The AICPA released a new exposure draft of the SOC 2 Trust Services Principles and Criteria for public comment. This represents an effort by the Assurance Services Executive Committee (ASEC) to revise the trust services principles and criteria to increase clarity, eliminate redundancy and update based on today’s technologically driven business environment. Below is a summary of our observations on the current exposure draft:
- The primary change is that many of the current criteria have been combined into a set of “common criteria.” Common criteria constitute the complete set of criteria for the Security Trust Principle. The common criteria concept is widely accepted and already used in many international information technology assessment frameworks and security standards.
- As such, the Security Trust Principle must always be included in the scope of the report (one cannot report on Availability, Confidentiality or Processing Integrity Trust Principles without also including the Security Trust Principle).
- The common set of security criteria eliminates much of the redundancy that was found in the previous framework. This is a welcome change and as a result, reports in the future should be more concise and easier to understand.
- The Processing Integrity Trust Principle is laid out in a much more understandable format. The e-commerce criteria have been removed in this draft, making this applicable to a wider set of organizations.
- This exposure draft only affects the Security, Availability, Confidentiality and Processing Integrity Trust Principles. The Privacy Trust Principle will be revised separately in the Generally Accepted Privacy Principles (GAPP).
Sikich LLP has extensive experience helping service organizations demonstrate that their control environments are properly designed and operating effectively. We provide a range of SOC assurance services, including readiness assessment services and information technology consulting to assist your service organization in preparation for a successful SOC audit.
This publication contains general information only and Sikich is not, by means of this publication, rendering accounting, business, financial, investment, legal, tax, or any other professional advice or services. This publication is not a substitute for such professional advice or services, nor should you use it as a basis for any decision, action or omission that may affect you or your business. Before making any decision, taking any action or omitting an action that may affect you or your business, you should consult a qualified professional advisor. In addition, this publication may contain certain content generated by an artificial intelligence (AI) language model. You acknowledge that Sikich shall not be responsible for any loss sustained by you or any person who relies on this publication.