SOC 2
CC - Common Criteria (Security)

SOC 2 SOC2-CC3.4: CC3.4 Identifying and assessing significant changes (COSO principle 9)

Changes that could significantly affect the system of internal control are identified and assessed. Points of focus: changes in the regulatory, economic and physical environment; changes to the business model such as new lines, acquisitions, divestments, rapid growth, geographic reliance and new technology; changes in leadership and their attitudes to control; changes in the organisation's systems and technology environment; and changes in vendor and partner relationships. The 2022 revision adds that the process also tracks shifts in internal and external threats and in the weaknesses of system components, and how those shifts change the likelihood and size of risks.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 125 controls across 29 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO/IEC 42001:2023 · 12 controls

  • 10.1 Continual improvement
  • 4.1 Understanding the organization and its context
  • 6.1 Actions to address risks and opportunities
  • 6.1.2 AI risk assessment
  • 6.1.3 AI risk treatment
  • 6.3 Planning of changes
  • 8.3 AI risk treatment
  • 9.3 Management review
  • A.2.3 Alignment with other organizational policies
  • A.4 Resources for AI systems
  • A.5.2 AI system impact assessment process
  • A.9 Use of AI systems

CIS Controls v8 · 11 controls

  • CIS-15.2 Establish and Maintain a Service Provider Management Policy
  • CIS-15.3 Classify Service Providers
  • CIS-16.1 Establish and Maintain a Secure Application Development Process
  • CIS-16.4 Establish and Manage an Inventory of Third-Party Software Components
  • CIS-17.4 Establish and Maintain an Incident Response Process
  • CIS-18.4 Validate Security Measures
  • CIS-2.2 Ensure Authorized Software is Currently Supported
  • CIS-3.8 Document Data Flows
  • CIS-4.2 Establish and Maintain a Secure Configuration Process for Network Infrastructure
  • CIS-6.6 Establish and Maintain an Inventory of Authentication and Authorization Systems
  • CIS-9.1 Ensure Use of Only Fully Supported Browsers and Email Clients

FedRAMP High · 10 controls

  • CA-1 Policy and Procedures
  • CA-7 Continuous Monitoring
  • CA-7(4) Continuous Monitoring | Risk Monitoring (CA-7(4))
  • CM-4 Impact Analyses
  • CP-7(2) Alternate Processing Site | Accessibility (CP-7(2))
  • IR-3(2) Incident Response Testing | Coordination with Related Plans (IR-3(2))
  • PL-1 Policy and Procedures
  • RA-3 Risk Assessment
  • RA-5(2) Update Vulnerabilities to be Scanned
  • RA-7 Risk Response

PCI DSS 4.0 · 10 controls

  • 11.3.1.3 11.3.1.3 Internal scans after significant change
  • 11.4.2 11.4.2 Internal penetration testing annually and after change
  • 12.1.2 12.1.2 Security policy reviewed annually and updated as needed
  • 12.10.6 12.10.6 Plan evolved from lessons learned and industry developments
  • 12.3.3 12.3.3 Cryptographic cipher suite and protocol inventory reviewed annually
  • 12.5.2 12.5.2 Annual and change-driven scope confirmation
  • 12.5.2.1 12.5.2.1 Six-monthly scope confirmation for service providers
  • 12.5.3 12.5.3 Scope review after significant organisational change
  • 6.5.1 6.5.1 Change control procedure for production
  • 6.5.2 6.5.2 Confirm PCI DSS controls after significant change

FedRAMP Moderate · 9 controls

  • CA-1 Policy and Procedures
  • CA-7 Continuous Monitoring
  • CA-7(4) Continuous Monitoring | Risk Monitoring (CA-7(4))
  • CM-4 Impact Analyses
  • CP-7(2) Alternate Processing Site | Accessibility (CP-7(2))
  • IR-3(2) Incident Response Testing | Coordination with Related Plans (IR-3(2))
  • PL-1 Policy and Procedures
  • RA-3 Risk Assessment
  • RA-5(2) Update Vulnerabilities to be Scanned

