Free compliance framework explorer — browse controls, evidence, and implementation guidance.Subscribe for updates →
BETA
SOC 247
ITSP.10.17198
ISO 42001soon
ISO 27001soon
Browse
Ctrl+K
33 controls
CC1.1
Commitment to integrity and ethical values
Control Environment
6 evidence2 controls
CC1.2
Board independence and oversight of internal control
Control Environment
3 evidence1 control
CC1.3
Organizational structure, reporting lines, and authority
Control Environment
3 evidence1 control
CC1.4
Commitment to attract, develop, and retain competent individuals
Control Environment
6 evidence2 controls
CC1.5
Accountability for internal control responsibilities
Control Environment
3 evidence1 control
CC2.1
Obtains or generates and uses relevant quality information
Communication and Information
3 evidence1 control
CC2.2
Internal communication of information to support internal control
Communication and Information
6 evidence2 controls
CC2.3
External communication regarding matters affecting internal control
Communication and Information
4 evidence1 control
CC3.1
Specifies objectives with sufficient clarity
Risk Assessment
3 evidence1 control
CC3.2
Identifies and analyzes risks to achievement of objectives
Risk Assessment
3 evidence1 control
CC3.3
Considers potential for fraud in assessing risks
Risk Assessment
3 evidence1 control
CC3.4
Identifies and assesses significant changes
Risk Assessment
3 evidence1 control
CC4.1
Selects, develops, and performs ongoing and separate evaluations
Monitoring Activities
6 evidence2 controls
CC4.2
Evaluates and communicates internal control deficiencies
Monitoring Activities
3 evidence1 control
CC5.1
Selects and develops control activities that mitigate risks
Control Activities
3 evidence1 control
CC5.2
Selects and develops general controls over technology
Control Activities
6 evidence2 controls
CC5.3
Deploys control activities through policies and procedures
Control Activities
3 evidence1 control
CC6.1Logical access security infrastructureSOC 2Logical and Physical Access Controls
Official Requirement
The entity implements logical access security software, infrastructure, and architectures over protected information assets to protect them from security events to meet the entity's objectives.
You have the technical building blocks in place to control who can access what: identity management, MFA, network segmentation, encryption at rest, and session controls. These aren't individual tools bolted together, they form a coherent architecture that auditors can trace from policy to implementation to evidence.
These are typical controls and implementation steps. Your systems and environment may differ.
Typical Control MFA enforced on all production access
Implementation Steps
Enable MFA enforcement at the identity provider level (Okta, Azure AD, or AWS IAM Identity Center), not just at the application level
Set conditional access policies to block any authentication attempt without a second factor for production systems
Enforce MFA for VPN and SSO sessions, not just console logins
Document MFA exceptions (break-glass accounts) with compensating controls
Tools / Systems
OktaAzure AD / Entra IDAWS IAM Identity CenterDuo SecurityGoogle Workspace
Typical Control Encryption at rest for all sensitive datastores
Implementation Steps
Enable encryption at rest on all S3 buckets (default encryption with SSE-S3 or SSE-KMS), RDS instances, and EBS volumes
Use KMS customer-managed keys (CMKs) for production databases, this also satisfies key management evidence requirements
Enable encryption on backups and snapshots; verify these inherit encryption from source volumes
Document key rotation schedule in your Encryption and Key Management Policy (annual rotation is the standard)