Identified and authenticated data subjects can see their stored personal information and, on request, receive physical or electronic copies; if access is denied they are told why, as objectives require. Points of focus: identity is authenticated before access is given; people can find out whether information about them is held and obtain it; it is provided in an understandable form, in reasonable time and at reasonable cost; and denials are explained promptly unless law prohibits it. The 2022 revision adds, for data processors, a process to act on data subject requests passed on by data controllers under the service agreement, including authenticating them, giving access where appropriate, answering in reasonable time and notifying any denial.
This control maps to 82 controls across 21 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
You are reading one control. How much of SOC 2 have you already done?
SOC 2 SOC2-P5.1 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of SOC 2 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 49 of 61 SOC 2 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 193 were rejected on the NIST SP 800-53 Rev 5 pair alone.