Disclaimer: An independent concept study by Kaushal Khodifad. Not affiliated with GoRico. Built from public sources; figures are illustrative.return to portfolio
Disclaimer: An independent concept study by Kaushal Khodifad. Not affiliated with GoRico.
TechCorp Solutions
3 Active Programs
TC

SOC 2 Type II

Version 2017

Service Organization Control 2 - Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy.

64

Total Controls

42

Implemented

12

In Progress

8

Not Started

2

Not Applicable

Overall Compliance66%
x
CodeTitleStatusOwnerLast Reviewed
CC1.1COSO Principle 1: The entity demonstrates a commitment to integrity and ethical valuesImplementedSarah Chen2026-03-15
CC1.2COSO Principle 2: The board of directors demonstrates independence from managementImplementedSarah Chen2026-03-15
CC1.3COSO Principle 3: Management establishes structures, reporting lines, and authoritiesImplementedMike Johnson2026-03-10
CC1.4COSO Principle 4: The entity demonstrates commitment to attract, develop, and retain competent individualsIn ProgressLisa Park2026-02-28
CC2.1COSO Principle 13: The entity obtains or generates and uses relevant, quality informationImplementedMike Johnson2026-03-12
CC3.1COSO Principle 6: The entity specifies objectives with sufficient clarity to enable risk identificationIn ProgressDavid Kim2026-02-20
CC3.2COSO Principle 7: The entity identifies risks to the achievement of its objectivesImplementedDavid Kim2026-03-08
CC4.1COSO Principle 16: The entity selects, develops, and performs ongoing evaluationsIn ProgressSarah Chen2026-03-01
CC5.1COSO Principle 10: The entity selects and develops control activities that mitigate risksImplementedLisa Park2026-03-14
CC5.2COSO Principle 11: The entity selects and develops general control activities over technologyImplementedMike Johnson2026-03-14
CC6.1Logical and physical access controls: The entity implements logical access security softwareImplementedAlex Rivera2026-03-16
CC6.2Prior to issuing system credentials, the entity registers and authorizes new usersIn ProgressAlex Rivera2026-03-05
CC6.3The entity authorizes, modifies, or removes access to data and assets based on rolesImplementedAlex Rivera2026-03-16
CC6.6The entity implements logical access security measures to protect against threats from outsideImplementedAlex Rivera2026-03-16
CC6.7The entity restricts the transmission, movement, and removal of information to authorized usersIn ProgressAlex Rivera2026-02-25
CC6.8The entity implements controls to prevent or detect and act upon introduction of unauthorized softwareNot StartedUnassigned-
CC7.1To meet its objectives, the entity uses detection and monitoring proceduresIn ProgressDavid Kim2026-03-02
CC7.2The entity monitors system components for anomalies indicative of malicious actsImplementedDavid Kim2026-03-13
CC7.3The entity evaluates security events to determine whether they could represent incidentsIn ProgressDavid Kim2026-02-18
CC7.4The entity responds to identified security incidents by executing a defined response processNot StartedUnassigned-
CC8.1The entity authorizes, designs, develops, configures, documents, tests, and implements changesImplementedLisa Park2026-03-11
CC9.1The entity identifies, selects, and develops risk mitigation activities for risksNot StartedUnassigned-
A1.1The entity maintains, monitors, and evaluates current processing capacity and usageImplementedMike Johnson2026-03-09
A1.2The entity authorizes, designs, develops, or acquires, implements, operates, and monitors environmental protectionsN/A--
C1.1The entity identifies and maintains confidential information to meet the entity objectivesIn ProgressSarah Chen2026-03-03

↑ An independent concept study by Kaushal Khodifad. GoRico is a real company in the GRC & compliance automation space; the design and the working prototype above were built independently. Not affiliated with, endorsed by, or representative of GoRico's actual product. Data is from public sources. Figures are estimates.

Return to portfolioOpen the live demo