Frameworks / SOC 2 / SOC2-CC4.2 SOC 2
CC - Common Criteria (Security)
SOC 2 SOC2-CC4.2: CC4.2 Evaluating and communicating control deficiencies (COSO principle 17) Control deficiencies are evaluated and reported promptly to those who must fix them, including senior management and the board where appropriate. Points of focus: management and the board assess the results of evaluations; deficiencies go to the parties responsible for correction and upward as appropriate; and management tracks whether they are remedied on time.
Maintained by Gerard Blokdyk · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 328 controls across 119 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
10.4.3 10.4.3 Exceptions and anomalies from log review addressed 11.3.1.1 11.3.1.1 Lower-risk vulnerabilities handled per risk analysis 11.4.4 11.4.4 Correct exploitable findings from penetration tests 12.1.2 12.1.2 Security policy reviewed annually and updated as needed 12.10.6 12.10.6 Plan evolved from lessons learned and industry developments 12.4.2 12.4.2 Quarterly reviews that personnel follow security procedures 12.4.2.1 12.4.2.1 Documentation of quarterly operational reviews 12.6.1 12.6.1 Formal security awareness program 2.1.1 2.1.1 Requirement 2 policies and procedures governed 2.2.2 2.2.2 Vendor default accounts managed 4.1.1 4.1.1 Requirement 4 policies and procedures maintained and communicated 6.1.1 6.1.1 Requirement 6 policies and procedures maintained and communicated 6.2.3.1 6.2.3.1 Manual code review independence and approval 7.1.1 7.1.1 Requirement 7 policies and procedures maintained 9.1.1 9.1.1 Requirement 9 policies and procedures maintained 8.1.1 8.1.1 Requirement 8 policies and procedures maintained NIST-CSF-DE.AE-06 Information on adverse events is provided to authorized staff and tools NIST-CSF-DE.AE-08 Incidents are declared when adverse events meet the defined incident criteria NIST-CSF-GV.OV-01 Cybersecurity risk management strategy outcomes are reviewed to inform and adjust strategy and direction NIST-CSF-GV.OV-02 The cybersecurity risk management strategy is reviewed and adjusted to ensure coverage of organizational requirements and risks NIST-CSF-GV.OV-03 Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed NIST-CSF-GV.PO-02 Policy for managing cybersecurity risks is reviewed, updated, communicated, and enforced to reflect changes in requirements, threats, technology, and organizational mission NIST-CSF-GV.RM-07 Strategic opportunities (i.e., positive risks) are characterized and are included in organizational cybersecurity risk discussions NIST-CSF-ID.IM-02 Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties NIST-CSF-ID.IM-03 Improvements are identified from execution of operational processes, procedures, and activities NIST-CSF-ID.RA-06 Risk responses are chosen, prioritized, planned, tracked, and communicated NIST-CSF-ID.RA-08 Processes for receiving, analyzing, and responding to vulnerability disclosures are established NIST-CSF-ID.RA-09 The authenticity and integrity of hardware and software are assessed prior to acquisition and use NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties NIST-CSF-RS.CO-02 Internal and external stakeholders are notified of incidents 5.5.5 Documented information 5.7 Performance evaluation 5.7.2 Internal audit 5.7.3 Management review 5.8 Improvement 5.8.1 Nonconformity and corrective action 5.8.2 Continual improvement 6.13.1 Management of information security incidents and improvements 6.15.2 Information security reviews 6.3 Organization of information security 10.1 Nonconformity and corrective action 10.2 Continual improvement 7.5 Documented information 8.3.1 General 9.2 Internal audit 9.2.2 Audit programme(s) 9.3 Management review 9.3.2 Management review input 9.3.3 Management review outputs 5.1 Policies for information security 5.22 Monitoring, review and change management of supplier services 5.25 Assessment and decision on information security events 5.26 Response to information security incidents 5.27 Learning from information security incidents 5.35 Independent review of information security 5.36 Compliance with policies, rules and standards for information security 5.4 Management responsibilities 8.16 Monitoring activities CIS-14.7 Train