Security Assessment Standards and Frameworks - Trust Services Criteria

13 slides · 5 min read · Domain 6

Security Assessment Standards and Frameworks - Trust Services Criteria

Trust Services Criteria

Service Organization Control (SOC) 2, SOC 3 and SOC for Cybersecurity reports use the Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality and Privacy.

These requirements were developed by the American Institute of Certified Public Accountants (AICPA) and the Canadian Institute of Chartered Accountants (CICA) to provide assurance beyond what is derived from internal controls over financial reporting (ICFR).

In 2017, AICPA realigned the TSC to better support the 17 principles in the COSO framework, and in 2020 made further modifications to support the new SOC Examination for Supply Chains. The list below summarizes the TSC by relating its criteria and requirements back to concepts and topics covered throughout this course.

This has been done in a modular way so that a SOC 2 or SOC 3 report could cover one or more of the principles depending on the needs of the service provider and its users.

Security

Text on this slide

Requirements:

  • Protect against unauthorized access to, use or disclosure of data, or damage to

systems and data

  • Prevent breakdowns in process design for security (i.e., separation of duties, covert paths), misuse

Text on this slide

Controls:

  • IT security policy
  • Security awareness and training
  • Risk assessment and management
  • Access control and identity management
  • Asset classification & categorization
  • Systems development security
  • Configuration and change management
  • Personnel security
  • Security monitoring, incident response, and reporting

Availability

Text on this slide

Requirements:

  • Data and systems can be used wherever, whenever, and however necessary

Controls:

  • Business continuity and disaster recovery planning, implementation, and management
  • Availability policy and design
  • System and data accessibility
  • Backup and restore policies and processes
  • Environmental controls

Ø Confidentiality

Requirements:

  • Protect against unauthorized access to, use, or disclosure of data designated (classified) as private or confidential

Controls:

  • Security classification and categorization policy and procedures
  • Protection of inputs, processing, outputs, | and data in transit
  • Policies and processes for data disclosure (including to third parties)
  • Protection of confidential data in systems development process.

Processing Integrity

Text on this slide

Requirements:

  • Data processing is complete, accurate, and timely, by means of properly authorized processes

Controls:

  • Systems and processes perform as intended, free from error, delay, unauthorized or inadvertent manipulation
  • Policies for systems and data integrity
  • Data integrity (data quality) enforced across data lifecycle

Text on this slide

Privacy

Requirements:

  • Data usage to meet objectives ensures protection of privacy- related data

Controls:

  • Proper notice to data subjects
  • Subjects choice and consent
  • Collection, use, retention, and disposal policies and controls
  • Subjects access and review
  • Disclosure and notification policies and processes
  • Data quality standards and processes to ensure relevant, timely, and accurate data
  • Monitoring and enforcement

By contrast, SOC 1 reports require that a service organization describes its system and define its control objectives and controls that are relevant to users' internal control over financial reporting.

A SOC 1 report generally should not cover services or control domains that are not relevant to users from an COR perspective, and it specifically cannot cover topics such as disaster recovery and privacy.

SOC Reports for Clouds and Data Centers

A cloud-based enterprise resource planning (ERP) service historically would have provided a SAS 70 report because it provided a core financial reporting service to users. It is likely that it would continue to provide a SOC 1 report for that same reason. However, it may also have a need to provide a SOC 2 or SOC 3 Security and Availability report to address user assurance needs specific to cloud services. It may also have to provide the more focused SOC for Cybersecurity report.

Many data center colocation providers have historically completed SAS 70 examinations limited to physical and environmental security controls.

However, most data center providers host much more than just customers' financial systems. As a result, leading providers are moving toward SOC 2 security reporting. Some service providers incorporate supporting environmental security controls within their SOC 2 security report, whereas others also address the availability criteria, depending on the nature of their services.

For IT systems management, which can include general IT services provided to a portfolio of users, as well as customized services provided to specific users, SOC 1 or SOC 2 reporting could be applicable, depending on whether users' assurance needs are more focused on ICFR or security/availability.

SOC reports can be used effectively for services that are focused on technology or operational support activities that have little if any direct connection to users' ICFR.

Medical and educational information systems, for example, are not likely to fall under the reporting requirements Sarbanes-Oxley (SOX) section 404 or similar laws outside of the U.S. (although other legal requirements, such as FERPA and HIPAA, may dictate their own audit requirements). Users of these services are typically most concerned about security of their data and availability of these systems, which can be addressed by a SOC 2 or SOC 3 report covering security and availability. Where applicable, SOC 2 SOC 3 reports can cover confidentiality, processing integrity, and/or privacy as well.

SOC 2 is also potentially applicable for any organization that is storing and processing sensitive third-party data of any kind.

Where there is a need to demonstrate to third parties that effective security and confidentiality controls are in place to protect that information, SOC 2, SOC 3 and SOC for Cybersecurity provide a range of mechanisms for providing assurance. Through the system description in the report, the organization clearly describes the boundary of the "system," and the examination is then performed based on the defined trust services criteria.

Test this domain