SOC 2 Type II
Version 2017
Service Organization Control 2 - Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy.
64
Total Controls
42
Implemented
12
In Progress
8
Not Started
2
Not Applicable
Overall Compliance66%
x
| Code | Title | Status | Owner | Last Reviewed |
|---|---|---|---|---|
| CC1.1 | COSO Principle 1: The entity demonstrates a commitment to integrity and ethical values | Implemented | Sarah Chen | 2026-03-15 |
| CC1.2 | COSO Principle 2: The board of directors demonstrates independence from management | Implemented | Sarah Chen | 2026-03-15 |
| CC1.3 | COSO Principle 3: Management establishes structures, reporting lines, and authorities | Implemented | Mike Johnson | 2026-03-10 |
| CC1.4 | COSO Principle 4: The entity demonstrates commitment to attract, develop, and retain competent individuals | In Progress | Lisa Park | 2026-02-28 |
| CC2.1 | COSO Principle 13: The entity obtains or generates and uses relevant, quality information | Implemented | Mike Johnson | 2026-03-12 |
| CC3.1 | COSO Principle 6: The entity specifies objectives with sufficient clarity to enable risk identification | In Progress | David Kim | 2026-02-20 |
| CC3.2 | COSO Principle 7: The entity identifies risks to the achievement of its objectives | Implemented | David Kim | 2026-03-08 |
| CC4.1 | COSO Principle 16: The entity selects, develops, and performs ongoing evaluations | In Progress | Sarah Chen | 2026-03-01 |
| CC5.1 | COSO Principle 10: The entity selects and develops control activities that mitigate risks | Implemented | Lisa Park | 2026-03-14 |
| CC5.2 | COSO Principle 11: The entity selects and develops general control activities over technology | Implemented | Mike Johnson | 2026-03-14 |
| CC6.1 | Logical and physical access controls: The entity implements logical access security software | Implemented | Alex Rivera | 2026-03-16 |
| CC6.2 | Prior to issuing system credentials, the entity registers and authorizes new users | In Progress | Alex Rivera | 2026-03-05 |
| CC6.3 | The entity authorizes, modifies, or removes access to data and assets based on roles | Implemented | Alex Rivera | 2026-03-16 |
| CC6.6 | The entity implements logical access security measures to protect against threats from outside | Implemented | Alex Rivera | 2026-03-16 |
| CC6.7 | The entity restricts the transmission, movement, and removal of information to authorized users | In Progress | Alex Rivera | 2026-02-25 |
| CC6.8 | The entity implements controls to prevent or detect and act upon introduction of unauthorized software | Not Started | Unassigned | - |
| CC7.1 | To meet its objectives, the entity uses detection and monitoring procedures | In Progress | David Kim | 2026-03-02 |
| CC7.2 | The entity monitors system components for anomalies indicative of malicious acts | Implemented | David Kim | 2026-03-13 |
| CC7.3 | The entity evaluates security events to determine whether they could represent incidents | In Progress | David Kim | 2026-02-18 |
| CC7.4 | The entity responds to identified security incidents by executing a defined response process | Not Started | Unassigned | - |
| CC8.1 | The entity authorizes, designs, develops, configures, documents, tests, and implements changes | Implemented | Lisa Park | 2026-03-11 |
| CC9.1 | The entity identifies, selects, and develops risk mitigation activities for risks | Not Started | Unassigned | - |
| A1.1 | The entity maintains, monitors, and evaluates current processing capacity and usage | Implemented | Mike Johnson | 2026-03-09 |
| A1.2 | The entity authorizes, designs, develops, or acquires, implements, operates, and monitors environmental protections | N/A | - | - |
| C1.1 | The entity identifies and maintains confidential information to meet the entity objectives | In Progress | Sarah Chen | 2026-03-03 |