# SOC 2 Trust Services Criteria

Framework id: `soc2_tsc`. Audit Framework. Publisher: AICPA. Version: 2017. Region: Global. Mapping licence: CC BY-SA 4.0.
Source text: https://www.aicpa-cima.com/topic/audit-assurance/audit-and-assurance-greater-than-soc-2

Each line is a clause, the NIST SP 800-53 controls OSA maps to it, and OSA's estimate of how far those controls cover it.
Clause titles and coverage figures are OSA's own summaries and estimates. No line-by-line check against the source text is recorded for this framework, so quote the source, not this card.

## Clauses (122, average coverage 66%)
- A1.1 The entity maintains, monitors, and evaluates current processing capacity and use of system components (infrastructure, data, and software) to manage capacity demand and to enable the implementation of additional capacity to help meet its objectives: SC-05, SC-06 (65%)
- A1.1-POF1 A1.1 POF1: Manages capacity to meet objectives — Processing capacity and use of system components are managed: SC-05 (60%)
- A1.2 The entity authorizes, designs, develops or acquires, implements, operates, approves, maintains, and monitors environmental protections, software, data backup processes, and recovery infrastructure to meet its objectives: CP-01, CP-02, CP-06, CP-07, CP-08, CP-09, CP-10, PE-01, PE-09, PE-10, PE-11, PE-12, PE-13, PE-14, PE-15, PE-16, PE-17, PE-18, PE-19, RA-03, SC-24 (85%)
- A1.2-POF1 A1.2 POF1: Implements recovery infrastructure and software — Recovery infrastructure is implemented and maintained: CP-01, CP-02, CP-10, PE-01, RA-01 (85%)
- A1.2-POF2 A1.2 POF2: Implements environmental protections — Environmental protections for data centers and facilities are implemented: CP-01, CP-02, CP-10, PE-01, PE-14 (90%)
- A1.2-POF3 A1.2 POF3: Implements data backup processes — Data backup and recovery processes are implemented and maintained: CP-01, CP-02, CP-10, PE-01 (90%)
- A1.3 The entity tests recovery plan procedures supporting system recovery to meet its objectives: CP-04 (90%)
- C1.1 The entity identifies and maintains confidential information to meet the entity's objectives related to confidentiality: CM-12, MP-01, MP-02 (80%)
- C1.1-POF1 C1.1 POF1: Identifies confidential information — The entity has procedures to identify confidential information: PL-02 (75%)
- C1.2 The entity disposes of confidential information to meet the entity's objectives related to confidentiality: AU-11, SI-12 (85%)
- CC1.1 COSO Principle 1: The entity demonstrates a commitment to integrity and ethical values: CA-07, PL-04, PL-09, PS-01 (35%)
- CC1.1-POF1 CC1.1 POF1: Sets the tone at the top — The board of directors and management demonstrate commitment to integrity and ethical values: PS-01 (20%)
- CC1.1-POF2 CC1.1 POF2: Establishes standards of conduct — Expectations of the board and senior management concerning integrity and ethical values are defined: no control mapped (25%)
- CC1.1-POF3 CC1.1 POF3: Evaluates adherence to standards of conduct — Processes are in place to evaluate performance against standards of conduct: CA-02, CA-07, PS-01 (20%)
- CC1.1-POF4 CC1.1 POF4: Addresses deviations in a timely manner — Deviations from standards of conduct are identified and remedied in a timely manner: PS-08 (30%)
- CC1.2 COSO Principle 2: The board of directors demonstrates independence from management and exercises oversight of the development and performance of internal control: PS-02 (25%)
- CC1.2-POF1 CC1.2 POF1: Establishes oversight responsibilities — The board identifies and accepts its oversight responsibilities in relation to established requirements and expectations: AC-01, AT-01, AU-01, CA-01, CM-01, CP-01, IA-01, IR-01, MA-01, MP-01, PE-01, PL-01, PS-01, PS-02, PT-01, RA-01, SA-01, SC-01, SI-01, SR-01 (20%)
- CC1.3 COSO Principle 3: Management establishes, with board oversight, structures, reporting lines, and appropriate authorities and responsibilities in the pursuit of objectives: PS-02 (45%)
- CC1.3-POF1 CC1.3 POF1: Considers all structures of the entity — Management and the board consider the multiple structures used to support the achievement of objectives: no control mapped (30%)
