Framework overlap

Does SOC 2 cover C5 (Germany)?

You hold SOC 2 and have been told to do C5 (Germany). Here is how much overlaps, control by control.

22% of C5 (Germany) you already have

SOC 2 already covers about 22% of C5 (Germany), leaving 94 of 121 controls as genuinely new work.

Already covered 27 Likely covered 0 New work 94

What is genuinely new work

Nothing in SOC 2 reaches these. This is the list to scope.

C5-AM-01
Asset Inventory
C5-AM-02
Acceptable Use and Safe Handling of Assets Policy
C5-AM-03
Commissioning of Hardware
C5-AM-04
Decommissioning of Hardware
C5-AM-05
Commitment to Permissible Use, Safe Handling and Return of Assets
C5-AM-06
Asset Classification and Labelling
C5-BCM-02
Business impact analysis policies and instructions
C5-BCM-03
Planning business continuity
C5-COM-01
Identification of applicable legal, regulatory, self-imposed or contractual requirements
C5-COM-02
Policy for planning and conducting audits
C5-COM-04
Information on information security performance and management assessment of the ISMS
C5-COS-02
Security requirements for connections in the Cloud Service Provider's network
C5-COS-03
Monitoring of connections in the Cloud Service Provider's network
C5-COS-04
Cross-network access
C5-COS-05
Networks for administration
C5-COS-06
Segregation of data traffic in jointly used network environments
C5-COS-07
Documentation of the network topology
C5-COS-08
Policies for data transmission
C5-CRY-02
Encryption of data for transmission (transport encryption)
C5-CRY-03
Encryption of sensitive data for storage
C5-CRY-04
Secure key management
C5-DEV-02
Outsourcing of the development
C5-DEV-04
Safety training and awareness programme regarding continuous software delivery and associated systems, components or tools
C5-DEV-05
Risk assessment, categorisation and prioritisation of changes
C5-DEV-06
Testing changes
C5-DEV-07
Logging of changes
C5-DEV-08
Version Control
C5-DEV-09
Approvals for provision in the production environment
C5-DEV-10
Separation of environments
C5-HR-01
Verification of qualification and trustworthiness
C5-HR-02
Employment terms and conditions
C5-HR-03
Security training and awareness programme
C5-HR-04
Disciplinary measures
C5-HR-05
Responsibilities in the event of termination or change of employment
C5-HR-06
Confidentiality agreements
C5-IDM-02
Granting and change of user accounts and access rights
C5-IDM-03
Locking and withdrawal of user accounts in the event of inactivity or multiple failed logins
C5-IDM-04
Withdraw or adjust access rights as the task area changes
C5-IDM-06
Privileged access rights
C5-IDM-07
Access to cloud customer data
C5-IDM-08
Confidentiality of authentication information
C5-INQ-01
Legal Assessment of Investigative Inquiries
C5-INQ-02
Informing Cloud Customers about Investigation Requests
C5-INQ-03
Conditions for Access to or Disclosure of Data in Investigation Requests
C5-INQ-04
Limiting Access to or Disclosure of Data in Investigation Requests
C5-OIS-03
Interfaces and Dependencies
C5-OIS-05
Contact with Relevant Government Agencies and Interest Groups
C5-OPS-02
Capacity Management - Monitoring
C5-OPS-03
Capacity Management - Controlling of Resources
C5-OPS-04
Protection Against Malware - Concept
C5-OPS-05
Protection Against Malware - Implementation
C5-OPS-07
Data Backup and Recovery - Monitoring
C5-OPS-08
Data Backup and Recovery - Regular Testing
C5-OPS-09
Data Backup and Recovery - Storage
C5-OPS-11
Logging and Monitoring - Metadata Management Concept
C5-OPS-12
Logging and Monitoring - Access, Storage and Deletion
C5-OPS-13
Logging and Monitoring - Identification of Events
C5-OPS-14
