Trust service criteria
SOC 2
SOC 2 governs how service organizations manage and protect customer data across five trust service criteria: security, availability, processing integrity, confidentiality, and privacy.
- 1Security controls and continuous monitoring
- 2Incident response procedures and tabletop exercises
- 3Access controls and multi-factor authentication
- 4Vendor management and third-party risk
- 5Regular risk assessments and control testing