- CC1.4 COSO Principle 4: The entity demonstrates a commitment to attract, develop, and retain competent individuals in alignment with objectives: AT-01, AT-06, PS-01, PS-09, SA-02 (55%)
- CC1.4-POF1 CC1.4 POF1: Establishes policies and practices — Policies and practices reflect expectations of competence necessary to support the achievement of objectives: AC-01, AT-01, AU-01, CA-01, CM-01, CP-01, IA-01, IR-01, MA-01, MP-01, PE-01, PL-01, PS-01, PT-01, RA-01, SA-01, SC-01, SI-01, SR-01 (50%)
- CC1.4-POF2 CC1.4 POF2: Evaluates competence and addresses shortcomings — The board and management evaluate competence and address shortcomings: AT-06, PS-01, PS-02, SA-04, SR-01, SR-06 (40%)
- CC1.4-POF3 CC1.4 POF3: Attracts, develops, and retains individuals — The entity provides mentoring and training to attract, develop, and retain sufficient and competent personnel: AT-01, PS-01, SA-04, SR-01, SR-06 (45%)
- CC1.4-POF4 CC1.4 POF4: Plans and prepares for succession — Senior management and the board develop succession plans for key roles: no control mapped (15%)
- CC1.5 COSO Principle 5: The entity holds individuals accountable for their internal control responsibilities in the pursuit of objectives: PL-01, PS-02, PS-04, PS-05, PS-06, PS-08, PS-09 (50%)
- CC1.5-POF1 CC1.5 POF1: Enforces accountability through structures, authorities, and responsibilities — Management and the board establish mechanisms to communicate and hold individuals accountable: no control mapped (45%)
- CC2.1 COSO Principle 13: The entity obtains or generates and uses relevant, quality information to support the functioning of internal control: MP-01, PL-02 (55%)
- CC2.1-POF1 CC2.1 POF1: Identifies information requirements — A process is in place to identify information required to support internal control: no control mapped (45%)
- CC2.2 COSO Principle 14: The entity internally communicates information, including objectives and responsibilities for internal control, necessary to support the functioning of internal control: CA-07, PL-01, PT-01, SA-08, SC-01, SI-01, SR-07 (50%)
- CC2.2-POF1 CC2.2 POF1: Communicates internal control information — A process is in place to communicate required information to enable all personnel to understand and carry out their responsibilities: AC-01, AT-01, AU-01, CA-01, CM-01, CP-01, IA-01, IR-01, MA-01, MP-01, PE-01, PL-01, PS-01, PT-01, RA-01, SA-01, SC-01, SI-01, SR-01 (50%)
- CC2.2-POF3 CC2.2 POF3: Communicates with the board of directors — Information necessary for the board to oversee internal control is communicated: IR-01, IR-04, PS-01 (25%)
- CC2.2-POF7 CC2.2 POF7: Communicates objectives and changes to objectives — The entity communicates its objectives and changes to those objectives: AC-01, AT-01, AU-01, CA-01, CM-01, CP-01, IA-01, IR-01, MA-01, MP-01, PE-01, PL-01, PS-01, PT-01, RA-01, SA-01, SC-01, SI-01, SR-01 (40%)
- CC2.2-POF10 CC2.2 POF10: Provides separate communication lines — Separate communication channels such as whistle-blower hotlines are in place and serve as fail-safe mechanisms: IR-01, IR-04 (10%)
- CC2.3 COSO Principle 15: The entity communicates with external parties regarding matters affecting the functioning of internal control: CA-07, IR-06, PL-01 (45%)
- CC2.3-POF1 CC2.3 POF1: Communicates to external parties — Processes are in place to communicate relevant information to external parties: IR-06 (45%)
- CC2.3-POF12 CC2.3 POF12: Provides information on notification agreements — The entity notifies external parties of system changes affecting their operation: SA-04, SR-01, SR-08 (40%)
- CC3.1 COSO Principle 6: The entity specifies objectives with sufficient clarity to enable the identification and assessment of risks relating to objectives: CA-02, PL-01, RA-01, RA-09, SR-02, SR-07 (50%)
- CC3.2 COSO Principle 7: The entity identifies risks to the achievement of its objectives across the entity and analyzes risks as a basis for determining how the risks should be managed: PT-01, RA-02, RA-07, SA-08, SC-01, SI-01, SR-02, SR-07 (75%)
- CC3.2-POF1 CC3.2 POF1: Includes entity, subsidiary, division, operating unit, and functional levels: RA-01, RA-03 (60%)
