Free compliance framework explorer — browse controls, evidence, and implementation guidance.Subscribe for updates →
BETA
SOC 247
ITSP.10.17198
ISO 42001soon
ISO 27001soon
Browse
Ctrl+K
33 controls
CC1.1
Commitment to integrity and ethical values
Control Environment
6 evidence2 controls
CC1.2
Board independence and oversight of internal control
Control Environment
3 evidence1 control
CC1.3
Organizational structure, reporting lines, and authority
Control Environment
3 evidence1 control
CC1.4
Commitment to attract, develop, and retain competent individuals
Control Environment
6 evidence2 controls
CC1.5
Accountability for internal control responsibilities
Control Environment
3 evidence1 control
CC2.1
Obtains or generates and uses relevant quality information
Communication and Information
3 evidence1 control
CC2.2
Internal communication of information to support internal control
Communication and Information
6 evidence2 controls
CC2.3
External communication regarding matters affecting internal control
Communication and Information
4 evidence1 control
CC3.1
Specifies objectives with sufficient clarity
Risk Assessment
3 evidence1 control
CC3.2
Identifies and analyzes risks to achievement of objectives
Risk Assessment
3 evidence1 control
CC3.3
Considers potential for fraud in assessing risks
Risk Assessment
3 evidence1 control
CC3.4
Identifies and assesses significant changes
Risk Assessment
3 evidence1 control
CC4.1Selects, develops, and performs ongoing and separate evaluationsSOC 2Monitoring Activities
Official Requirement
COSO Principle 16: The entity selects, develops, and performs ongoing and/or separate evaluations to ascertain whether the components of internal control are present and functioning.
You have a systematic process for verifying that controls actually work, not just that they exist. This includes continuous automated monitoring (GRC platform checks, SIEM alerts) and periodic manual evaluations (internal audits, penetration tests, control testing). The combination is what gives you and your auditor confidence that the program is operating, not just documented.
These are typical controls and implementation steps. Your systems and environment may differ.
Typical Control Continuous automated control monitoring via GRC platform
Implementation Steps
Configure your GRC platform (your GRC platform, Drata, or Vanta) to perform automated checks against your cloud environment: MFA enforcement status, encryption at rest, public bucket exposure, access review completion, training completion rates
Set alert thresholds so that when a control fails (e.g., a new user is added without MFA, or a bucket becomes public), the control owner is notified within 24 hours
Review the GRC platform's control monitoring dashboard at least monthly, document the review and any remediation actions taken
Integrate cloud security posture management (CSPM) tools to catch configuration drift that the GRC platform may not cover: AWS Security Hub, Azure Defender for Cloud, or your monitoring platform CSPM
Typical Control Annual penetration test and vulnerability assessment
Implementation Steps
Engage a qualified third-party penetration testing firm to conduct an annual network and application penetration test against your production environment; ensure scope includes DAST (dynamic application security testing) against running web applications and APIs
Provide the pen test firm with the scope: in-scope systems, applications, APIs, and the Rules of Engagement document, retain this document as evidence of a structured engagement
Supplement annual pen tests with automated DAST scanning (OWASP ZAP, Burp Suite) in CI/CD or on a recurring schedule against staging environments to catch vulnerabilities between annual assessments
After the engagement, track all critical and high findings in your ticketing system with assigned owners and remediation deadlines
Retest critical findings after remediation; obtain a remediation validation letter from the pen test firm if your audit window requires it
Tools / Systems
Third-party pen test firmJira (finding tracking)AWS Inspector / Burp Suite (DAST / supplemental scanning)OWASP ZAP (DAST, open source)GRC platform (e.g., Vanta, Drata, your GRC platform, Scrut)
Typical Control Continuous automated control monitoring via GRC platform
Evidence Artifacts
GRC platform control monitoring dashboard screenshot showing automated checks are running and current status
Sample alert notification showing a control failure was detected and the owner was notified
Monthly control review documentation showing the review was performed and findings addressed
📅Continuous automated checks; monthly manual review with documentation
Typical Control Annual penetration test and vulnerability assessment
Evidence Artifacts
Annual penetration test report with executive summary, scope, methodology, and findings
Remediation tracking spreadsheet or Jira export showing finding status, owner, and closure date
Retest confirmation or remediation validation letter for critical findings
📅Annual pen test; remediation tracked and closed within policy SLA
Cross-framework mappings coming in v1.1
When we add ISO 42001 and ISO 27001, you'll see which controls map to this criterion.
ISO
ISO 42001
AI Management Systems
ISO
ISO 27001
Information Security
Mapping data will appear here automatically when the frameworks are published.
CC4.2
Evaluates and communicates internal control deficiencies
Monitoring Activities
3 evidence1 control
CC5.1
Selects and develops control activities that mitigate risks
Control Activities
3 evidence1 control
CC5.2
Selects and develops general controls over technology
Control Activities
6 evidence2 controls
CC5.3
Deploys control activities through policies and procedures
Control Activities
3 evidence1 control
CC6.1
Logical access security infrastructure
Logical and Physical Access Controls
11 evidence3 controls
CC6.2
Registration and authorization prior to issuing credentials
Logical and Physical Access Controls
6 evidence2 controls
CC6.3
Role-based access management
Logical and Physical Access Controls
6 evidence2 controls
CC6.4
Physical access restrictions
Logical and Physical Access Controls
3 evidence1 control
CC6.5
Disposal and destruction of information assets
Logical and Physical Access Controls
3 evidence1 control
CC6.6
Controls against threats from outside system boundaries
Logical and Physical Access Controls
8 evidence2 controls
CC6.7
Restricts transmission and movement of information
Logical and Physical Access Controls
7 evidence2 controls
CC6.8
Controls to prevent or detect unauthorized software
Logical and Physical Access Controls
6 evidence2 controls
CC7.1
Detection and monitoring for vulnerabilities
System Operations
8 evidence2 controls
CC7.2
Monitoring for anomalies and security events
System Operations
4 evidence1 control
CC7.3
Evaluation of security events as security incidents
System Operations
4 evidence1 control
CC7.4
Incident response program
System Operations
4 evidence1 control
CC7.5
Recovery from security incidents
System Operations
4 evidence1 control
CC8.1
Authorized change management process
Change Management
8 evidence2 controls
CC9.1
Risk mitigation for business disruptions
Risk Mitigation
4 evidence1 control
CC9.2
Vendor and business partner risk management
Risk Mitigation
4 evidence1 control
Help us build what matters.
Vote for the next framework, subscribe for updates, and let us know if you'd contribute.
What should we add next?
Vote for the framework you need most.
0
ISO 42001
0
ISO 27001
0
CMMC
0
CPCSC
Stay Updated
Get notified when new frameworks and features are added.
On-premises implementation and evidence
Continuous automated control monitoring via GRC platform
Implementation steps
Deploy vulnerability/configuration management agents on all production servers to continuously monitor for security policy violations, configuration drift, and new vulnerabilities
Configure SIEM rules to alert on high-risk events: failed root login attempts, privileged account use outside business hours, file integrity changes on critical system paths
Run weekly CIS benchmark scans for Tier 1 systems; review the output and open remediation tickets for any new failures
Schedule a monthly control review meeting where the security team reviews your SIEM/monitoring platform alerts, your IDS/network monitoring platform IDS events, and any open control deficiencies
Tools / systems
Wazuh (log collection/HIDS) (continuous monitoring and CIS benchmarks)
Security Onion (IDS and NSM)
Work order system (remediation tickets)
GRC platform (e.g., Vanta, Drata, your GRC platform, Scrut)
Evidence artifacts
Wazuh dashboard screenshot showing agents are active and monitoring production systems
Sample CIS benchmark scan report for Tier 1 systems with findings and remediation status
Monthly control review meeting minutes or log showing review was conducted
Annual penetration test and vulnerability assessment
Implementation steps
Conduct an annual external and internal penetration test; include network, infrastructure, and application layers in scope, with DAST testing against web applications
The pen test report becomes a primary piece of CC4.1 evidence, auditors will review the report, scope, and how findings were remediated
Run DAST scans (OWASP ZAP, Nikto) against staging or pre-production environments on a recurring basis to catch web application vulnerabilities between annual pen tests
Track all findings in the work order system with owner, severity, target date, and closure confirmation
Run vulnerability scans weekly (Tier 1) as a continuous internal evaluation between annual pen tests
Tools / systems
Third-party pen test firm
OWASP ZAP (DAST, open source)
Nikto (web server DAST scanner)
Tenable (vulnerability management)
ConnectSecure (vulnerability and configuration management)
OpenSCAP (security configuration management)
Nmap with Vulners script (network vulnerability scanning)
Work order system (finding tracking)
GRC platform (e.g., Vanta, Drata, your GRC platform, Scrut)
Evidence artifacts
Penetration test report from third-party firm covering the audit period
Work orders or tickets for each finding showing owner, severity, and closure