SOC 2
CC - Common Criteria (Security)

SOC 2 SOC2-CC3.2: CC3.2 Identifying and analysing risks to objectives (COSO principle 7)

Risks to objectives are identified across the organisation and analysed as the basis for deciding how to manage them. Points of focus: risk is assessed at entity, subsidiary, division, unit and function level; internal and external factors are considered; appropriate management levels take part; the significance of each risk is estimated; a response of accept, avoid, reduce or share is chosen; information assets are identified and their criticality assessed together with threats and vulnerabilities; threats arising from vendors, partners and others with access are analysed; and significance combines asset criticality, threat impact and likelihood. The 2022 revision restructures the process into steps: list information assets (devices, virtual systems, software, data and its flows, external systems and roles) and rate their criticality; identify threats to objectives and the weaknesses of system components; judge how likely and how severe each resulting risk is; consider that some threats and weaknesses may not yet be known; devise mitigation strategies; and decide whether the residual risk is acceptable or should be reduced or shared.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 141 controls across 36 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • NIST-CSF-GV.OC-05 Outcomes, capabilities, and services that the organization depends on are understood and communicated
  • NIST-CSF-GV.OV-02 The cybersecurity risk management strategy is reviewed and adjusted to ensure coverage of organizational requirements and risks
  • NIST-CSF-GV.PO-01 Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced
  • NIST-CSF-GV.RM-02 Risk appetite and risk tolerance statements are established, communicated, and maintained
  • NIST-CSF-GV.RM-03 Cybersecurity risk management activities and outcomes are included in enterprise risk management processes
  • NIST-CSF-GV.RM-06 A standardized method for calculating, documenting, categorizing, and prioritizing cybersecurity risks is established and communicated
  • NIST-CSF-GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders
  • NIST-CSF-GV.SC-03 Cybersecurity supply chain risk management is integrated into cybersecurity and enterprise risk management, risk assessment, and improvement processes
  • NIST-CSF-GV.SC-06 Planning and due diligence are performed to reduce risks before entering into formal supplier or other third-party relationships
  • NIST-CSF-GV.SC-07 The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship
  • NIST-CSF-ID.AM-05 Assets are prioritized based on classification, criticality, resources, and impact on the mission
  • NIST-CSF-ID.RA-01 Vulnerabilities in assets are identified, validated, and recorded
  • NIST-CSF-ID.RA-03 Internal and external threats to the organization are identified and recorded
  • NIST-CSF-ID.RA-04 Potential impacts and likelihoods of threats exploiting vulnerabilities are identified and recorded
  • NIST-CSF-ID.RA-05 Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritization
  • NIST-CSF-ID.RA-06 Risk responses are chosen, prioritized, planned, tracked, and communicated
  • NIST-CSF-ID.RA-09 The authenticity and integrity of hardware and software are assessed prior to acquisition and use

ISO 22301:2019 · 14 controls

  • 4.1 Understanding the organization and its context
  • 4.2.1 General
  • 4.3.1 General
  • 6.1 Actions to address risks and opportunities
  • 6.1.1 Determining risks and opportunities
  • 6.1.2 Addressing risks and opportunities
  • 8.2 Business impact analysis and risk assessment
  • 8.2.1 General
  • 8.2.2 Business impact analysis
  • 8.2.3 Risk assessment
  • 8.3 Business continuity strategies and solutions
  • 8.3.1 General
  • 8.3.2 Identification of strategies and solutions
  • 8.4.1 General

CIS Controls v8 · 13 controls

  • CIS-1.3 Utilize an Active Discovery Tool
  • CIS-10.5 Enable Anti-Exploitation Features
  • CIS-16.14 Conduct Threat Modeling
  • CIS-16.2 Establish and Maintain a Process to Accept and Address Software Vulnerabilities
  • CIS-16.6 Establish and Maintain a Severity Rating System and Process for Application Vulnerabilities
  • CIS-18.1 Establish and Maintain a Penetration Testing Program
  • CIS-18.2 Perform Periodic External Penetration Tests
  • CIS-18.5 Perform Periodic Internal Penetration Tests
  • CIS-2.3 Address Unauthorized Software
  • CIS-7.1 Establish and Maintain a Vulnerability Management Process
  • CIS-7.2 Establish and Maintain a Remediation Process
  • CIS-7.5 Perform Automated Vulnerability Scans of Internal Enterprise Assets
  • CIS-9.4 Restrict Unnecessary or Unauthorized Browser and Email Client Extensions