NIST SP 800-53 Rev 5 · 9 controls

ISO 22301:2019 · 7 controls

  • 4.1 Understanding the organization and its context
  • 6.1.2 Addressing risks and opportunities
  • 6.3 Planning changes to the business continuity management system
  • 8.2 Business impact analysis and risk assessment
  • 8.2.3 Risk assessment
  • 8.3.1 General
  • 9.3.2 Management review input

ISO 27002:2022 · 7 controls

  • 5.22 Monitoring, review and change management of supplier services
  • 5.27 Learning from information security incidents
  • 5.29 Information security during disruption
  • 5.35 Independent review of information security
  • 5.8 Information security in project management
  • 8.25 Secure development life cycle
  • 8.32 Change management

ISO 27701:2019 · 6 controls

  • 5.2.1 Understanding the organization and its context
  • 5.4 Planning
  • 5.6.2 Information security risk assessment
  • 5.8.2 Continual improvement
  • 6.14 Information security aspects of business continuity management
  • 8.5.8 Change of subcontractor to process PII
  • NIST-CSF-GV.OC-02 Internal and external stakeholders are understood, and their needs and expectations regarding cybersecurity risk management are understood and considered
  • NIST-CSF-GV.OV-01 Cybersecurity risk management strategy outcomes are reviewed to inform and adjust strategy and direction
  • NIST-CSF-GV.RM-07 Strategic opportunities (i.e., positive risks) are characterized and are included in organizational cybersecurity risk discussions
  • NIST-CSF-ID.IM-03 Improvements are identified from execution of operational processes, procedures, and activities
  • NIST-CSF-ID.RA-07 Changes and exceptions are managed, assessed for risk impact, recorded, and tracked
  • NIST-CSF-ID.RA-09 The authenticity and integrity of hardware and software are assessed prior to acquisition and use

HIPAA Security Rule · 4 controls

  • CPS220-P33 Risks Arising from Strategic Objectives and the Business Plan
  • CPS220-P46 Scope of the Comprehensive Review
  • CPS220-P48 Assessment Following Material Change Outside the Review Cycle
  • CFTC-SS-12 Capacity and Performance Planning Category
  • CFTC-SS-24 Periodic Update of the Recovery Plan and Emergency Procedures
  • CFTC-SS-32 Timely Advance Notice of Material Planned Changes

ISO 27001:2022 · 3 controls

  • 5.29 Information security during disruption
  • 5.8 Information security in project management
  • 8.32 Change management

NIST SP 800-66 Rev 2 · 3 controls

  • CPS230-P26 Assessment of Business and Strategic Decisions on the Risk Profile
  • CPS230-P45 Annual Update of the Business Continuity Plan

APRA CPS 234 · 2 controls

  • CPS234-P17 Active Maintenance of Capability Against Change
  • CPS234-P31 Annual Review of Testing Program Sufficiency
  • AUCDR-IS-STEP2 Step 2 - Define the boundaries of the CDR data environment
  • AUCDR-IS-STEP3 Step 3 - Have and maintain an information security capability

C5 (Germany) · 2 controls

  • C5-DEV-05 Risk assessment, categorisation and prioritisation of changes
  • C5-OIS-07 Application of the Risk Management Policy

CMMC 2.0 · 2 controls

EU AI Act · 2 controls

NIST SP 800-171 Rev 3 · 2 controls

AICPA SOC 3 · 1 control

  • SOC3-RISK-ASSESS Risk Assessment Process
  • SEC01-BP07 Identify threats and prioritize mitigations using a threat model

DORA · 1 control

NIS2 Directive · 1 control

  • Art.21.3 Take account of supplier-specific vulnerabilities and of Union coordinated supply chain risk assessments

NIST SP 800-172 · 1 control

  • 3.11.5e Assess Effectiveness of Security Solutions

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in CC - Common Criteria (Security)

You are reading one control. How much of SOC 2 have you already done?

SOC 2 SOC2-CC3.4 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of SOC 2 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 49 of 61 SOC 2 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 193 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 125 it maps to, and the evidence behind each claim, over MCP and REST.