The AICPA Trust Services Criteria support examination of controls relevant to security, availability, processing integrity, confidentiality and privacy. A SOC 2 engagement evaluates the applicable criteria within a defined service-organisation system and reporting scope. See the AICPA SOC 2 resources.
Use in a programme
Identify the services, systems, commitments and criteria included in the intended examination. Document the controls and supporting evidence that address them. A requirement mapping helps organise this work, but does not establish the auditor's conclusion.
SOC 2 is an assurance-reporting engagement, not an ISO-style management-system certification. Keep the report's scope, period and conclusion with the evidence you use to assess a service provider.
Use in CSFaaS
The reviewed library labels its entry AICPA 2017 Updates - EN. AICPA's resource page identifies the 2017 Trust Services Criteria with revised points of focus from 2022. Verify which source material the imported entry represents before using it as an assessment baseline.
Link relevant policy controls, assign owners and attach evidence. Describe workspace adaptations clearly and distinguish internal maturity scores from the outcome of a SOC examination.