SOC 2
CC - Common Criteria (Security)

SOC 2 SOC2-CC4.2: CC4.2 Evaluating and communicating control deficiencies (COSO principle 17)

Control deficiencies are evaluated and reported promptly to those who must fix them, including senior management and the board where appropriate. Points of focus: management and the board assess the results of evaluations; deficiencies go to the parties responsible for correction and upward as appropriate; and management tracks whether they are remedied on time.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 328 controls across 119 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

PCI DSS 4.0 · 16 controls

  • 10.4.3 10.4.3 Exceptions and anomalies from log review addressed
  • 11.3.1.1 11.3.1.1 Lower-risk vulnerabilities handled per risk analysis
  • 11.4.4 11.4.4 Correct exploitable findings from penetration tests
  • 12.1.2 12.1.2 Security policy reviewed annually and updated as needed
  • 12.10.6 12.10.6 Plan evolved from lessons learned and industry developments
  • 12.4.2 12.4.2 Quarterly reviews that personnel follow security procedures
  • 12.4.2.1 12.4.2.1 Documentation of quarterly operational reviews
  • 12.6.1 12.6.1 Formal security awareness program
  • 2.1.1 2.1.1 Requirement 2 policies and procedures governed
  • 2.2.2 2.2.2 Vendor default accounts managed
  • 4.1.1 4.1.1 Requirement 4 policies and procedures maintained and communicated
  • 6.1.1 6.1.1 Requirement 6 policies and procedures maintained and communicated
  • 6.2.3.1 6.2.3.1 Manual code review independence and approval
  • 7.1.1 7.1.1 Requirement 7 policies and procedures maintained
  • 9.1.1 9.1.1 Requirement 9 policies and procedures maintained
  • 8.1.1 8.1.1 Requirement 8 policies and procedures maintained
  • NIST-CSF-DE.AE-06 Information on adverse events is provided to authorized staff and tools
  • NIST-CSF-DE.AE-08 Incidents are declared when adverse events meet the defined incident criteria
  • NIST-CSF-GV.OV-01 Cybersecurity risk management strategy outcomes are reviewed to inform and adjust strategy and direction
  • NIST-CSF-GV.OV-02 The cybersecurity risk management strategy is reviewed and adjusted to ensure coverage of organizational requirements and risks
  • NIST-CSF-GV.OV-03 Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed
  • NIST-CSF-GV.PO-02 Policy for managing cybersecurity risks is reviewed, updated, communicated, and enforced to reflect changes in requirements, threats, technology, and organizational mission
  • NIST-CSF-GV.RM-07 Strategic opportunities (i.e., positive risks) are characterized and are included in organizational cybersecurity risk discussions
  • NIST-CSF-ID.IM-02 Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties
  • NIST-CSF-ID.IM-03 Improvements are identified from execution of operational processes, procedures, and activities
  • NIST-CSF-ID.RA-06 Risk responses are chosen, prioritized, planned, tracked, and communicated
  • NIST-CSF-ID.RA-08 Processes for receiving, analyzing, and responding to vulnerability disclosures are established
  • NIST-CSF-ID.RA-09 The authenticity and integrity of hardware and software are assessed prior to acquisition and use
  • NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
  • NIST-CSF-RS.CO-02 Internal and external stakeholders are notified of incidents

NIST SP 800-53 Rev 5 · 11 controls

ISO 27701:2019 · 10 controls

  • 5.5.5 Documented information
  • 5.7 Performance evaluation
  • 5.7.2 Internal audit
  • 5.7.3 Management review
  • 5.8 Improvement
  • 5.8.1 Nonconformity and corrective action
  • 5.8.2 Continual improvement
  • 6.13.1 Management of information security incidents and improvements
  • 6.15.2 Information security reviews
  • 6.3 Organization of information security

ISO 22301:2019 · 9 controls

  • 10.1 Nonconformity and corrective action
  • 10.2 Continual improvement
  • 7.5 Documented information
  • 8.3.1 General
  • 9.2 Internal audit
  • 9.2.2 Audit programme(s)
  • 9.3 Management review
  • 9.3.2 Management review input
  • 9.3.3 Management review outputs

