SOC2 control

Page 1

SOC 2 Compliance

SOC 2 Compliance SOC stands for Service Organization Compliance Control Type 2. It is a voluntary compliance standard, i.e. it is not compulsory by law. It was developed by the AICPA, American Institute of Certified Public Accounts, to help organizations ensure that their service providers are securely managing their data. It is said to be based on five trust service principles 1. Security : The organization should protect its customer information from unauthorized access, use, and disclosure. 2. Availability: The organization should be able to process customers’ data when they need it. 3. Processing integrity: The customers’ data should be processed timely, accurately, and completely.


Turn static files into dynamic content formats.

Create a flipbook
Issuu converts static files into: digital portfolios, online yearbooks, online catalogs, digital photo albums and more. Sign up and create your flipbook.