Free compliance framework explorer — browse controls, evidence, and implementation guidance.Subscribe for updates →
BETA
SOC 247
ITSP.10.17198
ISO 42001soon
ISO 27001soon
Browse
Ctrl+K
33 controls
CC1.1
Commitment to integrity and ethical values
Control Environment
6 evidence2 controls
CC1.2
Board independence and oversight of internal control
Control Environment
3 evidence1 control
CC1.3
Organizational structure, reporting lines, and authority
Control Environment
3 evidence1 control
CC1.4
Commitment to attract, develop, and retain competent individuals
Control Environment
6 evidence2 controls
CC1.5
Accountability for internal control responsibilities
Control Environment
3 evidence1 control
CC2.1
Obtains or generates and uses relevant quality information
Communication and Information
3 evidence1 control
CC2.2
Internal communication of information to support internal control
Communication and Information
6 evidence2 controls
CC2.3
External communication regarding matters affecting internal control
Communication and Information
4 evidence1 control
CC3.1
Specifies objectives with sufficient clarity
Risk Assessment
3 evidence1 control
CC3.2
Identifies and analyzes risks to achievement of objectives
Risk Assessment
3 evidence1 control
CC3.3
Considers potential for fraud in assessing risks
Risk Assessment
3 evidence1 control
CC3.4
Identifies and assesses significant changes
Risk Assessment
3 evidence1 control
CC4.1
Selects, develops, and performs ongoing and separate evaluations
Monitoring Activities
6 evidence2 controls
CC4.2
Evaluates and communicates internal control deficiencies
Monitoring Activities
3 evidence1 control
CC5.1
Selects and develops control activities that mitigate risks
Control Activities
3 evidence1 control
CC5.2
Selects and develops general controls over technology
Control Activities
6 evidence2 controls
CC5.3Deploys control activities through policies and proceduresSOC 2Control Activities
Official Requirement
COSO Principle 12: Management deploys control activities through policies that establish what is expected and procedures that put policies into action.
Every significant control in your program traces back to a policy that requires it. The policy says what must happen; the procedure says how to do it; the evidence confirms it was done. This is the criterion that auditors use when they test your policy library, not just whether policies exist, but whether they are current, acknowledged, and enforced through actual operating procedures.
These are typical controls and implementation steps. Your systems and environment may differ.
Typical Control Comprehensive policy library with annual review and management approval
Implementation Steps
Maintain a policy inventory covering at minimum: Information Security, Access Control and Termination, Change Management, Incident Response, Vulnerability and Patch Management, Business Continuity and DR, Data Classification, Data Retention and Disposal, Vendor Risk Management, Acceptable Use, Encryption and Key Management
Each policy must have an effective date, a review date (no more than 12 months in the future), and a named owner, use your GRC platform to track this automatically
Conduct annual policy review: each policy owner reviews, updates if needed, and management formally approves the updated version
Distribute policy updates through your GRC platform and collect new acknowledgements from all staff when material changes are made
Typical Control Comprehensive policy library with annual review and management approval
Evidence Artifacts
Policy inventory from GRC platform showing all active policies, their effective dates, owners, and last review dates
Management approval records (email or GRC platform sign-off) for policies reviewed during the audit period
Policy acknowledgement completion report showing all staff acknowledged current policy versions
📅Annual review cycle; acknowledgement cycle runs concurrently or immediately following review
Cross-framework mappings coming in v1.1
When we add ISO 42001 and ISO 27001, you'll see which controls map to this criterion.
ISO
ISO 42001
AI Management Systems
ISO
ISO 27001
Information Security
Mapping data will appear here automatically when the frameworks are published.
CC6.1
Logical access security infrastructure
Logical and Physical Access Controls
11 evidence3 controls
CC6.2
Registration and authorization prior to issuing credentials
Logical and Physical Access Controls
6 evidence2 controls
CC6.3
Role-based access management
Logical and Physical Access Controls
6 evidence2 controls
CC6.4
Physical access restrictions
Logical and Physical Access Controls
3 evidence1 control
CC6.5
Disposal and destruction of information assets
Logical and Physical Access Controls
3 evidence1 control
CC6.6
Controls against threats from outside system boundaries
Logical and Physical Access Controls
8 evidence2 controls
CC6.7
Restricts transmission and movement of information
Logical and Physical Access Controls
7 evidence2 controls
CC6.8
Controls to prevent or detect unauthorized software
Logical and Physical Access Controls
6 evidence2 controls
CC7.1
Detection and monitoring for vulnerabilities
System Operations
8 evidence2 controls
CC7.2
Monitoring for anomalies and security events
System Operations
4 evidence1 control
CC7.3
Evaluation of security events as security incidents
System Operations
4 evidence1 control
CC7.4
Incident response program
System Operations
4 evidence1 control
CC7.5
Recovery from security incidents
System Operations
4 evidence1 control
CC8.1
Authorized change management process
Change Management
8 evidence2 controls
CC9.1
Risk mitigation for business disruptions
Risk Mitigation
4 evidence1 control
CC9.2
Vendor and business partner risk management
Risk Mitigation
4 evidence1 control
Help us build what matters.
Vote for the next framework, subscribe for updates, and let us know if you'd contribute.
What should we add next?
Vote for the framework you need most.
0
ISO 42001
0
ISO 27001
0
CMMC
0
CPCSC
Stay Updated
Get notified when new frameworks and features are added.
On-premises implementation and evidence
Comprehensive policy library with annual review and management approval
Implementation steps
Maintain all policies in a version-controlled repository (shared drive or intranet) with clear naming conventions: policy name, version number, effective date
Set calendar reminders for annual policy review 60 days before the expiry date, do not let policies expire unreviewed during an audit period
For each policy, document the procedure that implements it: the policy says 'access reviews must be conducted quarterly'; the procedure describes how to run the access review, what tool to use, and how to document it
Management sign-off on policies is required annually; retain the signed approval email or document as evidence
Tools / systems
Shared drive or intranet (policy repository)
Email (management approval records)
Spreadsheet (policy inventory with review dates)
GRC platform (e.g., Vanta, Drata, your GRC platform, Scrut)
Evidence artifacts
Policy inventory spreadsheet or your GRC platform export listing all policies, versions, effective dates, and owners
Signed management approval for each policy reviewed during the audit period
Acknowledgement log showing all staff accepted the current policy versions
Evidence frequency: Annual policy review; acknowledgements collected within 30 days of policy publication