SOC 2
CC - Common Criteria (Security)

SOC 2 SOC2-CC4.1: CC4.1 Ongoing and separate evaluations of control (COSO principle 16)

The organisation chooses, builds and carries out ongoing or separate evaluations to confirm the control components are present and working. Points of focus: a balance between continuous and point-in-time evaluations; the pace of business change informs their design; a baseline of the control system is established; evaluators understand what they evaluate; ongoing evaluations are built into processes; scope and frequency vary with risk; separate evaluations give objective feedback; and varied techniques are used such as penetration testing, independent certification against a standard and internal audit. The 2022 revision widens the evaluation types to include monitoring and testing by the first line and the second line, internal audit, compliance and resilience assessments, vulnerability scanning, security assessments, penetration tests and assessments by outside parties.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 216 controls across 37 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

PCI DSS 4.0 · 27 controls

  • 1.2.7 1.2.7 Six-monthly review of NSC configurations
  • 10.4.2.1 10.4.2.1 Periodic log review frequency set by targeted risk analysis
  • 11.3.1 11.3.1 Quarterly internal vulnerability scans
  • 11.3.1.2 11.3.1.2 Authenticated internal vulnerability scanning
  • 11.3.1.3 11.3.1.3 Internal scans after significant change
  • 11.3.2.1 11.3.2.1 External scans after significant change
  • 11.4.2 11.4.2 Internal penetration testing annually and after change
  • 11.4.4 11.4.4 Correct exploitable findings from penetration tests
  • 12.1.2 12.1.2 Security policy reviewed annually and updated as needed
  • 12.10.2 12.10.2 Annual review and testing of the incident response plan
  • 12.10.4.1 12.10.4.1 Responder training frequency set by targeted risk analysis
  • 12.10.6 12.10.6 Plan evolved from lessons learned and industry developments
  • 12.3.2 12.3.2 Targeted risk analysis for each customized-approach requirement
  • 12.3.3 12.3.3 Cryptographic cipher suite and protocol inventory reviewed annually
  • 12.4.2 12.4.2 Quarterly reviews that personnel follow security procedures
  • 12.4.2.1 12.4.2.1 Documentation of quarterly operational reviews
  • 12.5.2 12.5.2 Annual and change-driven scope confirmation
  • 4.1.1 4.1.1 Requirement 4 policies and procedures maintained and communicated
  • 5.2.3.1 5.2.3.1 Targeted risk analysis sets evaluation frequency
  • 6.2.3.1 6.2.3.1 Manual code review independence and approval
  • 7.1.1 7.1.1 Requirement 7 policies and procedures maintained
  • 7.2.5.1 7.2.5.1 Application and system account access reviewed periodically
  • 9.4.1.1 9.4.1.1 Secure storage location for offline backups
  • 9.4.5.1 9.4.5.1 Annual inventories of electronic media
  • 3.1.1 3.1.1 Requirement 3 policies and procedures maintained and in use
  • 6.4.3 6.4.3 Payment page script management
  • 7.2.4 7.2.4 User accounts and privileges reviewed every six months

NIST SP 800-53 Rev 5 · 20 controls

FedRAMP High · 16 controls

  • AC-2 Account Management
  • AC-6(7) Review of User Privileges
  • CA-1 Policy and Procedures
  • CA-2 Control Assessments
  • CA-6 Authorization
  • CA-7 Continuous Monitoring
  • CA-7(1) Independent Assessment
  • CA-7(4) Continuous Monitoring | Risk Monitoring (CA-7(4))
  • CA-8 Penetration Testing
  • CA-8(1) Penetration Testing | Independent Penetration Testing Agent or Team (CA-8(1))
  • CP-9(1) Testing for Reliability and Integrity
  • IR-3(2) Incident Response Testing | Coordination with Related Plans (IR-3(2))
  • PL-1 Policy and Procedures
  • PL-2 System Security and Privacy Plans
  • RA-3 Risk Assessment
  • SI-2(2) Automated Flaw Remediation Status

