Long story short…
We know this is a long article, so we’re going to give you the bottom line, up front.
This article applies to you if you manage SOC 2 2017 in Drata. We applied these changes in your account on 5/7/2024.
This update will not impact your framework readiness.
We gave you some additional controls, updated the control details, and refined some of our control-to-requirement mappings. However, you are not required to implement these changes to achieve or maintain compliance with SOC 2. If you want to take advantage of our new control details or control mapping, use the functionality outlined in this article and this article. (Do be aware that if you apply our default mappings, your readiness is likely to change.)
Why do you have more controls in your account if you aren’t required to do anything? Because we wanted to give you all the latest information that we had in the spirit of continuous improvement. We don’t want to hold anything back from you.
Why are we doing this?
Updates from the AICPA
In the fall of 2022, the AICPA released an updated version of the 2017 Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy (2017 TSC) with revised points of focus. The revised points of focus in this version are intended to better support application of the criteria in:
an environment of ever-changing technologies, threats and vulnerabilities, and other matters that may create additional risks to organizations.
addressing changing legal and regulatory requirements and related cultural expectations regarding privacy.
addressing data management (for example, data storage, backup, and retention), particularly when related to confidentiality.
differentiating which points of focus related to privacy may apply only to an organization that is a data controller or only to an organization that is a data processor, as defined in the glossary.
Control library improvements
We have updated the SOC 2 DCF control library to align with the 2022 revisions to the points of focus of the Trust Service Criteria. Additionally, we’ve used this as an opportunity to iterate on the DCF control library as a result of:
Realignment of DCF Controls with other connected Drata features (e.g., monitoring tests, policies, etc.)
Administrative maintenance and standardization
Alignment with evolving industry standards and best practices
Industry developments and emerging technologies (e.g., AI)
Scope calibration and removal of redundancies
Feedback from stakeholders (customers, audit firms, technology partners, etc.)
For more information on how Drata manages the DCF control library and control ↔ requirement mapping, refer to this article.
What changed:
Requirement updates
Under each SOC 2 trust service criterion (requirements), the descriptions of the points of focus have been updated to reflect TSP Section 100 - 2017 Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy (with Revised Points of Focus – 2022). Refer to this AICPA document for the authoritative reference.
DCF Control Library Updates
Below is a summary of the updates we made to the DCF control library.
Please note that these updates are not mandatory to maintain a SOC 2 compliance program because:
The changes to the points of focus in the 2022 revisions do not, in any way, alter the criteria in the 2017 TSC.
The trust services criteria do not prescribe a specific set of controls. Organizations define their own controls and processes based on their perceived risks and business objectives.
Use of the trust services criteria does not require an assessment of whether each point of focus is addressed.
You are encouraged to evaluate these updates and determine whether you want to incorporate these into your SOC 2 compliance program. For example:
You may determine that some of Drata’s new controls added to the SOC 2 catalog are not applicable to your organization, or are not necessary to mitigate a risk and therefore not relevant for your SOC 2 program. In this case, you can choose to mark these new controls out of scope.
You may determine some of Drata’s new controls added to the SOC 2 catalog align with activities that you are already performing in your organization, or are activities that you would like to implement to mitigate risk and enhance your security posture and compliance program. In these cases, you may decide you want to formally manage these controls for your SOC 2, so you keep these new controls in scope.
You may have made customizations to control descriptions that you wish to keep, so you may choose not to apply updates to descriptions based on Drata’s latest template. Alternatively, you may wish to align your control details to Drata’s latest recommendations, so you apply the latest updates to the control name and description to match Drata’s current version.
If you were an existing customer when we made these updates, you will see that we added new controls to your account. However, we did not pre-map them to SOC2 requirements on your behalf because we didn’t want to negatively impact your readiness upon release. This means you are able to review these new controls, and either apply Drata’s default mappings yourself, or you can mark them out of scope if you don’t want to include them in your compliance program.
We make it easy to map your controls and requirements according to our suggestions. Learn how to do that in this article.