ISO 27002:2022 · 9 controls

  • 5.1 Policies for information security
  • 5.22 Monitoring, review and change management of supplier services
  • 5.25 Assessment and decision on information security events
  • 5.26 Response to information security incidents
  • 5.27 Learning from information security incidents
  • 5.35 Independent review of information security
  • 5.36 Compliance with policies, rules and standards for information security
  • 5.4 Management responsibilities
  • 8.16 Monitoring activities

CIS Controls v8 · 8 controls

  • CIS-14.7 Train Workforce on How to Identify and Report if Their Enterprise Assets are Missing Security Updates
  • CIS-16.2 Establish and Maintain a Process to Accept and Address Software Vulnerabilities
  • CIS-17.4 Establish and Maintain an Incident Response Process
  • CIS-17.8 Conduct Post-Incident Reviews
  • CIS-18.3 Remediate Penetration Test Findings
  • CIS-7.2 Establish and Maintain a Remediation Process
  • CIS-7.7 Remediate Detected Vulnerabilities
  • CIS-8.11 Conduct Audit Log Reviews

FedRAMP High · 7 controls

  • CA-1 Policy and Procedures
  • CA-2 Control Assessments
  • CA-5 Plan of Action and Milestones
  • CA-9 Internal System Connections
  • PL-1 Policy and Procedures
  • SI-2(3) Flaw Remediation | Time to Remediate Flaws and Benchmarks for Corrective Actions (SI-2(3))
  • SR-1 Policy and Procedures (SR-1)

FedRAMP Moderate · 7 controls

  • CA-1 Policy and Procedures
  • CA-2 Control Assessments
  • CA-5 Plan of Action and Milestones
  • CA-9 Internal System Connections
  • PL-1 Policy and Procedures
  • SI-2(3) Flaw Remediation | Time to Remediate Flaws and Benchmarks for Corrective Actions (SI-2(3))
  • SR-1 Policy and Procedures (SR-1)

ISO 27001:2022 · 7 controls

  • 5.22 Monitoring, review and change management of supplier services
  • 5.25 Assessment and decision on information security events
  • 5.26 Response to information security incidents
  • 5.27 Learning from information security incidents
  • 5.35 Independent review of information security
  • 5.36 Compliance with policies, rules and standards for information security
  • 8.16 Monitoring activities

ISO/IEC 42001:2023 · 7 controls

  • 10.1 Continual improvement
  • 10.2 Nonconformity and corrective action
  • 4.4 AI management system
  • 7.4 Communication
  • 8.2 AI risk assessment
  • 9.3 Management review
  • 9.3.2 Management review inputs

CMMC 2.0 · 5 controls

  • CPS220-11 Annual Audit Review of the Framework
  • CPS220-16 Management Information System and Data Framework
  • CPS220-19 APRA Notification of Framework Breach within 10 Business Days
  • CPS220-P50 Qualification of the Risk Management Declaration

C5 (Germany) · 3 controls

  • C5-COM-03 Internal audits of the information security management system
  • C5-COM-04 Information on information security performance and management assessment of the ISMS
  • C5-OPS-20 Managing Vulnerabilities, Malfunctions and Errors - Measurements, Analyses and Assessments of Procedures
  • DA-1 Enterprise Data Architecture
  • DIQ-2 Data Quality Management
  • RMD-1 Reference Data Management

DORA · 3 controls

HIPAA Security Rule · 3 controls

  • IEC62304-5.2 Software Requirements Analysis
  • IEC62304-5.3 Software Architectural Design
  • IEC62304-7.2 Risk Control Measures
  • ISO-15189-5.1 Legal entity
  • ISO-15189-5.4 Structure and authority
  • ISO-15189-6.7 Service agreements
  • ISO-19650-1-4 Information management concepts
  • ISO-19650-1-7 Common Data Environment (CDE) concept
  • ISO-19650-3-5.3 Trigger events for information exchange

ISO 22320:2018 · 3 controls

  • ISO-22320-5.1 General process requirements
  • ISO-22320-5.3 Incident management structure (command)
  • ISO-22320-5.4 Roles and responsibilities

ISO/IEC 23894:2023 · 3 controls

  • ISO23894-1 Scope of AI Risk Management
  • ISO23894-3 AI-Specific Terminology
  • ISO23894-6.2 Scope, Context and Criteria

