.1 Objectives specified clearly enough to assess risk (COSO principle 6)

Objectives are defined precisely enough that risks to them can be identified and assessed. Points of focus: operations objectives reflect management's choices and risk tolerances, include performance goals and guide resource allocation; external financial reporting objectives follow suitable accounting principles, consider materiality and reflect real activity; external non-financial reporting objectives follow applicable laws and recognised frameworks with suitable precision; internal reporting gives management accurate, sufficiently precise information; compliance objectives absorb legal minimums and tolerances; and sub-objectives for security, availability, confidentiality, privacy and processing integrity are set to support the overall objectives.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 101 controls across 25 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 22301:2019 · 17 controls

  • 4.2.1 General
  • 4.2.2 Legal and regulatory requirements
  • 4.3.1 General
  • 4.3.2 Scope of the business continuity management system
  • 4.4 Business continuity management system
  • 6.1 Actions to address risks and opportunities
  • 6.1.1 Determining risks and opportunities
  • 6.2 Business continuity objectives and planning to achieve them
  • 6.2.1 Establishing business continuity objectives
  • 6.2.2 Determining business continuity objectives
  • 7.5 Documented information
  • 8.1 Operational planning and control
  • 8.2 Business impact analysis and risk assessment
  • 8.2.1 General
  • 8.2.2 Business impact analysis
  • 8.2.3 Risk assessment
  • 9.2.1 General

NIST SP 800-53 Rev 5 · 14 controls

  • NIST-CSF-GV.OC-01 The organizational mission is understood and informs cybersecurity risk management
  • NIST-CSF-GV.OC-04 Critical objectives, capabilities, and services that external stakeholders depend on or expect from the organization are understood and communicated
  • NIST-CSF-GV.OV-02 The cybersecurity risk management strategy is reviewed and adjusted to ensure coverage of organizational requirements and risks
  • NIST-CSF-GV.PO-01 Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced
  • NIST-CSF-GV.RM-01 Risk management objectives are established and agreed to by organizational stakeholders
  • NIST-CSF-GV.RM-02 Risk appetite and risk tolerance statements are established, communicated, and maintained
  • NIST-CSF-GV.RM-03 Cybersecurity risk management activities and outcomes are included in enterprise risk management processes
  • NIST-CSF-GV.RM-04 Strategic direction that describes appropriate risk response options is established and communicated
  • NIST-CSF-ID.AM-05 Assets are prioritized based on classification, criticality, resources, and impact on the mission
  • NIST-CSF-ID.RA-04 Potential impacts and likelihoods of threats exploiting vulnerabilities are identified and recorded
  • NIST-CSF-ID.RA-09 The authenticity and integrity of hardware and software are assessed prior to acquisition and use

ISO/IEC 42001:2023 · 10 controls

  • 4.1 Understanding the organization and its context
  • 4.4 AI management system
  • 5.2 AI policy
  • 6.1 Actions to address risks and opportunities
  • 6.1.1 General
  • 6.1.2 AI risk assessment
  • 6.2 AI objectives and planning to achieve them
  • 8.1 Operational planning and control
  • A.6.1.2 Objectives for responsible development of AI system
  • A.9.3 Objectives for responsible use of AI system

FedRAMP High · 7 controls

  • PL-2 System Security and Privacy Plans
  • PL-8 Security and Privacy Architectures
  • RA-1 Policy and Procedures
  • RA-2 Security Categorization
  • RA-3 Risk Assessment
  • RA-7 Risk Response
  • SR-1 Policy and Procedures (SR-1)

ISO 27701:2019 · 7 controls

  • 5.2.1 Understanding the organization and its context
  • 5.2.2 Understanding the needs and expectations of interested parties
  • 5.4 Planning
  • 5.4.1 Actions to address risks and opportunities
  • 5.4.2 Information security objectives and planning to achieve them
  • 5.6.2 Information security risk assessment
  • 5.6.3 Information security risk treatment

FedRAMP Moderate · 6 controls

  • PL-2 System Security and Privacy Plans
  • PL-8 Security and Privacy Architectures
  • RA-1 Policy and Procedures
  • RA-2 Security Categorization
  • RA-3 Risk Assessment
  • SR-1 Policy and Procedures (SR-1)
  • CPS220-06 Risk Appetite Statement
  • CPS220-P31 Maintenance of a Business Plan
  • CPS220-P32 Business Plan Duration, Review and Approval
  • CPS220-P33 Risks Arising from Strategic Objectives and the Business Plan

PCI DSS 4.0 · 4 controls

  • 11.3.1 11.3.1 Quarterly internal vulnerability scans
  • 12.1.1 12.1.1 Overall information security policy established and disseminated
  • 12.1.2 12.1.2 Security policy reviewed annually and updated as needed
  • 12.3.2 12.3.2 Targeted risk analysis for each customized-approach requirement

C5 (Germany) · 2 controls

  • C5-COM-01 Identification of applicable legal, regulatory, self-imposed or contractual requirements
  • C5-OIS-06 Risk Management Policy

CMMC 2.0 · 2 controls

HIPAA Security Rule · 2 controls

NIS2 Directive · 2 controls

  • Art.21.1 Take proportionate all-hazards measures calibrated to the entity's own risk exposure
  • Art.21.2.a Policies on risk analysis and on information system security

AICPA SOC 3 · 1 control

  • SOC3-RISK-ASSESS Risk Assessment Process
  • CPS230-15 Operational Risk Elements of the Risk Management Framework
  • SEC01-BP03 Identify and validate control objectives
  • AUCDR-IS-STEP3 Step 3 - Have and maintain an information security capability
  • CFTC-SS-1 Program of Risk Analysis and Oversight

CIS Controls v8 · 1 control

  • CIS-17.4 Establish and Maintain an Incident Response Process

DORA · 1 control

EU AI Act · 1 control

ISO 27002:2022 · 1 control

  • 5.8 Information security in project management

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in CC - Common Criteria (Security)

You are reading one control. How much of SOC 2 have you already done?

SOC 2 SOC2-CC3.1 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of SOC 2 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 49 of 61 SOC 2 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 193 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 101 it maps to, and the evidence behind each claim, over MCP and REST.