Controls currently in the SOC 2 control library that will no longer be mapped to SOC 2 criteria
These controls were in the control library mapped to one or more SOC 2 criteria. The default mappings associated with SOC 2 criteria are now removed. However, if you were an existing customer at the time of the release, we did not remove these mappings on your behalf. If you reset your framework to use the default mappings, then you will see these mappings removed.
Code | Legacy Name | Change Log |
DCF-1 | Customer Data Policies | Removed mapping from SOC 2 and ISO 27001. Consolidated in DCF-37 and DCF-45. |
DCF-2 | Least-Privileged Policy for Sensitive Data Access | Removed mapping from SOC 2 and ISO 27001. Replaced with DCF-69. |
DCF-3 | Require Encryption of Web-Based Admin Access | Removed mapping from SOC 2 and ISO 27001. Generalized in DCF-59. |
DCF-23 | Security Issues are Prioritized | Remove mapping from SOC 2 and ISO 27001. Replaced by DCF-28. |
DCF-24 | SLA for Security Bugs | Remove mappings from SOC 2 and ISO 27001. Replaced by DCF-28. |
DCF-34 | Security Team/Steering Committee | Removed mappings to SOC 2 and ISO 27001. Replaced with DCF-42. |
DCF-35 | Security Team Communicates in a Timely Manner | Removed mappings to SOC 2 and ISO 27001. Deprecated control. |
DCF-40 | Contractor Requirements | Removed SOC 2 and ISO 27001 Mappings. Control replaced by DCF-32, DCF-39, and DCF-44. |
DCF-43 | Termination/Offboarding Checklist | Removed SOC 2 and ISO 27001 Mappings. Control replaced by DCF-70 and DCF-688. |
DCF-53 | Cryptography Policies | Removed mappings for SOC 2 and ISO 27001. Redundant with DCF-181. |
DCF-58 | Authentication Protocol | Removed mapping to SOC 2 and ISO 27001. Replaced by DCF-68, DCF-69, and DCF-747. |
DCF-80 | Log Management System | Removed mapping to SOC 2 and ISO 27001. Replaced by DCF-79 and DCF-28. |
DCF-81 | Databases Monitored and Alarmed | Removed mapping to SOC 2 and ISO 27001. Consolidated in DCF-86. |
DCF-82 | Messaging Queues Monitored and Alarmed | Removed mapping to SOC 2 and ISO 27001. Consolidated in DCF-86. |
DCF-83 | NoSQL Database Monitored and Alarmed | Removed mapping to SOC 2 and ISO 27001. Consolidated in DCF-86. |
DCF-84 | Servers Monitored and Alarmed | Removed mapping to SOC 2 and ISO 27001. Consolidated in DCF-86. |
DCF-89 | Cloud Infrastructure Linked to Drata | Removed mapping to SOC 2 and ISO 27001. Consolidated in DCF-160 |
DCF-93 | Credential Keys Managed | Removed mapping to SOC 2 and ISO 27001. Redundant with DCF-181. |
DCF-98 | Daily Backup Statuses Monitored | Removed mapping to SOC 2 and ISO 27001. Redundant with DCF-99. |
DCF-113 | Review Privacy Notice Annually | Removed SOC 2 and ISO 27001 mapping. Redundant with DCF-120. |
DCF-114 | Privacy Policy Publicly Available | Removed SOC 2 and ISO 27001 mapping. Redundant with DCF-65. |
DCF-116 | Accept The Privacy Policy | Removed SOC 2 and ISO 27001 mapping. Redundant with DCF-112. |
DCF-117 | Minimal Information Required | Removed SOC 2 and ISO 27001 mapping. Deprecated control. |
DCF-118 | Third Party Reliability | Removed SOC 2 and ISO 27001 mapping. Replaced by DCF-507. |
DCF-119 | Allowable Use and Disclosure | Removed SOC 2 and ISO 27001 mapping. Redundant with DCF-115. |
DCF-121 | Purposeful Use Only | Removed SOC 2 and ISO 27001 mapping. Deprecated control. |
DCF-124 | Require Authentication for Access | Removed SOC 2 and ISO 27001 mapping. Redundant with DCF-126. |
DCF-125 | Users Can Access All Their Information | Removed SOC 2 and ISO 27001 mapping. Redundant with DCF-126. |
DCF-128 | Disclosure with 3rd Parties | Removed SOC 2 and ISO 27001 mapping. Redundant with DCF-132. |
DCF-129 | PII with 3rd Parties and Vendors | Removed SOC 2 and ISO 27001 mapping. Redundant with DCF-136. |
DCF-131 | Incident Report Template and Process | Removed SOC 2 and ISO 27001 mapping. Redundant with DCF-159. |
DCF-133 | Unauthorized Disclosures by 3rd Parties | Removed SOC 2 and ISO 27001 mapping. Redundant with DCF-127. |
DCF-134 | 3rd Parties and Vendors Given Instructions on Breach Reporting | Removed SOC 2 and ISO 27001 mapping. Redundant with DCF-127. |
DCF-137 | Data Entry Field Completion Automated | Removed SOC 2 and ISO 27001 mapping. Redundant with DCF-110 and DCF-111. |
DCF-138 | Confirmation Before Submission | Removed SOC 2 and ISO 27001 mapping. Deprecated control. |
DCF-139 | Contact Information for Privacy Concerns | Removed SOC 2 and ISO 27001 mapping. Redundant with DCF-140. |
DCF-142 | Quarterly Review of Privacy Compliance | Removed SOC 2 and ISO 27001 mapping. Redundant with DCF-146. |
DCF-143 | Board Oversight Briefings Conducted | Removed SOC 2 and ISO 27001 mapping. Redundant with DCF-146. |
DCF-145 | Board Expertise Developed | Removed SOC 2 and ISO 27001 mapping. Replaced by DCF-41. |
DCF-147 | Physical Access to Facilities is Protected | Removed SOC 2 and ISO 27001 mapping. Redundant with DCF-94. |
DCF-148 | Regression Testing in Place | Removed SOC 2 and ISO 27001 mapping. Redundant with DCF-155. |
DCF-151 | FIM (File Integrity Monitoring) Software in Place | Removed SOC 2 and ISO 27001 mapping. Replaced by DCF-478. |
DCF-153 | Conduct Control Self-Assessments | Removed SOC 2 and ISO 27001 mapping. Redundant with DCF-160. |
DCF-158 | MFA Available for External Users | Removed SOC 2 and ISO 27001 mappings. Replaced by DCF-747. |
New controls in the database that will be mapped to SOC 2
These controls did not previously exist in our database. They will be added to the database and mapped to one or more SOC 2 criteria. However, if you were an existing customer we did not pre-map them for you upon release. We gave these controls to you, but it’s up to you if you want to apply Drata’s default mappings to put them to use.
Code | Control Name |
DCF-543 | Communication of Changes in Subprocessors |
DCF-570 | Disciplinary Process |
DCF-571 | Fire Detection and Suppression |
DCF-572 | Temperature Monitoring Systems |
DCF-573 | Uninterruptible Power Supply |
DCF-574 | Mobile Device Management Software |
DCF-684 | Redundancy of Processing Facilites |
DCF-746 | Privacy Training |
DCF-747 | Secure Log-on for Customers |
DCF-748 | Segmentation of Networks |
DCF-749 | Leak Detection System |
DCF-753 | Mechanisms to Object to PII Processing |
DCF-754 | Right to Access |
DCF-756 | Dual Opt-In for Consent to Sell PII |
DCF-757 | User and System Guides |
DCF-765 | Limit Collection of PII |
DCF-770 | Consulting with Customer Prior to PII Disclosures |
DCF-774 | Data Processing Monitoring |
DCF-775 | Cloud Deletion Protection |
DCF-776 | Principle of Least Privilege |
DCF-777 | Cloud Resource Tagging |
DCF-778 | Fraud Risk Assessment |
DCF-779 | Key Rotation |
DCF-781 | Secure Login Procedures |
DCF-782 | Cloud Storage Lifecycle |
DCF-783 | Secret Rotation |
DCF-784 | Software Composition Analysis (SCA) |
DCF-785 | Secure Runtime Configurations |
DCF-786 | Defined Company Objectives |
Existing controls in the DCF control library that will now be mapped to SOC 2
These controls already exist in our DCF control library but are not mapped to SOC 2 criteria (i.e., they currently map to other frameworks offered by Drata). They will now be mapped to at least one SOC 2 criteria. However, if you were an existing customer, we did not pre-map them for you upon release. We gave these controls to you, but it’s up to you if you want to apply Drata’s default mappings to put them to use.
