24% of SOC 2 you already have
MTCS (Singapore) already covers about 24% of SOC 2, leaving
41 of 54 controls as genuinely new work.
Already covered 0
Likely covered 13
New work 41
No control in MTCS (Singapore)
maps directly to one in SOC 2. Everything counted as covered is covered because both
map to the same third standard, which is what a crosswalk is, but it is an inference rather
than a lookup.
What is genuinely new work
Nothing in MTCS (Singapore) reaches these. This is the list to scope.
SOC2-C1.1Confidential information is identified and protected during receipt, processing, storage
SOC2-C1.2Confidential information is disposed of securely
SOC2-CC1.1COSO principle 1: Demonstrates commitment to integrity and ethical values
SOC2-CC1.2COSO principle 2: Board exercises oversight responsibility
SOC2-CC1.3COSO principle 3: Management establishes structures, reporting lines, and authorities
SOC2-CC1.4COSO principle 4: Demonstrates commitment to attract and retain competent individuals
SOC2-CC1.5COSO principle 5: Holds individuals accountable for internal control responsibilities
SOC2-CC2.1COSO principle 13: Obtains and generates relevant, quality information
SOC2-CC2.2COSO principle 14: Internally communicates information including objectives and responsibilities
SOC2-CC2.3COSO principle 15: Communicates with external parties regarding matters affecting controls
SOC2-CC3.1COSO principle 6: Specifies objectives to identify and assess risks
SOC2-CC3.2COSO principle 7: Identifies risks and analyzes to determine how managed
SOC2-CC3.3COSO principle 8: Considers potential for fraud
SOC2-CC3.4COSO principle 9: Identifies and assesses changes that could impact internal controls
SOC2-CC4.1COSO principle 16: Selects and develops ongoing and separate evaluations
SOC2-CC5.1COSO principle 10: Selects and develops control activities to mitigate risks
SOC2-CC5.2COSO principle 11: Selects and develops general controls over technology
SOC2-CC5.3COSO principle 12: Deploys control activities through policies and procedures
SOC2-CC6.6Measures against threats outside system boundaries are implemented
SOC2-CC6.7Transmission of data is restricted to authorized users
SOC2-CC6.8Controls to prevent or detect unauthorized or malicious software
SOC2-CC7.1Detection and monitoring procedures for security events are in place
SOC2-CC7.2Monitors system components for anomalies indicating malicious acts
SOC2-CC7.3Evaluates security events to determine incident status
SOC2-CC9.1Identifies, selects and develops risk mitigation activities
SOC2-CC9.2Risk mitigation activities include assessment of vendor and business partner controls
SOC2-P1.1Privacy notice provides clear notice about privacy practices
SOC2-P2.1Consent is obtained for the collection, use, and disclosure of personal information
SOC2-P3.2Explicit consent is obtained for sensitive personal information
SOC2-P4.1Personal information is used for purposes identified in privacy commitments
SOC2-P4.2Personal information is retained for only as long as needed
SOC2-P5.1Personal information is accessed only by authorized personnel
SOC2-P5.2Corrections to personal information are processed timely
SOC2-P6.2Records of personal information disclosures are maintained
SOC2-P7.1Personal information collected is limited to what is necessary and relevant
SOC2-P8.1Inquiries, complaints, and disputes regarding personal information are addressed
SOC2-PI1.1Obtains or generates and uses relevant quality information to support processing integrity
SOC2-PI1.2System inputs are complete, accurate, and processed in a timely manner
SOC2-PI1.3System processing is complete, valid, accurate, timely, and authorized
SOC2-PI1.4System outputs are complete, valid, accurate, timely, and distributed
SOC2-PI1.5Inputs are processed completely, accurately, and timely for stored data
Show the 13 you already have
SOC2-A1.1Maintains capacity to meet availability commitments
SOC2-A1.2Environmental protections, data backups, and recovery infrastructure support availability
SOC2-A1.3Recovery plan procedures support system recovery from failures
SOC2-CC4.2COSO principle 17: Evaluates and communicates deficiencies in a timely manner
SOC2-CC6.1Logical and physical access security for information and assets
SOC2-CC6.2Prior to granting access, registration and authorization processes are established
SOC2-CC6.3Role-based access and least privilege are enforced
SOC2-CC7.4Responds to identified security incidents through defined procedures
SOC2-CC7.5Identifies the root cause of security incidents
SOC2-CC8.1Change management processes are in place
SOC2-P3.1Personal information is collected consistent with privacy commitments
SOC2-P4.3Personal information is securely disposed of
SOC2-P6.1Personal information is disclosed to third parties only as committed
How this is calculated
Already covered means a mapping runs from a control in MTCS (Singapore) to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition