22% of C5 (Germany) you already have
SOC 2 already covers about 22% of C5 (Germany), leaving
94 of 121 controls as genuinely new work.
Already covered 27
Likely covered 0
New work 94
What is genuinely new work
Nothing in SOC 2 reaches these. This is the list to scope.
C5-AM-02Acceptable Use and Safe Handling of Assets Policy
C5-AM-03Commissioning of Hardware
C5-AM-04Decommissioning of Hardware
C5-AM-05Commitment to Permissible Use, Safe Handling and Return of Assets
C5-AM-06Asset Classification and Labelling
C5-BCM-02Business impact analysis policies and instructions
C5-BCM-03Planning business continuity
C5-COM-01Identification of applicable legal, regulatory, self-imposed or contractual requirements
C5-COM-02Policy for planning and conducting audits
C5-COM-04Information on information security performance and management assessment of the ISMS
C5-COS-02Security requirements for connections in the Cloud Service Provider's network
C5-COS-03Monitoring of connections in the Cloud Service Provider's network
C5-COS-04Cross-network access
C5-COS-05Networks for administration
C5-COS-06Segregation of data traffic in jointly used network environments
C5-COS-07Documentation of the network topology
C5-COS-08Policies for data transmission
C5-CRY-02Encryption of data for transmission (transport encryption)
C5-CRY-03Encryption of sensitive data for storage
C5-CRY-04Secure key management
C5-DEV-02Outsourcing of the development
C5-DEV-04Safety training and awareness programme regarding continuous software delivery and associated systems, components or tools
C5-DEV-05Risk assessment, categorisation and prioritisation of changes
C5-DEV-07Logging of changes
C5-DEV-09Approvals for provision in the production environment
C5-DEV-10Separation of environments
C5-HR-01Verification of qualification and trustworthiness
C5-HR-02Employment terms and conditions
C5-HR-03Security training and awareness programme
C5-HR-04Disciplinary measures
C5-HR-05Responsibilities in the event of termination or change of employment
C5-HR-06Confidentiality agreements
C5-IDM-02Granting and change of user accounts and access rights
C5-IDM-03Locking and withdrawal of user accounts in the event of inactivity or multiple failed logins
C5-IDM-04Withdraw or adjust access rights as the task area changes
C5-IDM-06Privileged access rights
C5-IDM-07Access to cloud customer data
C5-IDM-08Confidentiality of authentication information
C5-INQ-01Legal Assessment of Investigative Inquiries
C5-INQ-02Informing Cloud Customers about Investigation Requests
C5-INQ-03Conditions for Access to or Disclosure of Data in Investigation Requests
C5-INQ-04Limiting Access to or Disclosure of Data in Investigation Requests
C5-OIS-03Interfaces and Dependencies
C5-OIS-05Contact with Relevant Government Agencies and Interest Groups
C5-OPS-02Capacity Management - Monitoring
C5-OPS-03Capacity Management - Controlling of Resources
C5-OPS-04Protection Against Malware - Concept
C5-OPS-05Protection Against Malware - Implementation
C5-OPS-07Data Backup and Recovery - Monitoring
C5-OPS-08Data Backup and Recovery - Regular Testing
C5-OPS-09Data Backup and Recovery - Storage
C5-OPS-11Logging and Monitoring - Metadata Management Concept
C5-OPS-12Logging and Monitoring - Access, Storage and Deletion
C5-OPS-13Logging and Monitoring - Identification of Events
C5-OPS-14Logging and Monitoring - Storage of the Logging Data
C5-OPS-15Logging and Monitoring - Accountability
C5-OPS-16Logging and Monitoring - Configuration
C5-OPS-17Logging and Monitoring - Availability of the Monitoring Software
C5-OPS-19Managing Vulnerabilities, Malfunctions and Errors - Penetration Tests
C5-OPS-20Managing Vulnerabilities, Malfunctions and Errors - Measurements, Analyses and Assessments of Procedures
C5-OPS-21Involvement of Cloud Customers in the Event of Incidents
C5-OPS-22Testing and Documentation of known Vulnerabilities
C5-OPS-23Managing Vulnerabilities, Malfunctions and Errors - System Hardening
C5-OPS-24Separation of Datasets in the Cloud Infrastructure
C5-PI-02Contractual agreements for the provision of data
C5-PI-03Secure deletion of data
C5-PS-01Physical Security and Environmental Control Requirements
C5-PS-03Perimeter Protection
C5-PS-04Physical site access control
C5-PS-05Protection from fire and smoke
C5-PS-06Protection against interruptions caused by power failures and other such risks
C5-PS-07Surveillance of operational and environmental parameters
C5-PSS-01Guidelines and Recommendations for Cloud Customers
C5-PSS-02Identification of Vulnerabilities of the Cloud Service
C5-PSS-03Online Register of Known Vulnerabilities
C5-PSS-04Error handling and Logging Mechanisms
C5-PSS-06Session Management
C5-PSS-07Confidentiality of Authentication Information
C5-PSS-08Roles and Rights Concept
C5-PSS-10Software Defined Networking
C5-PSS-11Images for Virtual Machines and Containers
C5-PSS-12Locations of Data Processing and Storage
C5-SIM-04Duty of the users to report security incidents to a central body
C5-SIM-05Evaluation and learning process
C5-SP-02Review and Approval of Policies and Instructions
C5-SP-03Exceptions from Existing Policies and Instructions
C5-SSO-02Risk assessment of service providers and suppliers
C5-SSO-03Directory of service providers and suppliers
C5-SSO-04Monitoring of compliance with requirements
C5-SSO-05Exit strategy for the receipt of benefits
Show the 27 you already have
C5-BCM-01Top management responsibility
C5-BCM-04Verification, updating and testing of the business continuity
C5-COM-03Internal audits of the information security management system
C5-COS-01Technical safeguards
C5-CRY-01Policy for the use of encryption procedures and key management
C5-DEV-01Policies for the development/procurement of information systems
C5-DEV-03Policies for changes to information systems
C5-IDM-01Policy for user accounts and access rights
C5-IDM-05Regular review of access rights
C5-IDM-09Authentication mechanisms
C5-OIS-01Information Security Management System (ISMS)
C5-OIS-02Information Security Policy
C5-OIS-04Segregation of Duties
C5-OIS-06Risk Management Policy
C5-OIS-07Application of the Risk Management Policy
C5-OPS-01Capacity Management - Planning
C5-OPS-06Data Backup and Recovery - Concept
C5-OPS-10Logging and Monitoring - Concept
C5-OPS-18Managing Vulnerabilities, Malfunctions and Errors - Concept
C5-PI-01Documentation and safety of input and output interfaces
C5-PSS-05Authentication Mechanisms
C5-PSS-09Authorisation Mechanisms
C5-SIM-01Policy for security incident management
C5-SIM-02Processing of security incidents
C5-SIM-03Documentation and reporting of security incidents
C5-SP-01Documentation, communication and provision of policies and instructions
C5-SSO-01Policies and instructions for controlling and monitoring third parties
How this is calculated
Already covered means a mapping runs from a control in SOC 2 to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition