Mapping · SOC 2 ↔ ISO 27001

SOC 2 to ISO 27001 mapping:
one control, tested once, evidenced twice.

Every SOC 2 criterion and ISO/IEC 27001:2022 Annex A control in the TryTrustable control library that is evidenced by the same control, and every one that is not.

20 shared controlsSOC 2: 55/61 reachedISO/IEC 27001: 87/93 reachedCopy as CSV

Last updated Published by TryTrustableNot legal advice

01

How does SOC 2 map to ISO 27001?

In the TryTrustable control library, 20 shared controls are tested against both SOC 2 and ISO/IEC 27001. Those controls reach 55 of the 61 SOC 2 requirements the library models and 87 of the 93 ISO/IEC 27001 requirements. Each row below is one control and the requirements on each side it is evidence for.

The library breaks SOC 2 into its criteria and ISO/IEC 27001 into its 2022 Annex A controls, maps each to the controls that evidence it, and pairs two requirements only when they share a control. Many-to-many is normal: CC6.1 needs both MFA and single sign-on, and MFA also answers A.8.5. For the programme-level comparison of the two, see SOC 2 vs ISO 27001.

Shared controlSOC 2ISO/IEC 27001
Periodic logical access reviewCTL-ACCESS-REVIEW
CC1.3 COSO 3: Management establishes structures, reporting lines, authorities and responsibilities
CC3.3 COSO 8: Potential for fraud considered in assessing risks to objectives
CC4.1 COSO 16: Ongoing and separate evaluations ascertain whether controls are present and functioning
CC6.2 New internal and external users registered and authorized prior to system access
CC6.3 Quarterly logical access reviews performed and evidenced
A.5.3 Segregation of duties
A.5.15 Access control
A.5.18 Access rights provisioned, reviewed and revoked on schedule
A.6.5 Responsibilities after termination or change of employment
A.8.2 Privileged access rights
A.8.3 Information access restriction
A.8.4 Access to source code
A.8.18 Use of privileged utility programs
A.8.34 Protection of information systems during audit testing
Backup and restore testingCTL-BACKUP
A1.1 Capacity, backup and recovery objectives defined and load-tested
A1.2 Environmental protections, backup processes and recovery infrastructure implemented
CC7.5 Activities to recover from identified security incidents identified, developed and implemented
PI1.5 Stored inputs, items in processing and outputs retained completely and accurately
A.5.30 ICT readiness for business continuity
A.5.33 Protection of records
A.8.13 Information backup maintained and restore-tested
Business continuity and disaster recoveryCTL-BCDR
A1.2 Environmental protections, backup processes and recovery infrastructure implemented
A1.3 Recovery plan procedures supporting system recovery tested
CC9.1 Risk mitigation activities identified and developed for business disruptions
A.5.29 Information security during disruption
A.5.30 ICT readiness for business continuity
A.7.11 Supporting utilities
A.8.6 Capacity management
A.8.14 Redundancy of information processing facilities
Formal change managementCTL-CHANGE-MGMT
CC3.4 COSO 9: Changes that could significantly impact internal control identified and assessed
CC5.2 COSO 11: General control activities over technology selected and developed
CC8.1 Formal change management with peer review and rollback
A.8.9 Configuration management
A.8.19 Installation of software on operational systems
A.8.31 Separation of development, test and production environments
A.8.32 Change management for information processing facilities
Data retention and disposalCTL-DATA-RETENTION
C1.2 Confidential information disposed of to meet confidentiality objectives
CC6.5 Logical and physical protections over decommissioned assets discontinued only after data removal
P4.2 Retention: personal information retained no longer than necessary for stated purposes
P4.3 Disposal: personal information securely disposed of when no longer required
PI1.5 Stored inputs, items in processing and outputs retained completely and accurately
A.5.12 Classification of information
A.5.13 Labelling of information
A.5.33 Protection of records
A.7.10 Storage media
A.7.14 Secure disposal or re-use of equipment
A.8.10 Information deletion
Data loss preventionCTL-DLP
CC6.7 Transmission, movement and removal of information restricted to authorized users and processes
A.8.12 Data leakage prevention
Data subject rights fulfilmentCTL-DSAR
P5.1 Access: data subjects able to access their personal information for review and update
P5.2 Access: corrections, amendments or deletions recorded and communicated to relevant parties
P6.7 Disclosure: accounting of disclosures provided to data subjects on request
A.5.34 Privacy and protection of personally identifiable information (PII)
Endpoint detection and responseCTL-EDR
CC6.8 Controls implemented to prevent or detect unauthorized or malicious software
A.6.7 Remote working
A.7.9 Security of assets off-premises
A.8.1 User endpoint devices
A.8.7 Protection against malware
A.8.23 Web filtering
Encryption of data at restCTL-ENCRYPT-REST
CC6.6 Encryption of sensitive data at rest and in transit
A.5.34 Privacy and protection of personally identifiable information (PII)
A.7.10 Storage media
A.8.11 Data masking
A.8.24 Use of cryptography: data encrypted at rest and in transit
Encryption of data in transitCTL-ENCRYPT-TRANSIT
CC6.6 Encryption of sensitive data at rest and in transit
CC6.7 Transmission, movement and removal of information restricted to authorized users and processes
A.5.14 Information transfer
Incident response plan and exerciseCTL-IR-PLAN
CC7.3 Security events evaluated to determine whether they represent security incidents
CC7.4 Documented incident response plan tested annually
CC7.5 Activities to recover from identified security incidents identified, developed and implemented
P6.3 Disclosure: record maintained of detected or reported unauthorized disclosures
P6.5 Disclosure: third-party unauthorized disclosures assessed and remediated
P6.6 Disclosure: data subjects notified of incidents affecting their personal information
A.5.5 Contact with authorities
A.5.6 Contact with special interest groups
A.5.24 Information security incident management planning and preparation
A.5.25 Assessment and decision on information security events
A.5.26 Response to information security incidents per documented plan
A.5.27 Learning from information security incidents
A.6.8 Information security event reporting
Centralised, tamper-evident loggingCTL-LOGGING
CC2.1 COSO 13: Relevant, quality information obtained, generated and used for internal control
CC4.1 COSO 16: Ongoing and separate evaluations ascertain whether controls are present and functioning
CC7.2 Security event monitoring with centralized, tamper-evident logging
CC7.3 Security events evaluated to determine whether they represent security incidents
P6.2 Disclosure: record maintained of authorized disclosures of personal information
P6.3 Disclosure: record maintained of detected or reported unauthorized disclosures
PI1.1 Quality information about processing objectives obtained and communicated
PI1.3 System processing is complete, accurate, timely and authorized
PI1.4 System outputs are complete, accurate and delivered to specified recipients
A.5.25 Assessment and decision on information security events
A.5.28 Collection of evidence
A.7.4 Physical security monitoring
A.8.15 Logging: event logs recorded, protected and analysed
A.8.16 Monitoring activities
A.8.17 Clock synchronization
Multi-factor authentication enforcedCTL-MFA
CC6.1 Logical access security: MFA enforced for all workforce users
A.5.17 Authentication information
A.6.7 Remote working
A.8.2 Privileged access rights
A.8.5 Secure authentication: MFA on all information systems
Physical access controlCTL-PHYS-ACCESS
CC6.4 Physical access to facilities and protected information assets restricted
A.7.1 Physical security perimeters
A.7.2 Physical entry
A.7.3 Securing offices, rooms and facilities
A.7.4 Physical security monitoring
A.7.5 Protecting against physical and environmental threats
A.7.6 Working in secure areas
A.7.8 Equipment siting and protection
A.7.12 Cabling security
Policy review and attestationCTL-POLICY-REVIEW
CC1.1 COSO 1: The entity demonstrates a commitment to integrity and ethical values
CC1.2 COSO 2: The board demonstrates independence and exercises oversight of internal control
CC1.5 COSO 5: Individuals are held accountable for their internal control responsibilities
CC3.1 COSO 6: Objectives specified with sufficient clarity to identify and assess related risks
CC4.2 COSO 17: Internal control deficiencies evaluated and communicated for corrective action
CC5.1 COSO 10: Control activities selected and developed to mitigate risks to acceptable levels
CC5.3 COSO 12: Control activities deployed through policies and procedures
P8.1 Monitoring & enforcement: privacy complaints and disputes handled; compliance monitored
A.5.1 Policies for information security
A.5.2 Information security roles and responsibilities
A.5.4 Management responsibilities
A.5.10 Acceptable use of information and other associated assets
A.5.31 Legal, statutory, regulatory and contractual requirements
A.5.32 Intellectual property rights
A.5.35 Independent review of information security
A.5.36 Compliance with policies, rules and standards for information security
A.5.37 Documented operating procedures
A.6.2 Terms and conditions of employment
A.6.4 Disciplinary process
Secure software development lifecycleCTL-SDLC
CC5.2 COSO 11: General control activities over technology selected and developed
PI1.2 System inputs are complete and accurate; input errors detected and corrected
PI1.3 System processing is complete, accurate, timely and authorized
A.5.8 Information security in project management
A.8.4 Access to source code
A.8.25 Secure development life cycle
A.8.26 Application security requirements
A.8.27 Secure system architecture and engineering principles
A.8.28 Secure coding
A.8.29 Security testing in development and acceptance
A.8.33 Test information
Single sign-on for workforce accessCTL-SSO
CC6.1 Logical access security: MFA enforced for all workforce users
CC6.2 New internal and external users registered and authorized prior to system access
A.5.15 Access control
A.5.16 Identity management
A.8.5 Secure authentication: MFA on all information systems
Security awareness trainingCTL-TRAINING
CC1.4 Security awareness training completed by all personnel
CC1.5 COSO 5: Individuals are held accountable for their internal control responsibilities
CC2.2 COSO 14: Information including objectives and responsibilities communicated internally
A.5.10 Acceptable use of information and other associated assets
A.6.1 Screening
A.6.3 Information security awareness, education and training
A.6.8 Information security event reporting
A.7.7 Clear desk and clear screen
Vendor due diligence and monitoringCTL-VENDOR-DD
C1.1 Vendor due diligence and sub-processor confidentiality commitments
CC2.3 COSO 15: Matters affecting internal control communicated with external parties
CC9.2 Risks associated with vendors and business partners assessed and managed
P6.1 Disclosure: personal information disclosed to third parties only for identified, consented purposes
P6.4 Disclosure: third parties contractually bound to protect personal information consistently
P6.5 Disclosure: third-party unauthorized disclosures assessed and remediated
A.5.19 Information security in supplier relationships
A.5.20 Addressing information security within supplier agreements
A.5.21 Managing information security in the ICT supply chain
A.5.22 Monitoring, review and change management of supplier services
A.5.23 Information security for use of cloud services
A.6.6 Confidentiality or non-disclosure agreements
A.8.30 Outsourced development
Vulnerability scanning and remediationCTL-VULN-SCAN
CC3.2 COSO 7: Risks to objectives identified and analysed as a basis for managing risk
CC7.1 Vulnerability scanning and remediation within SLA
A.5.7 Threat intelligence
A.8.8 Management of technical vulnerabilities

Generated from the TryTrustable control library. Requirement descriptions are the library's own short wording of what the control is tested against, not the text of the standard or law. A mapping we could not stand behind on review is left out until it is corrected in the library.

169 rows: one per control and requirement, with the library description. Paste into a spreadsheet.

02

Which SOC 2 requirements have no shared control with ISO/IEC 27001?

These SOC 2 requirements are modelled in the library but share no control with any ISO/IEC 27001 requirement. They are the work that ISO/IEC 27001 does not cover for you, or places where the library has not linked them yet.

  • P1.1 Notice: privacy practices, objectives and commitments communicated to data subjects
  • P2.1 Choice & consent: choices available and consent obtained for collection, use, retention and disclosure
  • P3.1 Collection: personal information collected consistent with the entity's privacy objectives
  • P3.2 Collection: explicit consent obtained for sensitive personal information at or before collection
  • P4.1 Use: personal information used only for the purposes identified in the notice and consented to
  • P7.1 Quality: personal information maintained accurate, complete and relevant for its purposes

And the ISO/IEC 27001 requirements with no shared control on the SOC 2 side:

  • A.5.9 Inventory of information and other associated assets
  • A.5.11 Return of assets
  • A.7.13 Equipment maintenance
  • A.8.20 Networks security
  • A.8.21 Security of network services
  • A.8.22 Segregation of networks
03

Which controls does only one side ask for?

A requirement can be reached through a general control and still need a specific one. These controls are mapped to requirements on one side only, so evidence for them does nothing for the other framework.

Only SOC 2:

  • Lawful basis and consent capture CTL-CONSENT: P2.1, P3.2
  • Data quality and integrity CTL-DATA-QUALITY: P7.1
  • Privacy notice and transparency CTL-PRIVACY-NOTICE: P1.1, P3.1, P4.1

Only ISO/IEC 27001:

  • Asset inventory CTL-ASSET-INV: A.5.9, A.5.11, A.7.9, A.7.13
  • Network segmentation CTL-NET-SEG: A.8.20, A.8.21, A.8.22, A.8.31
  • Independent penetration testing CTL-PENTEST: A.8.29
04

What this mapping does not tell you

A shared control is shared evidence, not a shared verdict. A SOC 2 auditor tests whether the control operated over the report period against your own system description; an ISO certification auditor tests whether the control is in your Statement of Applicability, operating, and managed by the ISMS. The same MFA result serves both, and the two audits still ask different questions of it. The AICPA's own mapping of the Trust Services Criteria to ISO 27001 is available to its members and is worth reading alongside this one.

The controls with nothing on the other side are informative too. Network segmentation, penetration testing and the asset inventory are mapped to ISO Annex A but to no SOC 2 criterion in the library, while privacy notice, consent and data quality appear only on the SOC 2 side through the Privacy and Processing Integrity criteria. The SOC 2 guide and the ISO 27001 solution cover each programme, and the integrations show which of these controls are checked automatically.

Questions

The things people ask us

Can one set of controls satisfy SOC 2 and ISO 27001?

Largely, yes. Both ask for access control, change management, logging, incident response, vendor management and continuity, so one implemented control can be tested once and evidence both. What does not transfer is the wrapper: ISO 27001 requires a certified management system under clauses 4 to 10, and SOC 2 is an auditor's attestation report on your own system description.

Is there an official SOC 2 to ISO 27001 mapping?

The AICPA publishes a mapping of the 2017 Trust Services Criteria to ISO 27001 for its members. This page is not that document. It is generated from the TryTrustable control library and pairs criteria with Annex A controls only where the same control is tested against both.

Which ISO 27001 version does this mapping use?

ISO/IEC 27001:2022, whose Annex A has 93 controls in four themes: organisational, people, physical and technological. The library models all 93. It does not model clauses 4 to 10, the management system requirements, as separate rows, so those do not appear here.

Does this mapping include the SOC 2 privacy criteria?

Yes. The library holds the Security common criteria and the Availability, Confidentiality, Processing Integrity and Privacy criteria, 61 points in all. The privacy criteria pair with ISO 27001 mostly through rights fulfilment, incident response, vendor management and retention; for privacy as a management system, ISO/IEC 27701 is the closer standard.

Should we do SOC 2 or ISO 27001 first?

Follow your buyers. SOC 2 reports are the common ask from North American customers, ISO 27001 certificates in Europe, India and much of Asia. Because the controls overlap this heavily, the second costs far less than the first if the controls are held once and mapped, not copied into a second project.

Can I download this mapping?

Use Copy as CSV below the table. It copies one line per control and requirement with the library's description, ready to paste into a spreadsheet. The mapping is generated from the control library the product uses, so it changes when the library does.

Book a walkthrough

Run SOC 2 and ISO 27001 on one control set.

Thirty minutes. We show one control tested once and landing against a SOC 2 criterion and an ISO 27001 control, with the evidence behind both.