Code | Control Name |
DCF-173 | Employment Terms & Conditions |
DCF-204 | Dataflow Diagram |
DCF-253 | Data Secure Disposal |
DCF-273 | Strong Key Generation Policies and Procedures |
DCF-278 | Key Retirement Policies and Procedures |
DCF-293 | Anti-Malware Capabilities and Automatic Updates |
DCF-294 | Anti-Malware Tools Behavior |
DCF-312 | Secure Code Development Training |
DCF-326 | Need-to-Know Principle |
DCF-339 | Account Lockout after Failed Logins |
DCF-340 | Lockout Duration |
DCF-350 | Password History Enforcement |
DCF-355 | MFA for Remote Network Access |
DCF-356 | Communication of Authentication Best Practices |
DCF-363 | Entry Controls in Place |
DCF-365 | Secure Physical Access Control Mechanisms |
DCF-372 | Restricted Access to Badge System |
DCF-374 | Visitors Authorized and Escorted |
DCF-375 | Personnel and Visitor Badges |
DCF-377 | Visitor Badge Control |
DCF-378 | Visitor Log |
DCF-381 | Media Physically Secured or Encrypted |
DCF-406 | Audit Logging |
DCF-407 | Audit Logs Data Points |
DCF-409 | Audit Trail for Privileged Access |
DCF-411 | Audit Trail for Invalid Access Attempts |
DCF-412 | Audit Trail for Identification and Authentication Mechanism Changes |
DCF-414 | Audit Trail of System-Level Object Changes |
DCF-478 | Change Detection Mechanism |
DCF-503 | Multiple Methods for Security Awareness |
DCF-507 | Vendor Due Diligence |
DCF-522 | Anti-Malware Scans of Media |
DCF-527 | Designated Data Protection Officer |
DCF-529 | Data Subject Consent |
DCF-531 | Notification of Disclosures to Third Parties |
DCF-536 | Record of Processing Activity (ROPA) |
DCF-537 | Data Processing Agreements |
DCF-540 | Timely Response to Data Subject Requests |
DCF-541 | Procedures for Management of Data Subject Rights |
DCF-549 | Identity Verification for Data Subject Requests |
DCF-557 | Shared Account Management |
DCF-558 | Restrictions on Software Installation |
DCF-562 | Management of Utility Programs |
DCF-567 | Change Management Policy |
DCF-677 | Software Update and Patch Management |
DCF-681 | Phishing Simulations |
DCF-688 | Return of Assets |
DCF-689 | On-Call Team |
DCF-691 | Marketing Express Consent |
DCF-712 | Static Application Security Testing |
DCF-741 | Logging and Monitoring Policy |
Complete SOC 2 Control Catalog as of May 7, 2024
In case anything above is lacking, we also wanted to provide you with a complete list of controls that are mapped to SOC2 as of the date of the release.
