SOC 2
PI - Processing Integrity

SOC 2 SOC2-PI1.4: PI1.4 Controls over output delivery

Policies and procedures make output available or deliver it completely, accurately and on time in line with specifications. Points of focus: stored or delivered output is protected against theft, destruction, corruption or deterioration; it goes only to intended parties; completeness, accuracy and timeliness of distribution are provided for; and records of output activity are created and kept.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 34 controls across 10 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 7 controls

FedRAMP High · 5 controls

  • AU-12 Audit Record Generation
  • CP-10 System Recovery and Reconstitution
  • CP-9 System Backup
  • SC-45 System Time Synchronization (SC-45)
  • SI-11 Error Handling

FedRAMP Moderate · 5 controls

  • AU-12 Audit Record Generation
  • CP-10 System Recovery and Reconstitution
  • CP-9 System Backup
  • SC-45 System Time Synchronization (SC-45)
  • SI-11 Error Handling

ISO 27002:2022 · 5 controls

  • 5.14 Information transfer
  • 5.36 Compliance with policies, rules and standards for information security
  • 8.13 Information backup
  • 8.16 Monitoring activities
  • 8.26 Application security requirements

ISO 27701:2019 · 5 controls

  • 5.6.1 Operational planning and control
  • 6.10.2 Information transfer
  • 6.11.1 Security requirements of information systems
  • 6.9.1 Operational procedures and responsibilities
  • 7.4.3 Accuracy and quality
  • CCM-AIS-02 Application Security Baseline Requirements
  • CCM-AIS-04 Secure Application Design and Development

EU AI Act · 2 controls

  • EUAI-Art.13 Transparency and provision of information to deployers
  • EUAI-Art.15 Accuracy, robustness and cybersecurity

C5 (Germany) · 1 control

  • C5-PI-01 Documentation and safety of input and output interfaces

ISO 27001:2022 · 1 control

  • 5.37 Documented operating procedures

ISO/IEC 42001:2023 · 1 control

  • A.8.2 System documentation and information for users

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in PI - Processing Integrity

You are reading one control. How much of SOC 2 have you already done?

SOC 2 SOC2-PI1.4 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of SOC 2 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 49 of 61 SOC 2 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 193 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 34 it maps to, and the evidence behind each claim, over MCP and REST.