FedRAMP Moderate · 16 controls

  • AC-2 Account Management
  • AC-6(7) Review of User Privileges
  • CA-1 Policy and Procedures
  • CA-2 Control Assessments
  • CA-6 Authorization
  • CA-7 Continuous Monitoring
  • CA-7(1) Independent Assessment
  • CA-7(4) Continuous Monitoring | Risk Monitoring (CA-7(4))
  • CA-8 Penetration Testing
  • CA-8(1) Penetration Testing | Independent Penetration Testing Agent or Team (CA-8(1))
  • CP-9(1) Testing for Reliability and Integrity
  • IR-3(2) Incident Response Testing | Coordination with Related Plans (IR-3(2))
  • PL-1 Policy and Procedures
  • PL-2 System Security and Privacy Plans
  • RA-3 Risk Assessment
  • SI-2(2) Automated Flaw Remediation Status

ISO 22301:2019 · 15 controls

  • 10.1 Nonconformity and corrective action
  • 4.4 Business continuity management system
  • 6.1 Actions to address risks and opportunities
  • 7.5 Documented information
  • 7.5.3 Control of documented information
  • 8.1 Operational planning and control
  • 8.2.1 General
  • 8.3.1 General
  • 8.5 Exercise programme
  • 8.6 Evaluation of business continuity documentation and capabilities
  • 9.1 Monitoring, measurement, analysis and evaluation
  • 9.2 Internal audit
  • 9.2.1 General
  • 9.2.2 Audit programme(s)
  • 9.3.1 General

CIS Controls v8 · 12 controls

  • CIS-11.5 Test Data Recovery
  • CIS-14.7 Train Workforce on How to Identify and Report if Their Enterprise Assets are Missing Security Updates
  • CIS-16.13 Conduct Application Penetration Testing
  • CIS-16.6 Establish and Maintain a Severity Rating System and Process for Application Vulnerabilities
  • CIS-18.1 Establish and Maintain a Penetration Testing Program
  • CIS-18.2 Perform Periodic External Penetration Tests
  • CIS-18.4 Validate Security Measures
  • CIS-18.5 Perform Periodic Internal Penetration Tests
  • CIS-5.5 Establish and Maintain an Inventory of Service Accounts
  • CIS-7.1 Establish and Maintain a Vulnerability Management Process
  • CIS-7.5 Perform Automated Vulnerability Scans of Internal Enterprise Assets
  • CIS-7.6 Perform Automated Vulnerability Scans of Externally-Exposed Enterprise Assets

ISO 27701:2019 · 10 controls

  • 5.6.2 Information security risk assessment
  • 5.7 Performance evaluation
  • 5.7.1 Monitoring, measurement, analysis and evaluation
  • 5.7.2 Internal audit
  • 5.8 Improvement
  • 5.8.1 Nonconformity and corrective action
  • 5.8.2 Continual improvement
  • 6.15.2 Information security reviews
  • 6.9.1 Operational procedures and responsibilities
  • 6.9.7 Information systems audit considerations
  • NIST-CSF-DE.CM-01 Networks and network services are monitored to find potentially adverse events
  • NIST-CSF-GV.OV-01 Cybersecurity risk management strategy outcomes are reviewed to inform and adjust strategy and direction
  • NIST-CSF-GV.OV-02 The cybersecurity risk management strategy is reviewed and adjusted to ensure coverage of organizational requirements and risks
  • NIST-CSF-GV.OV-03 Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed
  • NIST-CSF-GV.RM-07 Strategic opportunities (i.e., positive risks) are characterized and are included in organizational cybersecurity risk discussions
  • NIST-CSF-ID.IM-01 Improvements are identified from evaluations
  • NIST-CSF-ID.IM-02 Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties
  • NIST-CSF-ID.IM-03 Improvements are identified from execution of operational processes, procedures, and activities
  • NIST-CSF-ID.RA-08 Processes for receiving, analyzing, and responding to vulnerability disclosures are established
  • NIST-CSF-ID.RA-09 The authenticity and integrity of hardware and software are assessed prior to acquisition and use