Code | Name | SOC 2 Criteria |
DCF-4 | Version Control System | CC8.1 |
DCF-5 | Change Review Process | CC8.1 |
DCF-6 | Production Changes Restricted | CC8.1, CC5.1 |
DCF-7 | Separate Environments | CC8.1 |
DCF-8 | External Communication Channels | CC2.3 |
DCF-9 | Internal Communication Channels | CC2.2, CC1.1, CC1.5 |
DCF-10 | Access Control Policy | CC6.2, CC6.3 |
DCF-11 | Periodic Access Reviews | CC4.1, CC6.2, CC6.4, CC6.3 |
DCF-12 | System Security Configuration and Hardening Standards | CC7.1, CC6.1 |
DCF-13 | Information Security Policies | CC2.1, CC5.3 |
DCF-14 | Organizational Chart | CC1.3, CC1.5, CC2.2 |
DCF-15 | Risk Assessment Policy | CC3.2, CC3.3, CC4.2, CC5.3, CC3.4, CC3.1 |
DCF-16 | Periodic Risk Assessment | CC3.2, CC3.3, CC4.2, CC5.1, CC5.2, CC3.4, A1.2, CC3.1 |
DCF-17 | Risk Treatment Plan | CC3.2, CC3.3, CC4.2, CC5.1, CC5.2, CC3.4, CC3.1 |
DCF-18 | Vulnerability Scans | CC3.2, CC4.1, CC5.2, CC7.1 |
DCF-19 | Penetration Tests | CC4.1, CC5.2, CC7.1 |
DCF-20 | Asset Inventory | CC2.1, CC6.1 |
DCF-21 | Architectural Diagram | CC2.1 |
DCF-22 | Network Diagram | CC2.1 |
DCF-25 | Disaster Recovery Plan | CC5.3, CC9.1, A1.2, A1.3 |
DCF-26 | BCP/DR Tests | A1.2, A1.3 |
DCF-27 | Region or Zone Redundancy | CC9.1, A1.2 |
DCF-28 | Security Events Tracked and Evaluated | CC7.3, CC7.4, CC7.5 |
DCF-29 | Incident Response Team | CC7.4, CC7.5, CC7.3 |
DCF-30 | Incident Response Lessons Learned Documented | CC7.3, CC7.4, CC7.5 |
DCF-31 | Software Development Policies | CC8.1 |
DCF-32 | Security Policies | CC1.1, CC2.2, CC2.1, CC5.2, CC5.3 |
DCF-33 | Periodic Policy Reviews | CC2.1, CC2.2, CC5.3 |
DCF-36 | Periodic Security Training | CC1.4, CC2.2, CC5.2 |
DCF-37 | Acceptable Use Policy | CC5.3 |
DCF-38 | Performance Evaluations | CC1.4, CC1.5, CC1.1 |
DCF-39 | Background Checks | CC1.1 |
DCF-41 | Independent Board of Directors | CC1.2 |
DCF-42 | Defined Roles and Responsibilities | CC1.3, CC1.2 |
DCF-44 | Code of Conduct | CC1.1, CC1.4, CC1.5, CC2.2, CC5.3 |
DCF-45 | Data Protection Policy | CC6.7, C1.1, P4.2 |
DCF-46 | Formal Screening Process | CC1.4 |
DCF-47 | Job Descriptions | CC1.4, CC2.2 |
DCF-48 | Screen Lockout | CC6.6 |
DCF-49 | Password Manager | CC6.1 |
DCF-50 | Antimalware Software on Devices | CC6.8, CC7.1 |
DCF-51 | Automated Updates on Devices | CC7.1, CC6.7 |
DCF-52 | Hard-Disk Encryption | CC6.1, CC6.7 |
DCF-54 | Encryption at Rest | CC6.1, C1.1, P4.2, CC6.6, PI1.5, PI1.4 |
DCF-55 | Encryption in Transit | CC6.6, CC6.7, CC6.1, C1.1, P4.2 |
DCF-56 | Vendor Register and Agreements | CC3.2, CC9.2 |
DCF-57 | Vendor Compliance Monitoring | CC3.2, CC9.2, P6.4, P6.5 |
DCF-59 | Privileged Access Restricted | CC6.1, C1.1, P4.2, CC5.2, PI1.5, PI1.4 |
DCF-60 | Secure Password Storage | CC6.1 |
DCF-61 | Customer Data Segregation | CC6.1, C1.1, P4.2 |