- CC3.3 COSO Principle 8: The entity considers the potential for fraud in assessing risks to the achievement of objectives: SA-04, SA-09, SR-01, SR-05 (30%)
- CC3.3-POF1 CC3.3 POF1: Considers various types of fraud — The entity considers fraudulent reporting, possible loss of assets, and corruption: PS-01 (20%)
- CC3.4 COSO Principle 9: The entity identifies and assesses changes that could significantly impact the system of internal control: CM-03, CM-04, PL-01, SA-04, SR-06 (65%)
- CC3.4-POF1 CC3.4 POF1: Assesses changes in the external environment — The entity considers changes in regulatory, economic, and physical environments: RA-01, RA-03 (35%)
- CC3.4-POF2 CC3.4 POF2: Assesses changes in the business model — The entity considers the impact of new business lines, altered compositions of existing business lines, and acquired or divested business operations: RA-01, RA-03 (15%)
- CC3.4-POF3 CC3.4 POF3: Assesses changes in leadership — The entity considers changes in management and other personnel: RA-01, RA-03 (25%)
- CC4.1 COSO Principle 16: The entity selects, develops, and performs ongoing and/or separate evaluations to ascertain whether the components of internal control are present and functioning: CA-01, CA-02, PL-02, RA-01, RA-03, SA-02, SR-02, SR-07 (70%)
- CC4.1-POF1 CC4.1 POF1: Considers a mix of ongoing and separate evaluations — Management includes a balance of ongoing evaluations built into processes and separate evaluations: SA-11 (70%)
- CC4.2 COSO Principle 17: The entity evaluates and communicates internal control deficiencies in a timely manner to those parties responsible for taking corrective action, including senior management and the board of directors, as appropriate: CA-05 (65%)
- CC4.2-POF1 CC4.2 POF1: Assesses results — Management and the board assess results of ongoing and separate evaluations: CA-07 (55%)
- CC4.2-POF2 CC4.2 POF2: Communicates deficiencies — Deficiencies are communicated to parties responsible for taking corrective action and to senior management and the board as appropriate: CA-07 (55%)
- CC5.1 COSO Principle 10: The entity selects and develops control activities that contribute to the mitigation of risks to the achievement of objectives to acceptable levels: AC-05, PT-01, RA-01, SA-08, SC-01, SI-01 (70%)
- CC5.2 COSO Principle 11: The entity also selects and develops general control activities over technology to support the achievement of objectives: CA-02, PL-01, PT-01, SA-01, SA-03, SA-04, SA-08, SC-01, SI-01 (85%)
- CC5.2-POF1 CC5.2 POF1: Determines dependency between the use of technology in business processes and technology general controls: no control mapped (60%)
- CC5.3 COSO Principle 12: The entity deploys control activities through policies that establish what is expected and in procedures that put policies into action: AC-01, AT-01, AU-01, CA-01, CM-01, CP-01, IA-01, IR-01, MA-01, MP-01, PE-01, PL-01, PL-09, PS-01, PS-02, PS-07, PT-01, RA-01, SA-01, SC-01, SI-01, SR-01 (80%)
- CC5.3-POF1 CC5.3 POF1: Establishes policies and procedures to support deployment of management's directives: AC-01, AT-01, AU-01, CA-01, CM-01, CP-01, IA-01, IR-01, MA-01, MP-01, PE-01, PL-01, PS-01, PT-01, RA-01, SA-01, SC-01, SI-01, SR-01 (80%)
- CC5.3-POF6 CC5.3 POF6: Reassesses policies and procedures — Management periodically reassesses policies and procedures for continued relevance and effectiveness: AC-01, AT-01, AU-01, CA-01, CM-01, CP-01, IA-01, IR-01, MA-01, MP-01, PE-01, PL-01, PS-01, PT-01, RA-01, SA-01, SC-01, SI-01, SR-01 (75%)
- CC6.1 Logical and Physical Access Controls — The entity implements logical access security software, infrastructure, and architectures over protected information assets to protect them from security events to meet the entity's objectives: AC-01, AC-02, AC-03, AC-04, AC-06, CA-09, IA-01, IA-02, IA-03, IA-04, IA-05, SC-01, SC-07, SC-08, SC-12, SC-13, SC-17 (90%)
- CC6.1-POF1 CC6.1 POF1: Identifies and manages the inventory of information assets — The entity identifies and manages information assets: CM-08, CM-12, SA-05 (85%)
- CC6.1-POF2 CC6.1 POF2: Restricts logical access — Access to information assets is restricted through logical access security measures: CA-01, CA-02, PT-01, SA-08, SC-01, SI-01 (95%)
- CC6.1-POF3 CC6.1 POF3: Considers network segmentation — Network segmentation is implemented to restrict access: AC-01, IA-01, IA-02, IA-03, IA-04 (95%)
- CC6.1-POF4 CC6.1 POF4: Manages points of access — Points of access to information assets are managed and protected: IA-02, IA-04 (90%)
- CC6.1-POF5 CC6.1 POF5: Restricts access to information assets — Access to information assets is restricted through identity management: SC-01, SC-07 (95%)
- CC6.1-POF6 CC6.1 POF6: Manages identification and authentication — User identification and authentication is managed: AC-04 (95%)
- CC6.1-POF7 CC6.1 POF7: Manages credentials for infrastructure and software — System and application credentials are managed: AC-01, AC-06, AU-02, CM-02, CM-06, CM-07, IA-01, SA-08 (90%)
- CC6.1-POF8 CC6.1 POF8: Uses encryption to protect data — Encryption is used to protect data at rest and in transit: AC-01, IA-01, IA-02, IA-03 (90%)
- CC6.1-POF9 CC6.1 POF9: Protects encryption keys — Encryption keys are managed to protect data: AC-01, CA-01, CA-06, IA-01 (90%)
- CC6.2 Prior to issuing system credentials and granting system access, the entity registers and authorizes new internal and external users whose access is administered by the entity: no control mapped (90%)
- CC6.2-POF1 CC6.2 POF1: Controls access credentials to protected assets — New internal and external users are registered and authorized prior to being issued credentials and granted access: no control mapped (90%)
- CC6.3 The entity authorizes, modifies, or removes access to data, software, functions, and other protected information assets based on roles, responsibilities, or the system design and changes, giving consideration to the concepts of least privilege and segregation of duties: no control mapped (95%)
- CC6.3-POF1 CC6.3 POF1: Creates or modifies access — Processes are in place to create or modify access to protected assets: no control mapped (95%)
- CC6.4 The entity restricts physical access to facilities and protected information assets to authorized personnel to meet the entity's objectives: PE-01, PE-02, PE-03 (90%)
- CC6.5 The entity discontinues logical and physical access to protected information assets when that access is no longer required: MP-01, MP-06, SI-12, SR-12 (90%)
- CC6.6 The entity implements logical access security measures to protect against threats from sources outside its system boundaries: AC-01, AC-02, AC-03, AC-04, AC-05, AC-17, IA-01, IA-04, SC-01, SC-07, SI-03, SI-04, SI-05, SI-07, SI-10 (90%)
- CC6.6-POF1 CC6.6 POF1: Restricts access — The entity restricts access through network security and entry points: AC-04, SC-01, SC-07 (90%)
- CC6.6-POF2 CC6.6 POF2: Protects identification and authentication credentials — Identification and authentication credentials are protected during transmission outside system boundaries: AC-01, AC-02, AC-03, AC-05, IA-01, IA-04, SC-01, SC-13, SI-03, SI-04, SI-05, SI-07, SI-10 (90%)
- CC6.6-POF3 CC6.6 POF3: Requires additional authentication or credentials — Additional authentication measures are required for access from outside system boundaries: AC-01, AC-17, IA-01, IA-04, SC-01, SC-07 (85%)
- CC6.7 The entity restricts the transmission, movement, and removal of information to authorized internal and external users and processes, and protects it during transmission, movement, or removal to meet the entity's objectives: AC-20, CM-13, MP-01, SC-08, SC-13 (85%)
- CC6.7-POF1 CC6.7 POF1: Restricts the ability to perform transmission — Data loss prevention processes are in place to detect and prevent unauthorized transmission: AU-02, CM-02, CM-06, CM-07, SA-08 (75%)
- CC6.8 The entity implements controls to prevent or detect and act upon the introduction of unauthorized or malicious software to meet the entity's objectives: SC-07, SI-03, SI-07 (90%)
- CC7.1 To meet its objectives, the entity uses detection and monitoring procedures to identify changes to configurations that result in the introduction of new vulnerabilities, and susceptibilities to newly discovered vulnerabilities: AU-02, CA-09, CM-01, CM-02, CM-06, RA-05, SA-08, SC-45 (90%)