ISO/IEC 27004:2016 · 3 controls

  • 27004-3 Terms and definitions
  • 27004-A.2 Patching and Vulnerability Measures
  • 27004-B.1 Example measurement definitions
  • 27557-1 Scope
  • 27557-3 Terms and definitions
  • 27557-6.2 Scope, context, and criteria for privacy

ISO/IEC 29100:2024 · 3 controls

  • 29100-1 Scope
  • 29100-3 Terms and definitions
  • 29100-4.1 Actors and roles

NIS2 Directive · 3 controls

  • Art.20.1 Management body approves the cybersecurity risk-management measures and oversees their implementation
  • Art.21.2.f Policies and procedures to assess the effectiveness of the cybersecurity risk-management measures
  • Art.21.4 Take corrective measures without undue delay on finding that the measures are not met

NIST SP 800-66 Rev 2 · 3 controls

  • TRINIDAD-1 Scope, Definitions, Commission
  • TRINIDAD-2 Lawful Processing and Consent
  • TRINIDAD-3 Data Subject Rights
  • 58.1 Scope
  • 58.3 Definitions
  • CPS230-P30 Monitoring, Review and Testing of Control Effectiveness
  • CPS230-P31 Remediation of Material Operational Risk Weaknesses

APRA CPS 234 · 2 controls

  • CPS234-28 Escalation of Unremediated Testing Deficiencies
  • CPS234-36 APRA Notification of Material Control Weakness within 10 Business Days
  • AL-DPA-1 Scope and Definitions
  • AL-DPA-3 Lawful Basis for Processing
  • AT-DSG-2 Section 2 - Scope and application
  • AT-DSG-8 Section 22 - Functions and powers of the DPA
  • MLE.1 Machine Learning Requirements Analysis
  • MLE.3 Machine Learning Training
  • CFTC-SS-21 Remediation of Vulnerabilities and Deficiencies
  • CFTC-SS-36 Internal Reporting and Review by Senior Management and the Board

FedRAMP Rev 5 · 2 controls

  • FEDRAMP-CM-6 Configuration Settings
  • FEDRAMP-CP-9 System Backup
  • FDBR-702 Definitions (§501.702)
  • FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704)
  • 60601-1.3 Terminology and definitions
  • 60601-1.4.1 General requirements
  • ISO-20400-4.2 Principles of sustainable procurement
  • ISO-20400-7.2 Integrating sustainability into specifications
  • ISO-41001-4.1 Understanding the organization and its context
  • ISO-41001-4.3 Determining the scope of the FM management system

ISO 56002 · 2 controls

  • ISO-56002-4.3 Determining the scope of the innovation management system
  • ISO-56002-8.3.4 Develop solutions
  • ISO8000-DQM-02 Data Quality Dimensions
  • ISO8000-MDG-03 Continuous Improvement
  • ISO-17025-5.1 Legal entity
  • ISO-17025-5.4 Personnel for the management system
  • ISO-25012-5.2 Defining data quality measures
  • ISO-25012-5.3 Planning and performing data quality evaluations

ISO/IEC 27011:2024 · 2 controls

  • 27011-1 Scope
  • 27011-3 Terms and definitions

ISO/IEC 27014:2020 · 2 controls

  • 27014-1 Scope
  • 27014-3 Terms and definitions

ISO/IEC 29147:2018 · 2 controls

  • 29147-3 Terms and definitions
  • 29147-9.2 Contact mechanisms and scope

ISO/IEC 30111:2019 · 2 controls

  • 30111-3 Terms and definitions
  • 30111-5.1 Organizational policy
  • STANAG-1 STANAG 4774 Confidentiality Label Schema and XML Structure
  • STANAG-2 STANAG 4778 Metadata Binding Mechanism and Cryptographic Binding

NIST SP 800-171 Rev 3 · 2 controls

NIST SP 800-218 · 2 controls

  • 53A-3.4 Analyze Assessment Report Results
  • 53A-E Assessment Reports
  • NDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal
  • NDPA-5 Privacy Notice, Data Minimisation, and Purpose Limitation
  • PICERL-P2 Risk Assessment
  • PICERL-P3 CSIRT Formation
  • SSAE18-CC7.4 CC7.4 - Incident Response
  • SSAE18-PI1.1 PI1.1 - Processing Integrity Definition
  • C1 Organizational Boundary
  • C3 Scope 1 and 2 Coverage
  • TANZANIA-1 Scope, Registration, Lawful Basis
  • TANZANIA-4 Security and Cross-Border