Workforce on How to Identify and Report if Their Enterprise Assets are Missing Security Updates CIS-16.2 Establish and Maintain a Process to Accept and Address Software Vulnerabilities CIS-17.4 Establish and Maintain an Incident Response Process CIS-17.8 Conduct Post-Incident Reviews CIS-18.3 Remediate Penetration Test Findings CIS-7.2 Establish and Maintain a Remediation Process CIS-7.7 Remediate Detected Vulnerabilities CIS-8.11 Conduct Audit Log Reviews CA-1 Policy and Procedures CA-2 Control Assessments CA-5 Plan of Action and Milestones CA-9 Internal System Connections PL-1 Policy and Procedures SI-2(3) Flaw Remediation | Time to Remediate Flaws and Benchmarks for Corrective Actions (SI-2(3)) SR-1 Policy and Procedures (SR-1) CA-1 Policy and Procedures CA-2 Control Assessments CA-5 Plan of Action and Milestones CA-9 Internal System Connections PL-1 Policy and Procedures SI-2(3) Flaw Remediation | Time to Remediate Flaws and Benchmarks for Corrective Actions (SI-2(3)) SR-1 Policy and Procedures (SR-1) 5.22 Monitoring, review and change management of supplier services 5.25 Assessment and decision on information security events 5.26 Response to information security incidents 5.27 Learning from information security incidents 5.35 Independent review of information security 5.36 Compliance with policies, rules and standards for information security 8.16 Monitoring activities 10.1 Continual improvement 10.2 Nonconformity and corrective action 4.4 AI management system 7.4 Communication 8.2 AI risk assessment 9.3 Management review 9.3.2 Management review inputs CPS220-11 Annual Audit Review of the Framework CPS220-16 Management Information System and Data Framework CPS220-19 APRA Notification of Framework Breach within 10 Business Days CPS220-P50 Qualification of the Risk Management Declaration C5-COM-03 Internal audits of the information security management system C5-COM-04 Information on information security performance and management assessment of the ISMS C5-OPS-20 Managing Vulnerabilities, Malfunctions and Errors - Measurements, Analyses and Assessments of Procedures DA-1 Enterprise Data Architecture DIQ-2 Data Quality Management RMD-1 Reference Data Management IEC62304-5.2 Software Requirements Analysis IEC62304-5.3 Software Architectural Design IEC62304-7.2 Risk Control Measures ISO-15189-5.1 Legal entity ISO-15189-5.4 Structure and authority ISO-15189-6.7 Service agreements ISO-19650-1-4 Information management concepts ISO-19650-1-7 Common Data Environment (CDE) concept ISO-19650-3-5.3 Trigger events for information exchange ISO-22320-5.1 General process requirements ISO-22320-5.3 Incident management structure (command) ISO-22320-5.4 Roles and responsibilities ISO23894-1 Scope of AI Risk Management ISO23894-3 AI-Specific Terminology ISO23894-6.2 Scope, Context and Criteria 27004-3 Terms and definitions 27004-A.2 Patching and Vulnerability Measures 27004-B.1 Example measurement definitions 27557-1 Scope 27557-3 Terms and definitions 27557-6.2 Scope, context, and criteria for privacy 29100-1 Scope 29100-3 Terms and definitions 29100-4.1 Actors and roles Art.20.1 Management body approves the cybersecurity risk-management measures and oversees their implementation Art.21.2.f Policies and procedures to assess the effectiveness of the cybersecurity risk-management measures Art.21.4 Take corrective measures without undue delay on finding that the measures are not met TRINIDAD-1 Scope, Definitions, Commission TRINIDAD-2 Lawful Processing and Consent TRINIDAD-3 Data Subject Rights 58.1 Scope 58.3 Definitions CPS230-P30 Monitoring, Review and Testing of Control Effectiveness CPS230-P31 Remediation of Material Operational Risk Weaknesses CPS234-28 Escalation of Unremediated Testing Deficiencies CPS234-36 APRA Notification of Material Control Weakness within 10 Business Days AL-DPA-1 Scope and Definitions AL-DPA-3 Lawful Basis for Processing AT-DSG-2 Section 2 - Scope and application AT-DSG-8 Section 22 - Functions and powers of the DPA MLE.1 Machine Learning Requirements Analysis MLE.3 Machine Learning Training CFTC-SS-21 Remediation of Vulnerabilities and Deficiencies CFTC-SS-36 Internal Reporting and Review by Senior Management and the Board FEDRAMP-CM-6 Configuration Settings FEDRAMP-CP-9 System Backup FDBR-702 