SOC 2
SOC 2 (Service Organization Control 2) is an auditing standard developed by the AICPA that evaluates a service organization's controls for security, availability, processing integrity, confidentiality, and privacy. It is the baseline compliance requirement for most enterprise data center and cloud service customers.
SOC 2 Type I vs. Type II
- Type I: Evaluates the design of controls at a point in time. Faster to obtain; less assurance than Type II.
- Type II: Evaluates the operating effectiveness of controls over a period of time (typically 6–12 months). Higher assurance; required by most enterprise customers.
Trust Service Criteria
SOC 2 is organized around five Trust Service Criteria: Security (required), Availability, Processing Integrity, Confidentiality, and Privacy (optional, selected based on service type). Most data center and cloud providers include Security, Availability, and Confidentiality.
Audit Process
SOC 2 audits are conducted by licensed CPA firms. The audit evaluates: control design (are controls appropriate for the risks?), control implementation (are controls actually in place?), and operating effectiveness (do controls work consistently over time?).
ISO 27001
ISO/IEC 27001 is an international standard for information security management systems (ISMS). It provides a systematic approach to managing sensitive information through a risk management process. ISO 27001 certification demonstrates that an organization has implemented a comprehensive ISMS.
ISMS Framework
ISO 27001 requires organizations to: establish an ISMS scope, conduct a risk assessment, implement controls to address identified risks, and continuously monitor and improve the ISMS. Annex A provides 93 controls across 4 themes: organizational, people, physical, and technological.
Certification Process
ISO 27001 certification requires a two-stage audit by an accredited certification body: Stage 1 (documentation review) and Stage 2 (implementation audit). Certification is valid for 3 years with annual surveillance audits.
Relationship to Other Frameworks
ISO 27001 certification provides significant overlap with SOC 2, NIST CSF, and other frameworks. Organizations with ISO 27001 certification can often streamline other compliance audits by demonstrating that their ISMS addresses the relevant requirements.
NIST Cybersecurity Framework (CSF)
The NIST CSF is a voluntary framework for managing cybersecurity risk, developed by NIST in collaboration with industry. It is widely adopted by US government agencies and critical infrastructure operators, and increasingly required by government contractors and regulated industries.
CSF 2.0 Structure
CSF 2.0 (2024) organizes cybersecurity activities into six functions:
- Govern: Cybersecurity governance, risk management, and supply chain risk
- Identify: Asset management, risk assessment, improvement
- Protect: Identity management, awareness training, data security, platform security
- Detect: Continuous monitoring, adverse event analysis
- Respond: Incident management, analysis, mitigation, reporting
- Recover: Incident recovery, communication
Implementation Tiers
CSF defines four implementation tiers (Partial, Risk Informed, Repeatable, Adaptive) that describe the maturity of an organization's cybersecurity risk management practices. Most organizations target Tier 3 (Repeatable) as a baseline.
PCI DSS
Payment Card Industry Data Security Standard (PCI DSS) applies to any organization that stores, processes, or transmits cardholder data. PCI DSS v4.0 (2022) includes 12 requirements organized around six goals.
Applicability
PCI DSS applies to: merchants that accept card payments, payment processors, card issuers, and service providers that store, process, or transmit cardholder data on behalf of others. Data centers that host systems in scope for PCI DSS must comply with relevant PCI DSS requirements.
Key Requirements
- Install and maintain network security controls (firewalls, segmentation)
- Apply secure configurations to all system components
- Protect stored account data (encryption, tokenization)
- Protect cardholder data with strong cryptography during transmission
- Protect all systems against malware
- Develop and maintain secure systems and software
- Restrict access to system components and cardholder data by business need to know
- Identify users and authenticate access to system components
- Restrict physical access to cardholder data
- Log and monitor all access to system components and cardholder data
- Test security of systems and networks regularly
- Support information security with organizational policies and programs
Compliance Validation
PCI DSS compliance is validated through: Qualified Security Assessor (QSA) audit (for large merchants and service providers), Self-Assessment Questionnaire (SAQ) for smaller merchants, and Approved Scanning Vendor (ASV) quarterly network scans.
HIPAA
The Health Insurance Portability and Accountability Act (HIPAA) establishes requirements for protecting Protected Health Information (PHI). HIPAA applies to covered entities (healthcare providers, health plans, healthcare clearinghouses) and their business associates (including data centers that store or process PHI).
Security Rule Requirements
The HIPAA Security Rule requires covered entities and business associates to implement administrative, physical, and technical safeguards for electronic PHI (ePHI):
- Administrative safeguards: Security management process, workforce training, access management, contingency planning
- Physical safeguards: Facility access controls, workstation security, device and media controls
- Technical safeguards: Access controls, audit controls, integrity controls, transmission security
Business Associate Agreements
Data centers that store or process PHI must sign a Business Associate Agreement (BAA) with covered entities. The BAA establishes the data center's obligations for protecting PHI and the consequences of a breach.
FedRAMP
The Federal Risk and Authorization Management Program (FedRAMP) provides a standardized approach to security assessment, authorization, and continuous monitoring for cloud products and services used by US federal agencies. FedRAMP authorization is required for cloud services used by federal agencies.
Authorization Levels
- Low: Systems where loss of confidentiality, integrity, or availability would have limited adverse effect
- Moderate: Most federal systems; serious adverse effect from loss of CIA
- High: Systems where loss of CIA would have severe or catastrophic adverse effect (law enforcement, emergency services)
Unified Compliance Approach
Most organizations must comply with multiple frameworks simultaneously. A unified compliance approach maps controls across frameworks to identify overlaps and gaps, enabling a single set of controls to satisfy multiple requirements.
Common Control Framework
A common control framework (CCF) maps controls from multiple frameworks to a single control library. When a control satisfies requirements from multiple frameworks, it only needs to be implemented and audited once. This approach significantly reduces compliance overhead.
Continuous Compliance
Continuous compliance monitoring — using automated tools to continuously assess control effectiveness — is more efficient than point-in-time audits. Tools like Vanta, Drata, and Secureframe automate evidence collection and control monitoring for SOC 2, ISO 27001, and other frameworks.
Framework Mapping
NIST provides mapping documents between CSF and other frameworks (ISO 27001, PCI DSS, HIPAA). These mappings enable organizations to use CSF as a master framework and demonstrate compliance with other frameworks through the mapping.