DCF-62 | Inactivity and Browser Exit Logout | CC6.6 |
DCF-63 | Terms of Service | CC2.3 |
DCF-64 | Commitments Communicated to Customers | CC2.3, CC3.1 |
DCF-65 | Public Privacy Policy | P1.1, CC2.3 |
DCF-66 | Master Service Agreements | CC2.3 |
DCF-67 | Multi-Factor Authentication | CC6.1, CC6.6, C1.1, P4.2 |
DCF-68 | Authentication Configurations | CC6.1, CC6.6, C1.1, P4.2 |
DCF-69 | Access Provisioning | CC6.2, CC6.1, CC6.3, CC5.1, CC5.2 |
DCF-70 | Access Deprovisioning | CC6.2, CC6.1, CC6.3 |
DCF-71 | Unique User IDs | CC6.1 |
DCF-72 | Root Access Control | CC6.1 |
DCF-73 | Access to Remote Server Administration Ports Restricted | CC6.6 |
DCF-74 | Communication of System Changes | CC2.3 |
DCF-75 | Restricted Public Access | CC6.6, CC6.1 |
DCF-76 | Critical Change Management | CC8.1 |
DCF-77 | Database Backups | A1.2 |
DCF-78 | Storage Bucket Versioning | CC7.1 |
DCF-79 | Logging System | CC7.2, PI1.3 |
DCF-85 | Network Security Controls | CC6.6, CC6.1 |
DCF-86 | Operational Monitoring | CC7.2, CC4.1, A1.1, CC7.1 |
DCF-87 | Threat Detection System | CC6.8, CC7.1, CC7.2, CC6.6 |
DCF-88 | Web Application Firewall | CC6.6, CC7.2 |
DCF-90 | Root Infrastructure Account Monitored | CC7.2, CC6.1 |
DCF-91 | Intrusion Detection/Prevention System | CC6.6, CC7.1, CC7.2 |
DCF-92 | Encrypted Remote Production Access | CC6.1, CC6.6, C1.1, P4.2 |
DCF-94 | Physical Security Policy | CC6.4 |
DCF-95 | Monitoring Processing Capacity and Usage | A1.1 |
DCF-96 | Load Balancer | A1.1 |
DCF-97 | Autoscaling | A1.1 |
DCF-99 | Backup Monitoring | A1.2 |
DCF-100 | Backup Restore Testing | A1.3 |
DCF-101 | Data Retention Policy | C1.1, P4.2 |
DCF-102 | Data Classification Policy | CC2.1, C1.1, P4.2, PI1.1 |
DCF-103 | Customer Data Deletion Upon Termination | C1.2, P4.3 |
DCF-104 | Test Data | C1.1, P4.2, CC8.1 |
DCF-105 | Personnel Non-Disclosure Agreements (NDA) | CC1.1, CC2.3, C1.1 |
DCF-107 | Disposal of Sensitive Data on Paper | C1.2, CC6.5 |
DCF-108 | Secure Storage Mechanisms | CC6.4 |
DCF-109 | Disposal of Sensitive Data on Hardware | CC6.5, C1.2 |
DCF-110 | Acceptable Input Ranges | P7.1, PI1.2 |
DCF-111 | Mandatory Fields | P7.1, PI1.2 |
DCF-112 | Notice and Acknowledgement of Privacy Practices | P1.1, P2.1, P3.2 |
DCF-115 | Privacy Policy Content | P1.1, P3.2, P4.1 |
DCF-120 | Periodic Review of Privacy Policy | P1.1, P2.1, P3.1 |
DCF-122 | Requests for Deletion of PII | P4.3 |
DCF-123 | Procedures for Information Disposal | C1.2, P4.3, CC6.5 |
DCF-126 | Personal Information Accessible Through System Authentication | P5.1, P5.2, P4.3, P7.1 |
DCF-127 | Privacy Requirements Communicated to Third parties | P6.1, P6.4, P6.5 |
DCF-130 | Documentation of Breaches or Unauthorized Disclosures of PII | P6.3, P6.4, P6.5, P6.6, P8.1 |
DCF-132 | Privacy and Security Requirements in Third-Party Agreements | CC2.3, CC9.2, P6.5 |
