17% of SOC 2 you already have
ISO 27001:2022 already covers about 17% of SOC 2, leaving
45 of 54 controls as genuinely new work.
Already covered 0
Likely covered 9
New work 45
No control in ISO 27001:2022
maps directly to one in SOC 2. Everything counted as covered is covered because both
map to the same third standard, which is what a crosswalk is, but it is an inference rather
than a lookup.
What is genuinely new work
Nothing in ISO 27001:2022 reaches these. This is the list to scope.
SOC2-A1.1Maintains capacity to meet availability commitments
SOC2-C1.2Confidential information is disposed of securely
SOC2-CC1.1COSO principle 1: Demonstrates commitment to integrity and ethical values
SOC2-CC1.2COSO principle 2: Board exercises oversight responsibility
SOC2-CC1.3COSO principle 3: Management establishes structures, reporting lines, and authorities
SOC2-CC1.4COSO principle 4: Demonstrates commitment to attract and retain competent individuals
SOC2-CC1.5COSO principle 5: Holds individuals accountable for internal control responsibilities
SOC2-CC2.1COSO principle 13: Obtains and generates relevant, quality information
SOC2-CC2.2COSO principle 14: Internally communicates information including objectives and responsibilities
SOC2-CC2.3COSO principle 15: Communicates with external parties regarding matters affecting controls
SOC2-CC3.1COSO principle 6: Specifies objectives to identify and assess risks
SOC2-CC3.2COSO principle 7: Identifies risks and analyzes to determine how managed
SOC2-CC3.3COSO principle 8: Considers potential for fraud
SOC2-CC3.4COSO principle 9: Identifies and assesses changes that could impact internal controls
SOC2-CC4.1COSO principle 16: Selects and develops ongoing and separate evaluations
SOC2-CC4.2COSO principle 17: Evaluates and communicates deficiencies in a timely manner
SOC2-CC5.2COSO principle 11: Selects and develops general controls over technology
SOC2-CC5.3COSO principle 12: Deploys control activities through policies and procedures
SOC2-CC6.2Prior to granting access, registration and authorization processes are established
SOC2-CC6.6Measures against threats outside system boundaries are implemented
SOC2-CC6.7Transmission of data is restricted to authorized users
SOC2-CC6.8Controls to prevent or detect unauthorized or malicious software
SOC2-CC7.1Detection and monitoring procedures for security events are in place
SOC2-CC7.2Monitors system components for anomalies indicating malicious acts
SOC2-CC7.3Evaluates security events to determine incident status
SOC2-CC7.4Responds to identified security incidents through defined procedures
SOC2-CC7.5Identifies the root cause of security incidents
SOC2-CC8.1Change management processes are in place
SOC2-CC9.1Identifies, selects and develops risk mitigation activities
SOC2-CC9.2Risk mitigation activities include assessment of vendor and business partner controls
SOC2-P1.1Privacy notice provides clear notice about privacy practices
SOC2-P2.1Consent is obtained for the collection, use, and disclosure of personal information
SOC2-P3.2Explicit consent is obtained for sensitive personal information
SOC2-P4.1Personal information is used for purposes identified in privacy commitments
SOC2-P4.2Personal information is retained for only as long as needed
SOC2-P5.1Personal information is accessed only by authorized personnel
SOC2-P5.2Corrections to personal information are processed timely
SOC2-P6.2Records of personal information disclosures are maintained
SOC2-P7.1Personal information collected is limited to what is necessary and relevant
SOC2-P8.1Inquiries, complaints, and disputes regarding personal information are addressed
SOC2-PI1.1Obtains or generates and uses relevant quality information to support processing integrity
SOC2-PI1.2System inputs are complete, accurate, and processed in a timely manner
SOC2-PI1.3System processing is complete, valid, accurate, timely, and authorized
SOC2-PI1.4System outputs are complete, valid, accurate, timely, and distributed
SOC2-PI1.5Inputs are processed completely, accurately, and timely for stored data
Show the 9 you already have
SOC2-A1.2Environmental protections, data backups, and recovery infrastructure support availability
SOC2-A1.3Recovery plan procedures support system recovery from failures
SOC2-C1.1Confidential information is identified and protected during receipt, processing, storage
SOC2-CC5.1COSO principle 10: Selects and develops control activities to mitigate risks
SOC2-CC6.1Logical and physical access security for information and assets
SOC2-CC6.3Role-based access and least privilege are enforced
SOC2-P3.1Personal information is collected consistent with privacy commitments
SOC2-P4.3Personal information is securely disposed of
SOC2-P6.1Personal information is disclosed to third parties only as committed
How this is calculated
Already covered means a mapping runs from a control in ISO 27001:2022 to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition