SOC 2
P - Privacy

SOC 2 SOC2-P6.2: P6.2 Record of authorised disclosures

A full, correct and up-to-date log of authorised disclosures of personal information is created and kept. Point of focus: the record of authorised disclosures is maintained completely, accurately and promptly.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 61 controls across 21 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27701:2019 · 14 controls

  • 5.5.5 Documented information
  • 6.12 Supplier relationships
  • 6.12.1 Information security in supplier relationships
  • 6.9.7 Information systems audit considerations
  • 7.2.7 Joint PII controller
  • 7.2.8 Records related to processing PII
  • 7.5 PII sharing, transfer, and disclosure
  • 7.5.3 Records of transfer of PII
  • 7.5.4 Records of PII disclosure to third parties
  • 8.2.6 Records related to processing PII
  • 8.5 PII sharing, transfer, and disclosure
  • 8.5.3 Records of PII disclosure to third parties
  • 8.5.5 Legally binding PII disclosures
  • 8.5.6 Disclosure of subcontractors used to process PII
  • NIST-CSF-DE.AE-02 Potentially adverse events are analyzed to better understand associated activities
  • NIST-CSF-DE.CM-03 Personnel activity and technology usage are monitored to find potentially adverse events
  • NIST-CSF-ID.AM-04 Inventories of services provided by suppliers are maintained
  • NIST-CSF-RS.AN-07 Incident data and metadata are collected, and their integrity and provenance are preserved
  • NIST-CSF-RS.CO-03 Information is shared with designated internal and external stakeholders

ISO 27001:2022 · 4 controls

  • 5.31 Legal, statutory, regulatory and contractual requirements
  • 5.33 Protection of records
  • 5.34 Privacy and protection of personal identifiable information (PII)
  • 8.15 Logging

ISO 27002:2022 · 4 controls

  • 5.28 Collection of evidence
  • 5.33 Protection of records
  • 5.34 Privacy and protection of PII
  • 8.15 Logging

NIST SP 800-53 Rev 5 · 4 controls

PCI DSS 4.0 · 3 controls

  • 12.8.1 12.8.1 List of third-party service providers
  • 9.3.4 9.3.4 Visitor logs for facility and sensitive areas
  • 9.4.5 9.4.5 Inventory logs of electronic media

APPI · 2 controls

  • APPI-A29 Records When Providing Personal Data to a Third Party
  • APPI-A30 Confirmation and Records When Receiving Personal Data from a Third Party
  • MYHR-SBD-3 Record keeping for sharing with the My Health Record system
  • MYHR-SEC-3 Audit logging and access monitoring

C5 (Germany) · 2 controls

  • C5-INQ-01 Legal Assessment of Investigative Inquiries
  • C5-INQ-02 Informing Cloud Customers about Investigation Requests

CIS Controls v8 · 2 controls

  • CIS-3.2 Establish and Maintain a Data Inventory
  • CIS-3.8 Document Data Flows

FedRAMP High · 2 controls

  • AC-21 Information Sharing
  • PE-8 Visitor Access Records

FedRAMP Moderate · 2 controls

  • AC-21 Information Sharing
  • PE-8 Visitor Access Records

GDPR · 2 controls

  • GDPR-Art.19 Notification obligation regarding rectification, erasure or restriction
  • GDPR-Art.30 Records of processing activities

HIPAA Security Rule · 2 controls

NIST SP 800-66 Rev 2 · 2 controls

  • AUCDR-PS-10 Privacy Safeguard 10 - Notifying of the disclosure of CDR data

CCPA/CPRA · 1 control

  • §1798.115 Right to Know Personal Information Sold or Shared and Recipients

ISO/IEC 42001:2023 · 1 control

  • A.5.3 Documentation of AI system impact assessments

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in P - Privacy

You are reading one control. How much of SOC 2 have you already done?

SOC 2 SOC2-P6.2 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of SOC 2 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 49 of 61 SOC 2 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 193 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 61 it maps to, and the evidence behind each claim, over MCP and REST.