SOC 2
SOC 2 defines Trust Service Criteria (TSC) for security, availability, processing integrity, confidentiality, and privacy.
Trust Service Criteria
| Category | Description | GLACIS Support |
|---|---|---|
| Security | Protection of systems | Attestation integrity |
| Availability | System availability | Monitoring attestations |
| Processing Integrity | Complete, accurate processing | Request/response logging |
| Confidentiality | Protection of confidential data | Zero-egress design |
| Privacy | Collection and use of personal data | PII detection |
Mapping to ISO 42001
| SOC 2 | ISO 42001 | GLACIS Feature |
|---|---|---|
| CC1.1 | A.2.1 | Governance policy |
| CC3.1 | A.4.1 | System identification |
| CC3.2 | A.5.1 | Risk assessment |
| CC7.1 | A.6.2.6 | Monitoring (attestations) |
| CC7.2 | A.8.4 | Incident response |
Using GLACIS for SOC 2
- Map ISO 42001 controls to SOC 2 criteria
- Enable attestation monitoring
- Configure policy checks (PII, toxicity)
- Generate evidence for auditors
- Export OSCAL reports
Auditor Verification
Auditors can independently verify:
- Attestation signatures
- Merkle proofs
- Sampling coverage
- Policy enforcement