SOC 2

Overview#

SOC 2 Reports are from the AICPA Assurance Services Executive Committee (ASEC) released the revised version (2014) of the Trust Services Principles and Criteria (TSP).

SOC 2 examinations performed under the new standards must couple the Security Principle with any non-privacy principle. For instance, a SOC 2 that includes the Availability Principle must also include the Security Principle.

The Security Principle was restructured into the following seven categories:

Change Management: The criteria relevant to how the organization identifies the need for changes to the system, makes the changes following a controlled change management process, and prevents unauthorized changes from being made to meet the criteria for the principle(s) addressed in the engagement.

The other non-privacy principles, Availability, Processing Integrity, and Confidentiality, have also been modified to include criteria that are only applicable to the specific principle. This greatly reduces the redundancies found in the old TSPs when more than one non-privacy principle was in scope for the SOC 2 examination.

More Information#

There might be more information for this subject on one of the following: