11% of ISO/IEC 29115:2023 you already have
SOC 2 already covers about 11% of ISO/IEC 29115:2023, leaving
34 of 38 controls as genuinely new work.
Already covered 0
Likely covered 4
New work 34
No control in SOC 2
maps directly to one in ISO/IEC 29115:2023. Everything counted as covered is covered because both
map to the same third standard, which is what a crosswalk is, but it is an inference rather
than a lookup.
What is genuinely new work
Nothing in SOC 2 reaches these. This is the list to scope.
29115-10.1Enrollment and identity proofing criteria
29115-10.2Credential management criteria
29115-10.3Entity authentication criteria
29115-10.4Federation and assertion criteria
29115-5.1Entity authentication assurance framework overview
29115-5.2Authentication lifecycle phases
29115-6.1Authentication context
29115-7.1Level of Assurance 1 (LoA1)
29115-7.2Level of Assurance 2 (LoA2)
29115-7.3Level of Assurance 3 (LoA3)
29115-9.1Threat analysis overview
29115-9.2Enrollment and identity proofing threats
29115-9.3Credential management threats
29115-9.4Authentication mechanism threats
ISO29115-10.1Audit and Accountability
ISO29115-10.2Independent Assessment
ISO29115-11.1Cross LoA Federation
ISO29115-11.2Privacy in Authentication
ISO29115-12.1Documented Operating Procedures
ISO29115-5.1Authentication Assurance Level Selection
ISO29115-5.2Enrolment Phase Controls
ISO29115-5.3Identity Proofing at LoA 1
ISO29115-5.4Identity Proofing at LoA 2
ISO29115-5.5Identity Proofing at LoA 3
ISO29115-5.6Identity Proofing at LoA 4
ISO29115-6.1Credential Lifecycle Management
ISO29115-6.2Authenticator Binding
ISO29115-7.1Authentication Protocol Requirements
ISO29115-7.2Multi Factor Authentication
ISO29115-7.3Session Management
ISO29115-8.1Credential Service Provider Assurance
ISO29115-8.2Registration Authority Operations
ISO29115-9.1Threat Mitigation Mapping
ISO29115-9.2Fraud Detection and Response
Show the 4 you already have
29115-11Mapping other authentication schemes
29115-12.1Exchanging authentication results
29115-12.2Controls for mitigating threats
29115-7.4Level of Assurance 4 (LoA4)
How this is calculated
Already covered means a mapping runs from a control in SOC 2 to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition