0% found this document useful (0 votes)
31 views2 pages

Internal Control Framework Overview

The document outlines various internal control measures categorized under Common Criteria, Security, Availability, Processing Integrity, Confidentiality, and Privacy. Each control is associated with specific responsibilities, procedures, and compliance requirements aimed at ensuring organizational integrity, risk management, and data protection. Additionally, it maps controls to relevant cloud services and frameworks, specifically SOC2.

Uploaded by

moorthyms
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as XLSX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
31 views2 pages

Internal Control Framework Overview

The document outlines various internal control measures categorized under Common Criteria, Security, Availability, Processing Integrity, Confidentiality, and Privacy. Each control is associated with specific responsibilities, procedures, and compliance requirements aimed at ensuring organizational integrity, risk management, and data protection. Additionally, it maps controls to relevant cloud services and frameworks, specifically SOC2.

Uploaded by

moorthyms
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as XLSX, PDF, TXT or read online on Scribd

Control ID Control Name Description

CC1.1 Control Environment Organization demonstrates commitment to integrity and ethical value
CC1.2 Board Oversight Board exercises oversight of internal controls.
CC1.3 Roles & Responsibilities Management assigns responsibility for internal controls.
CC1.4 Competency & Training Personnel are trained and competent.
CC1.5 Accountability Individuals are held accountable for internal control responsibilities.
CC2.1 Risk Assessment Process Entity specifies objectives and identifies risks.
CC2.2 Risk Identification Risks identified and analyzed to determine responses.
CC2.3 Fraud Risk Fraud risks considered in assessments.
CC3.1 Policies & Procedures Policies established and reviewed.
CC3.2 Change Management Changes to systems approved, tested, and documented.
CC3.3 Roles Segregation Segregation of duties implemented.
CC3.4 Logical Access Logical access controls protect data and systems.
CC3.5 Authentication & Authorization Strong authentication enforced.
CC3.6 Logging & Monitoring System events logged and monitored.
CC3.7 Incident Handling Security incidents identified and resolved.
CC4.1 Information Communication Relevant information communicated internally.
CC4.2 External Communication External communications with clients/vendors handled appropriately.
CC5.1 Monitoring Internal controls monitored for continuous effectiveness.
CC5.2 Control Deficiency ManagementDeficiencies identified and corrected.
LOG-01 Password Policy Passwords follow complexity and rotation policies.
LOG-02 Privileged Access Management Privileged access monitored and reviewed.
LOG-03 Access Reviews Periodic access certification performed.
LOG-04 Network Segmentation Segmentation implemented between sensitive assets.
LOG-05 Firewall Management Firewall rules reviewed periodically.
CM-01 Configuration Baselines Secure configuration standards exist and enforced.
CM-02 Vulnerability Scanning Regular vulnerability scans performed.
CM-03 Patch Management Patches applied within SLA.
AV-01 Backup Scheduling Regular backups performed and verified.
AV-02 Disaster Recovery DR plan documented and tested.
AV-03 Capacity Planning Resources monitored to meet availability objectives.
PI-01 Data Validation Controls Input, process, output validation performed.
PI-02 Error Handling System errors logged and resolved.
CONF-01 Encryption At Rest Data encrypted at rest using strong cryptography.
CONF-02 Encryption In Transit TLS enforced for data in transit.
CONF-03 Data Retention & Disposal Retention schedules enforced with secure disposal.
CONF-04 Access to Confidential Data Access to confidential data restricted.
PRIV-01 Privacy Notice Privacy notice published, updated and communicated.
PRIV-02 Data Subject Requests DSRs handled with proper authentication.
PRIV-03 PII Minimization Only minimum necessary PII collected and retained.
Control Category Control Type Tags Mapped Cloud ServicesSource Framework
Common Criteria Preventive ethics,governance N/A SOC2 (TSC)
Common Criteria Detective oversight,governance N/A SOC2
Common Criteria Preventive roles,responsibility N/A SOC2
Common Criteria Preventive training,hr N/A SOC2
Common Criteria Preventive accountability,policy N/A SOC2
Common Criteria Preventive risk,assessment N/A SOC2
Common Criteria Preventive risk N/A SOC2
Common Criteria Detective fraud N/A SOC2
Common Criteria Preventive policy,procedure N/A SOC2
Common Criteria Preventive change,release CI/CD SOC2
Common Criteria Preventive sod IAM SOC2
Common Criteria Preventive access,iam IAM,Identity Center SOC2
Common Criteria Preventive mfa,auth Cognito,Azure AD SOC2
Common Criteria Detective logging,siem CloudWatch,Splunk SOC2
Common Criteria Corrective incident,response PagerDuty,ServiceNow SOC2
Common Criteria Preventive communication N/A SOC2
Common Criteria Preventive client,communication Email/SNS SOC2
Common Criteria Detective monitoring BI Tools SOC2
Common Criteria Corrective deficiency,tracking Ticketing SOC2
Security Preventive password,iam Secrets Manager SOC2 Security
Security Preventive privileged,PAM IAM SOC2 Security
Security Detective access-review IAM/Azure AD SOC2 Security
Security Preventive network,segmentation VPC/NSG SOC2 Security
Security Detective firewall Security Groups SOC2 Security
Security Preventive hardening,baseline SSM,Terraform SOC2 Security
Security Detective vulnerability Inspector/Tenable SOC2 Security
Security Preventive patching,os SSM SOC2 Security
Availability Preventive backup S3,Blob SOC2 Availability
Availability Corrective dr,failover Multi-region Cloud SOC2 Availability
Availability Preventive capacity Auto Scaling SOC2 Availability
Processing IntegrityPreventive validation,data-quality App Layer SOC2 PI
Processing IntegrityCorrective error-handling App Logs SOC2 PI
Confidentiality Preventive encryption KMS SOC2 Confidentiality
Confidentiality Preventive tls,network CloudFront,LB SOC2 Confidentiality
Confidentiality Preventive retention,disposal Lifecycle Policies SOC2 Confidentiality
Confidentiality Preventive confidentiality,access IAM Policies SOC2 Confidentiality
Privacy Preventive privacy,notice N/A SOC2 Privacy
Privacy Corrective dsr,privacy Support/CRM SOC2 Privacy
Privacy Preventive pii,minimization App/DB SOC2 Privacy

You might also like