Cybersecurity GRC 22 items
SOC 2 Trust Services Criteria Readiness Assessment
Evaluates readiness for a SOC 2 Type II examination across the AICPA Common Criteria and the Availability and Confidentiality categories.
SOC 2AICPA TSC
Free PDF · enter your email to download.
Control Environment (CC1)
- Is there a documented code of conduct that all personnel acknowledge? *
- Does the board or an equivalent oversight body operate independently of management and review security matters? *
- Are organizational structures, reporting lines, and authorities documented? *
- Are background checks performed on new hires prior to granting system access? *
- Are individuals held accountable for internal control responsibilities through performance evaluations? *
Communication & Information (CC2)
- Are security commitments and system requirements communicated to internal users? *
- Are security responsibilities communicated to external users, vendors, and partners? *
- Is there a defined channel for personnel to report security issues or control failures? *
Risk Assessment (CC3)
- Are specific, measurable security objectives defined for the system? *
- Is a formal risk assessment performed at least annually to identify threats to objectives? *
- Is the potential for fraud considered when assessing risks? *
- Are changes that could significantly affect the system of internal control identified and assessed? *
Monitoring Activities (CC4)
- Are ongoing and separate evaluations performed to verify controls are operating? *
- Are identified control deficiencies communicated to parties responsible for corrective action? *
- When was the most recent internal control self-assessment completed?
Control Activities & Availability (CC5, A1)
- Are control activities selected and developed to mitigate risks to acceptable levels? *
- Are technology general controls over infrastructure implemented? *
- Is capacity monitored and forecast to meet availability commitments? *
- Are environmental protections, backups, and recovery infrastructure maintained and tested? *
- Are recovery plan procedures tested to meet availability objectives? *
Confidentiality (C1)
- Is confidential information identified and maintained per commitments and requirements? *
- Is confidential information disposed of securely when no longer required? *
Download the full SOC 2 Trust Services Criteria Readiness Assessment checklist
Get it as a clean, printable PDF — free.