NIST SP 800-53 Rev 5 · 10 controls

ISO/IEC 42001:2023 · 9 controls

  • 4.1 Understanding the organization and its context
  • 6.1 Actions to address risks and opportunities
  • 6.1.2 AI risk assessment
  • 6.1.3 AI risk treatment
  • 6.1.4 AI system impact assessment
  • 8.2 AI risk assessment
  • A.5.2 AI system impact assessment process
  • A.5.3 Documentation of AI system impact assessments
  • A.5.4 Assessing AI system impact on individuals or groups of individuals

PCI DSS 4.0 · 9 controls

  • 1.2.4 1.2.4 Accurate data-flow diagram for account data
  • 10.3.2 10.3.2 Audit log files protected from modification
  • 10.4.2.1 10.4.2.1 Periodic log review frequency set by targeted risk analysis
  • 11.3.1.1 11.3.1.1 Lower-risk vulnerabilities handled per risk analysis
  • 12.3.2 12.3.2 Targeted risk analysis for each customized-approach requirement
  • 5.2.3.1 5.2.3.1 Targeted risk analysis sets evaluation frequency
  • 5.3.2.1 5.3.2.1 Targeted risk analysis sets malware scan frequency
  • 9.5.1.2 9.5.1.2 Periodic inspection of POI device surfaces
  • 6.3.1 6.3.1 Vulnerability identification and risk ranking

HIPAA Security Rule · 5 controls

ISO 27701:2019 · 5 controls

  • 5.2.1 Understanding the organization and its context
  • 5.4.1 Actions to address risks and opportunities
  • 5.6.2 Information security risk assessment
  • 5.6.3 Information security risk treatment
  • 7.2.5 Privacy impact assessment
  • CPS220-04 Maintenance of a Risk Management Framework
  • CPS220-07 Material Risk Categories the Framework Must Address
  • CPS220-P22 Framework Structure for Managing Each Material Risk
  • CPS220-P35 Required Content of Risk Management Policies and Procedures
  • CPS230-11 Identification, Assessment and Management of Operational Risk
  • CPS230-9 Management of the Full Range of Operational Risks
  • CPS230-P27 Comprehensive Assessment of the Operational Risk Profile
  • CPS230-P28 Risk Assessment Before Providing a Material Service to Another Party

FedRAMP High · 4 controls

  • RA-3 Risk Assessment
  • RA-7 Risk Response
  • RA-9 Criticality Analysis (RA-9)
  • SA-11(2) Developer Testing and Evaluation | Threat Modeling and Vulnerability Analyses (SA-11(2))

NIST SP 800-66 Rev 2 · 4 controls

  • CFTC-SS-1 Program of Risk Analysis and Oversight
  • CFTC-SS-17 Enterprise Technology Risk Assessment
  • CFTC-SS-2 Enterprise Risk Management and Governance Category

CMMC 2.0 · 3 controls

DORA · 3 controls

EU AI Act · 3 controls

  • EUAI-Art.27 Fundamental rights impact assessment for high-risk AI systems
  • EUAI-Art.6 Classification rules for high-risk AI systems
  • EUAI-Art.9 Risk management system

FedRAMP Moderate · 3 controls

  • RA-3 Risk Assessment
  • RA-9 Criticality Analysis (RA-9)
  • SA-11(2) Developer Testing and Evaluation | Threat Modeling and Vulnerability Analyses (SA-11(2))

APRA CPS 234 · 2 controls

C5 (Germany) · 2 controls

ISO 27001:2022 · 2 controls

  • 5.7 Threat intelligence
  • 8.26 Application security requirements

NIS2 Directive · 2 controls

  • Art.21.1 Take proportionate all-hazards measures calibrated to the entity's own risk exposure
  • Art.21.2.a Policies on risk analysis and on information system security

NIST SP 800-161 Rev 1 · 2 controls

NIST SP 800-171 Rev 3 · 2 controls

  • E8-PATCHAPP-ML1 Patch Applications (ML1)

AICPA SOC 3 · 1 control

  • SOC3-RISK-ASSESS Risk Assessment Process
  • SEC01-BP07 Identify threats and prioritize mitigations using a threat model
  • AUCDR-IS-STEP3 Step 3 - Have and maintain an information security capability

GDPR · 1 control

ISO 27002:2022 · 1 control

  • 5.7 Threat intelligence

NIST SP 800-172 · 1 control

  • 3.11.1e Threat-Aware Risk Assessment

NIST SP 800-218 · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in CC - Common Criteria (Security)

You are reading one control. How much of SOC 2 have you already done?

SOC 2 SOC2-CC3.2 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of SOC 2 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 49 of 61 SOC 2 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 193 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 141 it maps to, and the evidence behind each claim, over MCP and REST.