SOC 2 Trust Services Criteria

SOC 2 Security Criterion

The security criterion is mandatory for every SOC 2 report. It covers protection against unauthorised access (both logical and physical). Every organisation that does SOC 2 includes this one.

SCOPEEVIDENCERISKEVIDENCETESTEVIDENCEREPORTEVIDENCEAUDIT TRAILSOC 2 Security EvidencePOLICY / CONTROL / EVIDENCE / REVIEW

Common control areas

Logical access security

Define the owner, operating process, sample evidence, exception handling, and review cadence before the audit period starts.

Access authorisation

Define the owner, operating process, sample evidence, exception handling, and review cadence before the audit period starts.

Role-based access

Define the owner, operating process, sample evidence, exception handling, and review cadence before the audit period starts.

Onboarding and offboarding

Define the owner, operating process, sample evidence, exception handling, and review cadence before the audit period starts.

Multi-factor authentication

Define the owner, operating process, sample evidence, exception handling, and review cadence before the audit period starts.

Privileged access management

Define the owner, operating process, sample evidence, exception handling, and review cadence before the audit period starts.

Network security

Define the owner, operating process, sample evidence, exception handling, and review cadence before the audit period starts.

Data encryption (in transit and at rest)

Define the owner, operating process, sample evidence, exception handling, and review cadence before the audit period starts.

Malware protection

Define the owner, operating process, sample evidence, exception handling, and review cadence before the audit period starts.

Security event monitoring

Define the owner, operating process, sample evidence, exception handling, and review cadence before the audit period starts.

Vulnerability management

Define the owner, operating process, sample evidence, exception handling, and review cadence before the audit period starts.

Asset management and labelling

Define the owner, operating process, sample evidence, exception handling, and review cadence before the audit period starts.

Evidence to keep

  • Control owner and review cadence
  • Policy or procedure approved by management
  • System export, ticket, report, or log sample
  • Exception record and remediation evidence

Security policy templates

Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.

Open the control-to-policy map

Back to all SOC 2 criteria, or open the SOC 2 template pack.