UK Bribery Act 2010 · 2 controls

  • Section 6(5) Definition of Foreign Public Official
  • Section 8 Definition of Associated Person
  • US-SEC-DA-SC-01 Howey Test Application
  • US-SEC-DA-SC-02 Registration Requirements
  • CFR211-A-3 Section 211.3 - Definitions

AICPA SOC 3 · 1 control

  • SOC3-MONITORING Monitoring Controls
  • ANSSI-HYG-38 Carry Out Regular Security Checks and Audits and Apply the Corrective Actions
  • 4.4.1 Resources, Roles, Responsibility, and Authority
  • SEC04-BP04 Initiate remediation for non-compliant resources
  • AUCDR-IS-STEP4 Step 4 - Implement a formal controls assessment program
  • AEO-13 Measurement, Analyses and Improvement
  • AZ-DPA-2 Article 2 - Basic Concepts
  • CPG-6.B Supply Chain Incident Reporting

COBIT 2019 · 1 control

  • COBIT-BAI02 Managed requirements definition
  • CTDPA-1 Definitions

EU AI Act · 1 control

  • FFIEC-05 Roles and responsibilities definition
  • FTC-Safeguards-Scope-Defs Scope, Definitions and Financial Institution Applicability (16 CFR 314.1, 314.2)

GDPR · 1 control

  • ICP-1 Objectives, Powers and Responsibilities of the Supervisor
  • 62351-2 Glossary of terms
  • ISO-14064-1-5.1 Organizational boundaries
  • ISO-26262-3-5 Item definition
  • ISO28001-PI-01 Personnel Security Screening

ISO/IEC 23837:2023 · 1 control

  • 23837-1.1 Scope

ISO/IEC 27003:2017 · 1 control

  • ISO27003-4.3 Determining the scope of the information security management system

ISO/IEC 27007:2020 · 1 control

  • 27007-5.2 Audit Programme Objectives

ISO/IEC 27031:2011 · 1 control

  • 27031-5.1 IRBC Policy

ISO/IEC 27043:2015 · 1 control

  • ISO27043-04 Roles and responsibilities definition
  • 27050-1.4 Terms and definitions

ISO/IEC 27400:2022 · 1 control

  • 27400-3 Terms and definitions
  • 29115-3 Terms and definitions

ISO/IEC 29134:2023 · 1 control

  • 29134-3 Terms and definitions

ISO/SAE 21434 · 1 control

  • ISO21434-04 Roles and responsibilities definition
  • BIPA-SEC5-1 Biometric Identifier Definition

NIST SP 800-172 · 1 control

  • 3.11.5e Assess Effectiveness of Security Solutions

NIST SP 800-190 · 1 control

PCI P2PE · 1 control

  • PCI-P2PE-05 Roles and responsibilities definition

PCI PIN Security · 1 control

  • PCI-PIN-05 Roles and responsibilities definition

PCI SSF · 1 control

  • PCI-SSF-05 Roles and responsibilities definition
  • RIDTPPA-1 Scope, Applicability, Definitions
  • SCA-S2 Interpretation and Definitions

South Korea ISMS-P · 1 control

  • ISMSP-SYS-04 Vulnerability Management
  • SWE-2 Relationship to GDPR
  • UKGDPRREG-1 Subject Matter, Scope, Principles (Articles 1-11)
  • OB-OPS.2 Performance Standards
  • UK-TSA-NET-01 Security Architecture
  • 15 U.S.C. § 78dd-2(h) Definition of Domestic Concern

WCAG 2.2 · 1 control

  • WCAGREC-3 Principle 3: Understandable
  • SO2.2 Digital health architecture blueprint

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in CC - Common Criteria (Security)

You are reading one control. How much of SOC 2 have you already done?

SOC 2 SOC2-CC4.2 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of SOC 2 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 49 of 61 SOC 2 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 193 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 328 it maps to, and the evidence behind each claim, over MCP and REST.