ISO/IEC 42001:2023 · 8 controls

  • 10.1 Continual improvement
  • 4.4 AI management system
  • 8.3 AI risk treatment
  • 9.1 Monitoring, measurement, analysis and evaluation
  • 9.2 Internal audit
  • 9.2.1 General
  • 9.2.2 Internal audit programme
  • 9.3 Management review

ISO 27001:2022 · 6 controls

  • 5.22 Monitoring, review and change management of supplier services
  • 5.35 Independent review of information security
  • 5.36 Compliance with policies, rules and standards for information security
  • 8.16 Monitoring activities
  • 8.29 Security testing in development and acceptance
  • 8.32 Change management

ISO 27002:2022 · 6 controls

  • 5.22 Monitoring, review and change management of supplier services
  • 5.28 Collection of evidence
  • 5.35 Independent review of information security
  • 5.36 Compliance with policies, rules and standards for information security
  • 8.16 Monitoring activities
  • 8.32 Change management

CMMC 2.0 · 5 controls

  • CPS220-11 Annual Audit Review of the Framework
  • CPS220-18 Triennial Comprehensive Review of the Framework
  • CPS220-P46 Scope of the Comprehensive Review
  • CPS220-P47 Minimum Assessment Required by the Framework Review
  • CPS230-16 Internal Audit Review of the Business Continuity Plan
  • CPS230-49 Internal Audit Review of Proposed Critical Operation Outsourcing
  • CPS230-66 Review of Operational Risk Management
  • CPS230-P30 Monitoring, Review and Testing of Control Effectiveness

APRA CPS 234 · 4 controls

  • CPS234-22 Systematic Control Testing Program
  • CPS234-25 Internal Audit Review of Information Security Controls
  • CPS234-P30 Independence and Skill of Testing Personnel
  • CPS234-P31 Annual Review of Testing Program Sufficiency

C5 (Germany) · 4 controls

  • C5-COM-02 Policy for planning and conducting audits
  • C5-COM-03 Internal audits of the information security management system
  • C5-OPS-19 Managing Vulnerabilities, Malfunctions and Errors - Penetration Tests
  • C5-OPS-20 Managing Vulnerabilities, Malfunctions and Errors - Measurements, Analyses and Assessments of Procedures
  • ASBv3-GS-5 Define and implement security posture management strategy
  • ASBv3-PV-7 Conduct regular red team operations
  • PV-2 Audit and enforce secure configurations

DORA · 3 controls

  • DORA-Art.24 General requirements for the performance of digital operational resilience testing
  • DORA-Art.50 Administrative penalties and remedial measures
  • DORA-Art.6 ICT risk management framework

EU AI Act · 3 controls

  • EUAI-Art.17 Quality management system
  • EUAI-Art.43 Conformity assessment
  • EUAI-Art.72 Post-market monitoring by providers and post-market monitoring plan for high-risk AI systems

HIPAA Security Rule · 3 controls

NIST SP 800-171 Rev 3 · 3 controls

  • 53A-3.1 Prepare for Control Assessments
  • 53A-3.3 Conduct Control Assessments
  • 53A-F Ongoing Assessment and Automation

NIST SP 800-66 Rev 2 · 3 controls

  • AEO-13 Measurement, Analyses and Improvement
  • P2-S1 Partnership

GDPR · 2 controls

NIST SP 800-172 · 2 controls

  • 3.11.5e Assess Effectiveness of Security Solutions
  • 3.12.1e Penetration Testing by Independent Agents
  • E8-APP-ML2 Application Control (ML2)

AICPA SOC 3 · 1 control

  • SOC3-MONITORING Monitoring Controls
  • ANSSI-HYG-38 Carry Out Regular Security Checks and Audits and Apply the Corrective Actions
  • AUCDR-IS-STEP4 Step 4 - Implement a formal controls assessment program

NIS2 Directive · 1 control

  • Art.21.2.f Policies and procedures to assess the effectiveness of the cybersecurity risk-management measures

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in CC - Common Criteria (Security)

You are reading one control. How much of SOC 2 have you already done?

SOC 2 SOC2-CC4.1 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of SOC 2 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 49 of 61 SOC 2 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 193 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 216 it maps to, and the evidence behind each claim, over MCP and REST.