SOC 2 (Systems and Organization Controls 2) is a security and compliance standard that provides guidelines for service organizations to protect sensitive data from unauthorized access, security incidents, and other vulnerabilities. It is part of the System and Organization Controls (SOC) suite of services developed by the American Institute of Certified Public Accountants (AICPA)1.
In essence, SOC 2 focuses on how companies should handle customer data stored in the cloud. The framework establishes trust between service providers and their customers by ensuring robust security protocols and compliance with five Trust Services Criteria (TSC):
- Security: Ensuring protection against unauthorized access and data breaches.
- Availability: Ensuring systems are available and operational when needed.
- Processing Integrity: Ensuring accurate and complete processing of data.
- Confidentiality: Safeguarding sensitive information.
- Privacy: Managing personal data in accordance with privacy regulations.
Knowledge Base Article Categories
Choose from the Knowledge Base category to view the available articles.