Determining What Trust Services Criteria Is Applicable to an Organization
Key Takeaways
- Security Is Required: Every SOC 2 report must include the Security Trust Services Criteria (TSC), while the other four are optional.
- Match TSC to Services: Determine which criteria apply based on the organization’s systems, services, customers, and regulatory requirements.
- Consider Business Impact: Availability may be relevant when uptime is critical, while Processing Integrity applies when systems process customer data or transactions.
- Differentiate Data Protection Needs: Confidentiality focuses on sensitive business information, while Privacy addresses the handling of customers’ personally identifiable information (PII).
An organization engages with a firm to get a SOC 2 report – now what? The next step would be to determine SOC 2 controls. There are five Trust Services Criteria (TSC) that can be included in SOC 2 reports. All reports are required to have the Security criteria; however, organizations can choose to also incorporate Availability, Processing Integrity, Confidentiality, and/or Privacy. This article will define the five TSC and how to determine any additional TSC an organization should add to the SOC 2 report.
The Five Trust Services Criteria
First, let’s define the five TSC. The American Institute of CPAs (AICPA) defines the five TSC as follows:
- Security – Ensures that information and systems are protected against unauthorized access, unauthorized disclosure of information, and damage to systems that could compromise the availability, integrity, confidentiality, and privacy of information or systems and affect the entity’s ability to achieve its objectives.
- Availability – Ensures that information and systems are available for operation and used to meet the entity’s objectives.
- Processing integrity – Ensures that systems process complete, valid, accurate, timely, and authorized data to meet the entity’s objectives.
- Confidentiality – Ensures that information that is designated as confidential is protected to meet the entity’s objectives.
- Privacy – Ensures that personal information is collected, used, retained, disclosed, and disposed of to meet the entity’s objectives.
Determining Which TSC to Include
With the five TSC definitions in mind, the organization needs to determine which systems and processes they want to include in the SOC 2 report. It is very common that a SOC 2 report does not encompass the entire organization’s services or systems; usually, the main services or systems are under audit. However, if a regulator requires you to obtain a SOC report around specific services or systems, then the scope of the SOC will already be determined for the organization.
For the first year SOC 2 report, it is common for organizations to only complete the Security TSC. This keeps things simple and only focuses on the required criteria as security is the largest of the five criteria. If management or regulators would like a first-year report with additional criteria, here are some items to keep in mind to help determine which criteria to add:
Availability
This criteria is usually added in cases when system uptime is critical and any downtime would have a significant impact on customers.
Processing Integrity
This criteria is usually added when the organization’s services or systems perform transactions or data collections for customers. For example, if a customer provides the organization with input data, like a report of a workers compensation injury, and the data is entered into the organization system to create an output, like review of injury by an adjustor, monitoring treatment care, and return to work procedures.
Confidentiality and Privacy
These two criteria can be tough to differentiate when the TSC are new to an organization. Confidentiality is usually added when an organization wants to protect sensitive business information. Privacy is usually added when an organization deals with personally identifiable information (PII) provided to them by their customers.
Final Thoughts
Overall, determining which of the five TSC to include in an organization’s SOC 2 report can be daunting at the start. However, after reading this article and analyzing the organizations services or systems, organizations should have a better idea of what TSC are applicable to their report.
If your entity is interested in obtaining any additional information on SOC 2 reports, or if there are any other questions related to SOC, please contact us. Be sure to visit our firm’s SOC & Cybersecurity industry page, and don’t hesitate to contact Dave Hammarberg, CPA, CFE, CISSP, GSEC, MCSE, CISA, CHQP, CCSFP, CCA regarding our services.
About the Author
Kaity McConnell joined McKonly & Asbury in 2021 and is a Supervisor with the firm. She primarily works with clients in the SOC industry.