Definitions (§501.702) FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704) 60601-1.3 Terminology and definitions 60601-1.4.1 General requirements ISO-20400-4.2 Principles of sustainable procurement ISO-20400-7.2 Integrating sustainability into specifications ISO-41001-4.1 Understanding the organization and its context ISO-41001-4.3 Determining the scope of the FM management system ISO-56002-4.3 Determining the scope of the innovation management system ISO-56002-8.3.4 Develop solutions ISO8000-DQM-02 Data Quality Dimensions ISO8000-MDG-03 Continuous Improvement ISO-17025-5.1 Legal entity ISO-17025-5.4 Personnel for the management system ISO-25012-5.2 Defining data quality measures ISO-25012-5.3 Planning and performing data quality evaluations 27011-1 Scope 27011-3 Terms and definitions 27014-1 Scope 27014-3 Terms and definitions 29147-3 Terms and definitions 29147-9.2 Contact mechanisms and scope 30111-3 Terms and definitions 30111-5.1 Organizational policy STANAG-1 STANAG 4774 Confidentiality Label Schema and XML Structure STANAG-2 STANAG 4778 Metadata Binding Mechanism and Cryptographic Binding 53A-3.4 Analyze Assessment Report Results 53A-E Assessment Reports NDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal NDPA-5 Privacy Notice, Data Minimisation, and Purpose Limitation PICERL-P2 Risk Assessment PICERL-P3 CSIRT Formation SSAE18-CC7.4 CC7.4 - Incident Response SSAE18-PI1.1 PI1.1 - Processing Integrity Definition C1 Organizational Boundary C3 Scope 1 and 2 Coverage TANZANIA-1 Scope, Registration, Lawful Basis TANZANIA-4 Security and Cross-Border Section 6(5) Definition of Foreign Public Official Section 8 Definition of Associated Person US-SEC-DA-SC-01 Howey Test Application US-SEC-DA-SC-02 Registration Requirements CFR211-A-3 Section 211.3 - Definitions SOC3-MONITORING Monitoring Controls ANSSI-HYG-38 Carry Out Regular Security Checks and Audits and Apply the Corrective Actions 4.4.1 Resources, Roles, Responsibility, and Authority SEC04-BP04 Initiate remediation for non-compliant resources AWWA-1.1 Security Policy and Governance AUCDR-IS-STEP4 Step 4 - Implement a formal controls assessment program AEO-13 Measurement, Analyses and Improvement AZ-DPA-2 Article 2 - Basic Concepts CPG-6.B Supply Chain Incident Reporting COBIT-BAI02 Managed requirements definition FFIEC-05 Roles and responsibilities definition FTC-Safeguards-Scope-Defs Scope, Definitions and Financial Institution Applicability (16 CFR 314.1, 314.2) ICP-1 Objectives, Powers and Responsibilities of the Supervisor 62351-2 Glossary of terms ISO-14064-1-5.1 Organizational boundaries ISO-26262-3-5 Item definition ISO28001-PI-01 Personnel Security Screening ISO27003-4.3 Determining the scope of the information security management system 27007-5.2 Audit Programme Objectives ISO27043-04 Roles and responsibilities definition 27050-1.4 Terms and definitions 27400-3 Terms and definitions 29115-3 Terms and definitions 29134-3 Terms and definitions ISO21434-04 Roles and responsibilities definition BIPA-SEC5-1 Biometric Identifier Definition 3.11.5e Assess Effectiveness of Security Solutions PCI-P2PE-05 Roles and responsibilities definition PCI-PIN-05 Roles and responsibilities definition PCI-SSF-05 Roles and responsibilities definition RIDTPPA-1 Scope, Applicability, Definitions SCA-S2 Interpretation and Definitions IM8-RES.2 Disaster Recovery ISMSP-SYS-04 Vulnerability Management SWE-2 Relationship to GDPR FADP-5 Definitions (Article 5) UKGDPRREG-1 Subject Matter, Scope, Principles (Articles 1-11) OB-OPS.2 Performance Standards UK-TSA-NET-01 Security Architecture 15 U.S.C. § 78dd-2(h) Definition of Domestic Concern WCAGREC-3 Principle 3: Understandable SO2.2 Digital health architecture blueprint Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in CC - Common Criteria (Security) You are reading one control. How much of SOC 2 have you already done? SOC 2 SOC2-CC4.2 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of SOC 2 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 49 of 61 SOC 2 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 193 were rejected on the NIST SP 800-53 Rev 5 pair alone.
Query this from an agent The graph holds this control, the 328 it maps to, and the evidence behind each claim, over MCP and REST.