Logging and Monitoring - Storage of the Logging Data
C5-OPS-15
Logging and Monitoring - Accountability
C5-OPS-16
Logging and Monitoring - Configuration
C5-OPS-17
Logging and Monitoring - Availability of the Monitoring Software
C5-OPS-19
Managing Vulnerabilities, Malfunctions and Errors - Penetration Tests
C5-OPS-20
Managing Vulnerabilities, Malfunctions and Errors - Measurements, Analyses and Assessments of Procedures
C5-OPS-21
Involvement of Cloud Customers in the Event of Incidents
C5-OPS-22
Testing and Documentation of known Vulnerabilities
C5-OPS-23
Managing Vulnerabilities, Malfunctions and Errors - System Hardening
C5-OPS-24
Separation of Datasets in the Cloud Infrastructure
C5-PI-02
Contractual agreements for the provision of data
C5-PI-03
Secure deletion of data
C5-PS-01
Physical Security and Environmental Control Requirements
C5-PS-02
Redundancy model
C5-PS-03
Perimeter Protection
C5-PS-04
Physical site access control
C5-PS-05
Protection from fire and smoke
C5-PS-06
Protection against interruptions caused by power failures and other such risks
C5-PS-07
Surveillance of operational and environmental parameters
C5-PSS-01
Guidelines and Recommendations for Cloud Customers
C5-PSS-02
Identification of Vulnerabilities of the Cloud Service
C5-PSS-03
Online Register of Known Vulnerabilities
C5-PSS-04
Error handling and Logging Mechanisms
C5-PSS-06
Session Management
C5-PSS-07
Confidentiality of Authentication Information
C5-PSS-08
Roles and Rights Concept
C5-PSS-10
Software Defined Networking
C5-PSS-11
Images for Virtual Machines and Containers
C5-PSS-12
Locations of Data Processing and Storage
C5-SIM-04
Duty of the users to report security incidents to a central body
C5-SIM-05
Evaluation and learning process
C5-SP-02
Review and Approval of Policies and Instructions
C5-SP-03
Exceptions from Existing Policies and Instructions
C5-SSO-02
Risk assessment of service providers and suppliers
C5-SSO-03
Directory of service providers and suppliers
C5-SSO-04
Monitoring of compliance with requirements
C5-SSO-05
Exit strategy for the receipt of benefits
Show the 27 you already have
C5-BCM-01
Top management responsibility
C5-BCM-04
Verification, updating and testing of the business continuity
C5-COM-03
Internal audits of the information security management system
C5-COS-01
Technical safeguards
C5-CRY-01
Policy for the use of encryption procedures and key management
C5-DEV-01
Policies for the development/procurement of information systems
C5-DEV-03
Policies for changes to information systems
C5-IDM-01
Policy for user accounts and access rights
C5-IDM-05
Regular review of access rights
C5-IDM-09
Authentication mechanisms
C5-OIS-01
Information Security Management System (ISMS)
C5-OIS-02
Information Security Policy
C5-OIS-04
Segregation of Duties
C5-OIS-06
Risk Management Policy
C5-OIS-07
Application of the Risk Management Policy
C5-OPS-01
Capacity Management - Planning
C5-OPS-06
Data Backup and Recovery - Concept
C5-OPS-10
Logging and Monitoring - Concept
C5-OPS-18
Managing Vulnerabilities, Malfunctions and Errors - Concept
C5-PI-01
Documentation and safety of input and output interfaces
C5-PSS-05
Authentication Mechanisms
C5-PSS-09
Authorisation Mechanisms
C5-SIM-01
Policy for security incident management
C5-SIM-02
Processing of security incidents
C5-SIM-03
Documentation and reporting of security incidents
C5-SP-01
Documentation, communication and provision of policies and instructions
C5-SSO-01
Policies and instructions for controlling and monitoring third parties

How this is calculated

Already covered means a mapping runs from a control in SOC 2 to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition