{
  "code": "SOC2-2017",
  "name": "SOC 2 Type II — Trust Services Criteria (2017)",
  "version": "2017",
  "issuing_body": "AICPA",
  "description": "Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy",
  "regions": ["us"],
  "industries": ["Technology", "Financial Services", "Healthcare"],
  "effective_date": "2017-12-15",
  "is_global": false,
  "requirements": [
    {
      "reference_code": "CC1",
      "title": "Control Environment",
      "requirement_type": "mandatory",
      "category": "Common Criteria",
      "children": [
        { "reference_code": "CC1.1", "title": "COSO Principle 1: Demonstrates Commitment to Integrity and Ethical Values", "description": "The entity demonstrates a commitment to integrity and ethical values.", "requirement_type": "mandatory" },
        { "reference_code": "CC1.2", "title": "COSO Principle 2: Exercises Oversight Responsibility", "description": "The board of directors demonstrates independence from management and exercises oversight.", "requirement_type": "mandatory" },
        { "reference_code": "CC1.3", "title": "COSO Principle 3: Establishes Structure, Authority, and Responsibility", "description": "Management establishes organizational structures, reporting lines, and authorities.", "requirement_type": "mandatory" },
        { "reference_code": "CC1.4", "title": "COSO Principle 4: Demonstrates Commitment to Competence", "description": "The entity demonstrates a commitment to attract, develop, and retain competent individuals.", "requirement_type": "mandatory" },
        { "reference_code": "CC1.5", "title": "COSO Principle 5: Enforces Accountability", "description": "The entity holds individuals accountable for their internal control responsibilities.", "requirement_type": "mandatory" }
      ]
    },
    {
      "reference_code": "CC2",
      "title": "Communication and Information",
      "requirement_type": "mandatory",
      "category": "Common Criteria",
      "children": [
        { "reference_code": "CC2.1", "title": "COSO Principle 13: Uses Relevant Information", "description": "The entity obtains or generates and uses relevant, quality information.", "requirement_type": "mandatory" },
        { "reference_code": "CC2.2", "title": "COSO Principle 14: Communicates Internally", "description": "The entity internally communicates information necessary to support the functioning of internal control.", "requirement_type": "mandatory" },
        { "reference_code": "CC2.3", "title": "COSO Principle 15: Communicates Externally", "description": "The entity communicates with external parties regarding matters affecting internal control.", "requirement_type": "mandatory" }
      ]
    },
    {
      "reference_code": "CC6",
      "title": "Logical and Physical Access Controls",
      "requirement_type": "mandatory",
      "category": "Common Criteria",
      "children": [
        { "reference_code": "CC6.1", "title": "Logical access security", "description": "The entity implements logical access security software, infrastructure, and architectures over protected information assets.", "requirement_type": "mandatory" },
        { "reference_code": "CC6.2", "title": "Prior authorization access", "description": "Prior to issuing system credentials and granting system access, the entity registers and authorizes new internal and external users.", "requirement_type": "mandatory" },
        { "reference_code": "CC6.3", "title": "Access roles and responsibilities", "description": "The entity authorizes, modifies, or removes access to data, software, functions, and other protected information assets based on roles.", "requirement_type": "mandatory" },
        { "reference_code": "CC6.6", "title": "Security boundary threat protection", "description": "The entity implements controls to prevent or detect and act upon the introduction of unauthorized or malicious software.", "requirement_type": "mandatory" },
        { "reference_code": "CC6.7", "title": "Transmission protection", "description": "The entity restricts the transmission, movement, and removal of information to authorized internal and external users.", "requirement_type": "mandatory" },
        { "reference_code": "CC6.8", "title": "Malicious software prevention", "description": "The entity implements controls to prevent or detect and act upon the introduction of unauthorized software.", "requirement_type": "mandatory" }
      ]
    },
    {
      "reference_code": "CC7",
      "title": "System Operations",
      "requirement_type": "mandatory",
      "category": "Common Criteria",
      "children": [
        { "reference_code": "CC7.1", "title": "Vulnerability detection", "description": "The entity uses detection and monitoring procedures to identify changes to configurations.", "requirement_type": "mandatory" },
        { "reference_code": "CC7.2", "title": "Anomaly detection", "description": "The entity monitors system components and the operation of those components for anomalies.", "requirement_type": "mandatory" },
        { "reference_code": "CC7.3", "title": "Incident response", "description": "The entity evaluates security events to determine whether they could or have resulted in a failure of the entity.", "requirement_type": "mandatory" },
        { "reference_code": "CC7.4", "title": "Incident response program", "description": "The entity responds to identified security incidents by executing a defined incident response program.", "requirement_type": "mandatory" },
        { "reference_code": "CC7.5", "title": "Incident recovery", "description": "The entity identifies, develops, and implements activities to recover from identified security incidents.", "requirement_type": "mandatory" }
      ]
    },
    {
      "reference_code": "CC8",
      "title": "Change Management",
      "requirement_type": "mandatory",
      "category": "Common Criteria",
      "children": [
        { "reference_code": "CC8.1", "title": "Infrastructure changes", "description": "The entity authorizes, designs, develops or acquires, configures, documents, tests, approves, and implements changes.", "requirement_type": "mandatory" }
      ]
    },
    {
      "reference_code": "A1",
      "title": "Availability",
      "requirement_type": "recommended",
      "category": "Availability Criteria",
      "children": [
        { "reference_code": "A1.1", "title": "Availability commitments", "description": "The entity maintains, monitors, and evaluates current processing capacity and use of system components.", "requirement_type": "recommended" },
        { "reference_code": "A1.2", "title": "Environmental protections", "description": "The entity authorizes, designs, develops or acquires, implements, operates, approves, maintains, and monitors environmental protections.", "requirement_type": "recommended" },
        { "reference_code": "A1.3", "title": "Recovery plan", "description": "The entity tests recovery plan procedures supporting system availability.", "requirement_type": "recommended" }
      ]
    },
    {
      "reference_code": "C1",
      "title": "Confidentiality",
      "requirement_type": "recommended",
      "category": "Confidentiality Criteria",
      "children": [
        { "reference_code": "C1.1", "title": "Confidential information identification", "description": "The entity identifies and maintains confidential information to meet the entity's objectives.", "requirement_type": "recommended" },
        { "reference_code": "C1.2", "title": "Confidential information disposal", "description": "The entity disposes of confidential information to meet the entity's objectives.", "requirement_type": "recommended" }
      ]
    }
  ]
}