- CC7.1-POF1 CC7.1 POF1: Uses defined configuration standards — The entity uses defined configuration standards to assess newly deployed or changed IT assets: AU-02, CM-01, CM-02, CM-06, SA-08 (90%)
- CC7.2 The entity monitors system components and the operation of those components for anomalies that are indicative of malicious acts, natural disasters, and errors affecting the entity's ability to meet its objectives; anomalies are analyzed to determine whether they represent security events: AU-01, AU-02, AU-06, AU-07, SC-45, SI-04 (90%)
- CC7.2-POF1 CC7.2 POF1: Implements detection policies, procedures, and tools — The entity implements and maintains detection policies, procedures, and tools: AC-01, AT-01, AU-01, AU-02, AU-06, CA-01, CM-01, CP-01, IA-01, IR-01, MA-01, MP-01, PE-01, PL-01, PS-01, PT-01, RA-01, SA-01, SC-01, SI-01, SI-04, SR-01 (90%)
- CC7.2-POF2 CC7.2 POF2: Designs detection measures — Detection measures are designed to identify anomalies including known and unknown threats: no control mapped (85%)
- CC7.3 The entity evaluates security events to determine whether they could or have resulted in a failure of the entity to meet its objectives (security incidents) and, if so, takes actions to prevent or address such failures: AU-02, AU-06, AU-07, IR-01, IR-04, RA-03, SI-04 (90%)
- CC7.3-POF1 CC7.3 POF1: Responds to security incidents — Procedures are in place to respond to security incidents: IR-01, IR-04 (90%)
- CC7.4 The entity responds to identified security incidents by executing a defined incident response program to understand, contain, remediate, and communicate security incidents, as appropriate: IR-01, IR-04, IR-05, IR-06, IR-09 (90%)
- CC7.4-POF1 CC7.4 POF1: Assigns roles and responsibilities — Roles and responsibilities for responding to incidents are assigned: IR-01, IR-04 (90%)
- CC7.4-POF2 CC7.4 POF2: Contains security incidents — Processes are in place to contain security incidents: IR-01, IR-04 (90%)
- CC7.4-POF3 CC7.4 POF3: Mitigates ongoing security incidents — Procedures are in place to mitigate the effects of ongoing incidents: IR-01, IR-04 (85%)
- CC7.4-POF4 CC7.4 POF4: Ends threats posed by security incidents — Steps are taken to end the threats posed by security incidents: IR-01, IR-04 (85%)
- CC7.4-POF5 CC7.4 POF5: Restores operations — Procedures are in place to restore normal operations: CP-01, CP-02, CP-10, IR-01, IR-04, SC-24 (85%)
- CC7.4-POF6 CC7.4 POF6: Develops and implements communication protocols for security incidents: IR-01, IR-04, IR-05, IR-06 (80%)
- CC7.4-POF10 CC7.4 POF10: Meets regulatory notification requirements — The entity meets notification requirements for security incidents: CP-04, IR-01, IR-04 (75%)
- CC7.4-POF11 CC7.4 POF11: Obtains understanding of nature of incident — The entity obtains understanding of the incident nature and scope: IR-01, IR-04 (85%)
- CC7.4-POF12 CC7.4 POF12: Remediates identified vulnerabilities — The entity remediates identified vulnerabilities following incidents: IR-01, IR-04 (85%)
- CC7.4-POF13 CC7.4 POF13: Evaluates the effectiveness of incident response — The entity evaluates incident response effectiveness: IR-01, IR-04, IR-06 (80%)
- CC7.5 The entity identifies, develops, and implements activities to recover from identified security incidents: CP-01, CP-02, CP-04, CP-09, CP-10 (85%)
- CC8.1 The entity authorizes, designs, develops or acquires, configures, documents, tests, approves, and implements changes to infrastructure, data, software, and procedures required to meet its objectives: AU-02, CM-02, CM-03, CM-06, SA-03, SA-08 (85%)
- CC8.1-POF1 CC8.1 POF1: Manages changes throughout the system life cycle — Processes are in place to manage changes to system components through the life cycle: CM-03, SA-03 (85%)
- CC9.1 The entity identifies, selects, and develops risk mitigation activities for risks arising from potential business disruptions: CP-01, CP-02, CP-10, RA-01, RA-07, RA-09, SA-04, SR-01, SR-02, SR-03, SR-05, SR-06 (75%)
