Content library
SOC 2

Requirements included in the framework

Policy
Linked frameworks
Framework
Tasks
Logical access control for protected information assets
CC6.1b
SOC 2 (Systems and Organization Controls)
6
Technical security for protected information assets
CC6.1c
SOC 2 (Systems and Organization Controls)
6
Registering and authorizing new users before granting access
CC6.2
SOC 2 (Systems and Organization Controls)
6
Management of access to data based on roles and responsibilities
CC6.3
SOC 2 (Systems and Organization Controls)
4
Physical access control to facilities and protected information assets
CC6.4
SOC 2 (Systems and Organization Controls)
10
Discontinuation of logical physical protections when no longer required
CC6.5
SOC 2 (Systems and Organization Controls)
5
Logical access security measures against threats from sources outside system boundries
CC6.6
SOC 2 (Systems and Organization Controls)
7
Restriction and protection of information in transmission, movement or removal
CC6.7
SOC 2 (Systems and Organization Controls)
11
Detection and prevention of unauthorized or malicious software
CC6.8
SOC 2 (Systems and Organization Controls)
9
Procedures for monitoring changes to configurations
CC7.1
SOC 2 (Systems and Organization Controls)
6
Monitoring of system components for anomalies
CC7.2
SOC 2 (Systems and Organization Controls)
7
Evaluation of security events
CC7.3
SOC 2 (Systems and Organization Controls)
6
Responding to identified security incidents
CC7.4
SOC 2 (Systems and Organization Controls)
7
Recovery from security incidents
CC7.5
SOC 2 (Systems and Organization Controls)
6
Security - Change management
CC8
SOC 2 (Systems and Organization Controls)
2
Change management procedures
CC8.1
SOC 2 (Systems and Organization Controls)
10
Treatment plans for business disruption risks
CC9.1
SOC 2 (Systems and Organization Controls)
1
Partner risk management
CC9.2
SOC 2 (Systems and Organization Controls)
8
Providing notice to data subjects about privacy practices
P1.1
SOC 2 (Systems and Organization Controls)
4
Communication of choices about personal information to data subjects
P2.1
SOC 2 (Systems and Organization Controls)
4
Collection of personal information is consistent with objects related to privacy
P3.1
SOC 2 (Systems and Organization Controls)
3
Additional measures when processing requires explicit consent
P3.2
SOC 2 (Systems and Organization Controls)
1
Limiting use of personal information to purposes according to objectives related to privacy
P4.1
SOC 2 (Systems and Organization Controls)
3
Retention of personal information according to objectives related to privacy
P4.2
SOC 2 (Systems and Organization Controls)
1

Universal cyber compliance language model: Comply with confidence and least effort

In Cyberday, all frameworks’ requirements are mapped into universal tasks, so you achieve multi-framework compliance effortlessly.

Security frameworks tend to share the common core. All frameworks cover basic topics like risk management, backup, malware, personnel awareness or access management in their respective sections.
Cyberday’s universal cyber security language technology creates you a single security plan and ensures you implement the common parts of frameworks just once. You focus on implementing your plan, we automate the compliance part - for current and upcoming frameworks.
Start your free trial
Get to know Cyberday
Start your free trial
Cyberday is your all-in-one solution for building a secure and compliant organization. Whether you're setting up a cyber security plan, evaluating policies, implementing tasks, or generating automated reports, Cyberday simplifies the entire process.
With AI-driven insights and a user-friendly interface, it's easier than ever to stay ahead of compliance requirements and focus on continuous improvement.
Clear framework compliance plans
Activate relevant frameworks and turn them into actionable policies tailored to your needs.
Credible reports to proof your compliance
Use guided tasks to ensure secure implementations and create professional reports with just a few clicks.
AI-powered improvement suggestions
Focus on the most impactful improvements in your compliance with help from Cyberday AI.