SOC 2 SOC2-CC3.2: CC3.2 Identifying and analysing risks to objectives (COSO principle 7)
Risks to objectives are identified across the organisation and analysed as the basis for deciding how to manage them. Points of focus: risk is assessed at entity, subsidiary, division, unit and function level; internal and external factors are considered; appropriate management levels take part; the significance of each risk is estimated; a response of accept, avoid, reduce or share is chosen; information assets are identified and their criticality assessed together with threats and vulnerabilities; threats arising from vendors, partners and others with access are analysed; and significance combines asset criticality, threat impact and likelihood. The 2022 revision restructures the process into steps: list information assets (devices, virtual systems, software, data and its flows, external systems and roles) and rate their criticality; identify threats to objectives and the weaknesses of system components; judge how likely and how severe each resulting risk is; consider that some threats and weaknesses may not yet be known; devise mitigation strategies; and decide whether the residual risk is acceptable or should be reduced or shared.
This control maps to 141 controls across 36 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST-CSF-GV.OC-05 Outcomes, capabilities, and services that the organization depends on are understood and communicated
NIST-CSF-GV.OV-02 The cybersecurity risk management strategy is reviewed and adjusted to ensure coverage of organizational requirements and risks
NIST-CSF-GV.PO-01 Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced
NIST-CSF-GV.RM-02 Risk appetite and risk tolerance statements are established, communicated, and maintained
NIST-CSF-GV.RM-03 Cybersecurity risk management activities and outcomes are included in enterprise risk management processes
NIST-CSF-GV.RM-06 A standardized method for calculating, documenting, categorizing, and prioritizing cybersecurity risks is established and communicated
NIST-CSF-GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders
NIST-CSF-GV.SC-03 Cybersecurity supply chain risk management is integrated into cybersecurity and enterprise risk management, risk assessment, and improvement processes
NIST-CSF-GV.SC-06 Planning and due diligence are performed to reduce risks before entering into formal supplier or other third-party relationships
NIST-CSF-GV.SC-07 The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship
NIST-CSF-ID.AM-05 Assets are prioritized based on classification, criticality, resources, and impact on the mission
NIST-CSF-ID.RA-01 Vulnerabilities in assets are identified, validated, and recorded
NIST-CSF-ID.RA-03 Internal and external threats to the organization are identified and recorded
NIST-CSF-ID.RA-04 Potential impacts and likelihoods of threats exploiting vulnerabilities are identified and recorded
NIST-CSF-ID.RA-05 Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritization
NIST-CSF-ID.RA-06 Risk responses are chosen, prioritized, planned, tracked, and communicated
NIST-CSF-ID.RA-09 The authenticity and integrity of hardware and software are assessed prior to acquisition and use
You are reading one control. How much of SOC 2 have you already done?
SOC 2 SOC2-CC3.2 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of SOC 2 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 49 of 61 SOC 2 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 193 were rejected on the NIST SP 800-53 Rev 5 pair alone.