- CC9.1-POF1 CC9.1 POF1: Considers mitigation through business continuity — The entity considers mitigation through contingency planning: CP-01, CP-02, CP-10 (80%)
- CC9.2 The entity assesses and manages risks associated with vendors and business partners: SA-04, SR-01, SR-02, SR-07 (80%)
- CC9.2-POF1 CC9.2 POF1: Creates policies for vendor and business partner risk management — Vendor risk management processes are established: SA-04, SR-01, SR-02, SR-07 (80%)
- CC9.2-POF13 CC9.2 POF13: Assesses vendor and business partner risks — The entity periodically assesses vendor and business partner risks: RA-05, SI-02, SI-03, SI-05, SR-06, SR-08 (75%)
- P1.0 Privacy Criteria Introduction — The entity's privacy practices meet its objectives: PT-01, SC-42 (45%)
- P1.1 The entity provides notice to data subjects about its privacy practices to meet the entity's objectives related to privacy: PT-05 (55%)
- P1.1-POF1 P1.1 POF1: Communicates to data subjects — Privacy notices are provided to data subjects: PT-03, PT-05 (55%)
- P1.1-POF5 P1.1 POF5: Provides notice of changes — Data subjects are notified of changes to the entity's privacy practices: AC-01, AT-01, AU-01, CA-01, CM-01, CP-01, IA-01, IR-01, MA-01, MP-01, PE-01, PL-01, PS-01, PT-01, PT-05, RA-01, SA-01, SC-01, SI-01, SR-01 (40%)
- P1.2 The entity communicates choices available regarding the collection, use, retention, disclosure, and disposal of personal information to data subjects and obtains consent: no control mapped (40%)
- P1.3 The entity collects personal information only for the purposes identified in the notice to the data subject: CM-13, SC-42 (50%)
- P1.4 The entity limits the use of personal information to the purposes identified in the notice and for which the data subject has provided explicit consent: CM-13 (50%)
- P1.5 The entity retains personal information consistent with the entity's objectives related to privacy: CM-13 (55%)
- P1.6 The entity disposes of personal information to meet the entity's privacy objectives: CM-13 (65%)
- P1.7 The entity discloses personal information to third parties with the consent of the data subject or as authorized under applicable law or regulation: CM-13 (40%)
- P1.8 The entity provides data subjects with access to their personal information for review and correction: SI-18 (30%)
- P1.9 The entity provides data subjects the ability to update and correct personal information: SI-18 (25%)
- PI1.1 The entity obtains or generates, uses, and communicates relevant, quality information regarding the objectives related to processing, including definitions of data processed and product and service specifications, to support the use of products and services: SA-01 (50%)
- PI1.2 The entity implements policies and procedures over system inputs, including controls over completeness and accuracy, to result in products, services, and reporting to meet the entity's objectives: PL-01, SA-01, SA-04 (60%)
- PI1.3 The entity implements policies and procedures over system processing to result in products, services, and reporting to meet the entity's objectives: PL-01, SA-01, SA-04 (55%)
- PI1.4 The entity implements policies and procedures to make available or deliver output completely, accurately, and timely in accordance with specifications to meet the entity's objectives: AU-02, AU-03, AU-09, PE-05, SA-01 (50%)
- PI1.5 The entity implements policies and procedures to store inputs, items in processing, and outputs completely, accurately, and timely in accordance with system specifications to meet the entity's objectives: AU-09, MP-01, SA-01, SI-12 (55%)

## More
- A pattern's controls with their clauses in this framework: /api/v1/patterns/{id}/crosswalk?framework=soc2_tsc
- Control-to-clause mappings as JSON: /api/v1/frameworks/soc2_tsc?fields=mappings&per_page=100
- Rationale and gaps for each clause, as JSON: https://raw.githubusercontent.com/opensecurityarchitecture/osa-data/main/data/framework-coverage/soc2-tsc.json
- Page for people: /frameworks/soc2-tsc/
- Found an error? Open an issue at https://github.com/opensecurityarchitecture/osa-data/issues with the id, what OSA says and what the source says.