DCF-135 | Notification of Incidents or Breaches | P6.6, P8.1, CC7.3, CC7.4, CC7.5, P6.3 |
DCF-136 | Use of Subprocessors Communicated | CC2.3, P6.1 |
DCF-140 | Point of Contact for Privacy Inquiries | P4.3, P8.1, CC2.3 |
DCF-141 | Privacy Inquiries Tracked | P6.7, P8.1 |
DCF-144 | Board Charter Documented | CC1.2, CC1.3 |
DCF-146 | Board Meetings | CC1.2, CC2.2, CC2.3, CC4.2 |
DCF-149 | Removable Media Device Encryption | CC6.7 |
DCF-150 | Data Loss Prevention (DLP) Mechanisms | CC6.7 |
DCF-152 | Automated Security Updates | CC6.8, CC8.1 |
DCF-154 | Incident Response Test | CC7.3, CC7.4, CC7.5 |
DCF-155 | Testing of Changes | CC8.1 |
DCF-156 | Change Releases Approved | CC8.1 |
DCF-157 | Cybersecurity Insurance | CC9.1 |
DCF-159 | Incident Response Plan | CC7.3, CC9.1, P6.6, CC7.4, CC7.5 |
DCF-160 | Continuous Control Monitoring | CC2.1, CC2.2, CC5.1, CC5.2, CC3.3, CC3.2, CC3.4, CC4.1, CC4.2 |
DCF-166 | Business Continuity Plan | CC5.3, CC9.1 |
DCF-168 | Vendor Management Policy | CC9.2 |
DCF-169 | Backup Policy | A1.2 |
DCF-173 | Employment Terms & Conditions | CC1.3, CC2.2, CC1.1 |
DCF-181 | Encryption Policy | CC6.1, CC5.3 |
DCF-182 | Asset Management Policy | CC5.3 |
DCF-183 | Vulnerability Management Policy | CC7.1, CC5.3 |
DCF-204 | Dataflow Diagram | CC2.1, PI1.1 |
DCF-253 | Data Secure Disposal | C1.2, P4.3 |
DCF-273 | Strong Key Generation Policies and Procedures | CC6.1 |
DCF-278 | Key Retirement Policies and Procedures | CC6.1 |
DCF-293 | Anti-Malware Capabilities and Automatic Updates | CC6.8 |
DCF-294 | Anti-Malware Tools Behavior | CC6.8 |
DCF-305 | Production Components Change Control Procedures | CC8.1, CC6.8, CC5.2 |
DCF-312 | Secure Code Development Training | CC1.4, CC2.2 |
DCF-326 | Need-to-Know Principle | CC6.1 |
DCF-339 | Account Lockout after Failed Logins | CC6.1 |
DCF-340 | Lockout Duration | CC6.1 |
DCF-350 | Password History Enforcement | CC6.1 |
DCF-355 | MFA for Remote Network Access | CC6.6 |
DCF-356 | Communication of Authentication Best Practices | CC6.1 |
DCF-363 | Entry Controls in Place | CC6.4 |
DCF-365 | Secure Physical Access Control Mechanisms | CC6.4 |
DCF-372 | Restricted Access to Badge System | CC6.4 |
DCF-374 | Visitors Authorized and Escorted | CC6.4 |
DCF-375 | Personnel and Visitor Badges | CC6.4 |
DCF-377 | Visitor Badge Control | CC6.4 |
DCF-378 | Visitor Log | CC6.4 |
DCF-381 | Media Physically Secured or Encrypted | CC6.7 |
DCF-406 | Audit Logging | CC7.2 |
DCF-407 | Audit Logs Data Points | CC7.2 |
DCF-409 | Audit Trail for Privileged Access | CC7.2 |
DCF-411 | Audit Trail for Invalid Access Attempts | CC7.2 |
DCF-412 | Audit Trail for Identification and Authentication Mechanism Changes | CC7.2 |
DCF-414 | Audit Trail of System-Level Object Changes | CC7.2 |
DCF-478 | Change Detection Mechanism | CC8.1, CC7.1, CC6.8 |
DCF-503 | Multiple Methods for Security Awareness | CC2.2 |
DCF-507 | Vendor Due Diligence | CC3.2, CC9.2, P3.1 |
DCF-522 | Anti-Malware Scans of Media | CC6.8 |
DCF-527 | Designated Data Protection Officer | CC1.3 |
DCF-529 | Data Subject Consent | P3.2, P2.1 |
DCF-531 | Notification of Disclosures to Third Parties | P6.2 |
DCF-536 | Record of Processing Activity (ROPA) | P4.1, CC2.2 |
DCF-537 | Data Processing Agreements | P6.1, P6.5, CC9.2 |
DCF-540 | Timely Response to Data Subject Requests or Inquiries | P5.1, P5.2, P4.3, P6.7, P8.1 |
DCF-541 | Procedures for Management of Data Subject Rights | P5.1, P5.2, P4.3, P6.7 |
DCF-543 | Communication of Changes in Subprocessors | CC2.3, P6.1 |
DCF-549 | Identity Verification for Data Subject Requests | P5.1, P5.2 |
DCF-557 | Shared Account Management | CC6.1 |
DCF-558 | Restrictions on Software Installation | CC6.8 |
DCF-562 | Management of Utility Programs | CC6.8 |
DCF-567 | Change Management Policy | CC8.1 |
DCF-570 | Disciplinary Process | CC1.1, CC1.5 |
DCF-571 | Fire Detection and Suppression | A1.2 |
DCF-572 | Temperature Monitoring Systems | A1.2 |
DCF-573 | Uninterruptible Power Supply | A1.2 |
DCF-574 | Mobile Device Management Software | CC6.4, CC6.8, CC6.5 |
DCF-677 | Software Update and Patch Management | CC8.1 |
DCF-681 | Phishing Simulations | CC1.4, CC2.2 |
DCF-684 | Redundancy of Processing | A1.2 |
DCF-688 | Return of Assets | CC6.4 |
DCF-689 | On-Call Team | CC7.3, CC7.4, CC7.5 |
DCF-691 | Marketing Express Consent | P2.1, P3.1, P3.2 |
DCF-712 | Static Application Security Testing | CC7.1, CC8.1 |
DCF-741 | Logging and Monitoring Policy | CC7.2 |
DCF-746 | Privacy Training | CC2.2, CC1.4 |
DCF-747 | Secure Log-on for Customers | PI1.4, PI1.3 |
DCF-748 | Segmentation of Networks | CC6.1, CC6.6 |
DCF-749 | Leak Detection System | A1.2 |
DCF-753 | Mechanisms to Object to PII Processing | P2.1, P3.2 |
DCF-754 | Right to Access | P5.1, P5.2, P6.7 |
DCF-756 | Dual Opt-In for Consent to Sell PII | P2.1, P3.2 |
DCF-757 | User and System Guides | CC2.2, CC2.3, PI1.1, PI1.3, PI1.4 |
DCF-765 | Limit Collection of PII | P3.1, P4.1 |
DCF-770 | Consulting with Customer Prior to PII Disclosures | P3.2 |
DCF-774 | Data Processing Monitoring | PI1.3 |
DCF-775 | Cloud Deletion Protection | C1.1 |
DCF-776 | Principle of Least Privilege | CC6.3 |
DCF-777 | Cloud Resource Tagging | CC6.1 |
DCF-778 | Fraud Risk Assessment | CC3.3 |
DCF-779 | Cryptographic Key Rotation | CC6.1 |
DCF-781 | Secure Login Procedures | CC3.3 |
DCF-782 | Cloud Storage Lifecycle | C1.2 |
DCF-783 | Credentials Rotation | CC6.1 |
DCF-784 | Software Composition Analysis (SCA) | CC7.1 |
DCF-785 | Secure Runtime Configurations | CC7.1 |
DCF-786 | Defined Company Objectives | CC3.1, CC2.2, CC3.2 |
