CROSSWALKS

GAISSF to SOC 2 Crosswalk

Public crosswalk publication mapping GAISSF v1.0 to SOC 2, with scope, method, limitations and traceability.

1. Executive Summary

This crosswalk contains 215 outcome-based records covering all 59 GAISSF controls and all 60 Trust Services Criteria identifiers. It supports control rationalization, readiness planning, evidence reuse, and scoping discussions. It does not constitute a SOC 2 examination, report, certification, or opinion.

2. Assurance Architecture

The Trust Services Criteria are criteria used by management and practitioners. A SOC 2 engagement additionally requires a defined service organization system, management description and assertion, applicable trust services categories, examination procedures, evidence, treatment of subservice organizations and complementary user-entity controls, and an independent CPA report. These assurance layers are not collapsed into this crosswalk.

3. Scope and Method

All 61 criterion identifiers are included. Security/Common Criteria, Availability, Processing Integrity, Confidentiality, and Privacy are shown separately. Mappings compare control outcomes and expected evidence. They do not reproduce the full proprietary criteria or points of focus.

4. High-Alignment Areas

  • Governance, accountability and risk assessment

  • Logical access, boundary protection and secure transmission

  • Vulnerability, event and incident management

  • Change management and supplier risk

  • Availability and recovery

  • Processing integrity and data quality

  • Confidentiality and privacy-supporting controls

5. Material Residual Work

  • System boundary and service commitments

  • Management system description and assertion

  • Trust services category selection

  • Control design and operating-effectiveness evidence

  • Type I point-in-time versus Type II period coverage

  • Complementary user-entity and subservice-organization controls

  • Independent CPA testing, exceptions and opinion

6. Notably Absent

No basis was found to claim that GAISSF certification equals SOC 2, that a crosswalk produces auditor acceptance, that mapped controls have operated effectively, or that the AICPA or any CPA firm endorses this publication.

7. Criterion Coverage Register

Criterion Functional summary Category Mapped controls Coverage
CC1.1 Integrity and ethical values Security / Common Criteria - Control Environment 0 Not Addressed
CC1.2 Board oversight Security / Common Criteria - Control Environment 3 Partially Addressed
CC1.3 Structures, reporting lines, authority and responsibility Security / Common Criteria - Control Environment 3 Partially Addressed
CC1.4 Commitment to competence Security / Common Criteria - Control Environment 5 Substantially Addressed
CC1.5 Accountability Security / Common Criteria - Control Environment 6 Substantially Addressed
CC2.1 Quality information Security / Common Criteria - Communication and Information 1 Indirectly Supported
CC2.2 Internal communication Security / Common Criteria - Communication and Information 1 Indirectly Supported
CC2.3 External communication Security / Common Criteria - Communication and Information 1 Indirectly Supported
CC3.1 Suitable objectives Security / Common Criteria - Risk Assessment 1 Indirectly Supported
CC3.2 Risk identification and analysis Security / Common Criteria - Risk Assessment 1 Indirectly Supported
CC3.3 Fraud risk Security / Common Criteria - Risk Assessment 2 Partially Addressed
CC3.4 Significant change Security / Common Criteria - Risk Assessment 2 Partially Addressed
CC4.1 Ongoing and separate evaluations Security / Common Criteria - Monitoring 1 Indirectly Supported
CC4.2 Deficiency evaluation and communication Security / Common Criteria - Monitoring 1 Indirectly Supported
CC5.1 Control activity selection and development Security / Common Criteria - Control Activities 0 Not Addressed
CC5.2 Technology general controls Security / Common Criteria - Control Activities 0 Not Addressed
CC5.3 Policies and procedures Security / Common Criteria - Control Activities 0 Not Addressed
CC6.1 Logical access security architecture Security / Common Criteria - Logical and Physical Access 0 Not Addressed
CC6.2 User registration and authorization Security / Common Criteria - Logical and Physical Access 0 Not Addressed
CC6.3 Access modification and removal Security / Common Criteria - Logical and Physical Access 0 Not Addressed
CC6.4 Physical access restrictions Security / Common Criteria - Logical and Physical Access 0 Not Addressed
CC6.5 Asset disposal and removal Security / Common Criteria - Logical and Physical Access 4 Partially Addressed
CC6.6 System boundary protection Security / Common Criteria - Logical and Physical Access 4 Partially Addressed
CC6.7 Secure transmission and movement Security / Common Criteria - Logical and Physical Access 4 Partially Addressed
CC6.8 Malicious software prevention and detection Security / Common Criteria - Logical and Physical Access 6 Substantially Addressed
CC7.1 Configuration and vulnerability management Security / Common Criteria - System Operations 0 Not Addressed
CC7.2 Security event monitoring Security / Common Criteria - System Operations 13 Substantially Addressed
CC7.3 Security event evaluation Security / Common Criteria - System Operations 13 Substantially Addressed
CC7.4 Incident response Security / Common Criteria - System Operations 13 Substantially Addressed
CC7.5 Recovery from incidents Security / Common Criteria - System Operations 13 Substantially Addressed
CC8.1 Authorized and controlled changes Security / Common Criteria - Change Management 2 Partially Addressed
CC9.1 Risk mitigation activities Security / Common Criteria - Risk Mitigation 2 Partially Addressed
CC9.2 Vendor and business-partner risk Security / Common Criteria - Risk Mitigation 2 Partially Addressed
A1.1 Capacity and availability commitments Availability 2 Partially Addressed
A1.2 Environmental protections and recovery infrastructure Availability 2 Partially Addressed
A1.3 Recovery plan testing Availability 3 Partially Addressed
PI1.1 Processing objectives and specifications Processing Integrity 0 Not Addressed
PI1.2 Input completeness and accuracy Processing Integrity 11 Substantially Addressed
PI1.3 Processing completeness and accuracy Processing Integrity 12 Substantially Addressed
PI1.4 Output completeness and accuracy Processing Integrity 14 Substantially Addressed
PI1.5 Data storage integrity Processing Integrity 14 Substantially Addressed
C1.1 Identification and protection of confidential information Confidentiality 0 Not Addressed
C1.2 Confidential information disposal Confidentiality 0 Not Addressed
P1.1 Privacy notice and communication Privacy 2 Partially Addressed
P2.1 Choice and consent Privacy 2 Partially Addressed
P3.1 Collection limitation Privacy 1 Indirectly Supported
P3.2 Collection from third parties Privacy 1 Indirectly Supported
P4.1 Use limitation Privacy 5 Substantially Addressed
P4.2 Retention Privacy 5 Substantially Addressed
P4.3 Disposal Privacy 7 Substantially Addressed
P5.1 Data-subject access Privacy 0 Not Addressed
P6.1 Disclosure to third parties Privacy 0 Not Addressed
P6.2 Third-party data handling agreements Privacy 0 Not Addressed
P6.3 Third-party monitoring Privacy 0 Not Addressed
P6.4 Unauthorized disclosure response Privacy 6 Substantially Addressed
P6.5 Data quality communication Privacy 7 Substantially Addressed
P6.6 Correction and amendment Privacy 8 Substantially Addressed
P6.7 Disclosure accounting Privacy 8 Substantially Addressed
P7.1 Privacy data quality Privacy 0 Not Addressed
P8.1 Privacy inquiry, complaint and dispute handling Privacy 1 Indirectly Supported

Annex A — Complete Mapping Register

Controlled Publication. The table below shows a representative sample (6 of 215 total records). The complete control-by-control mapping register — full requirement-level traceability, evidence guidance and machine-readable export — is a Controlled Publication. Contact ODA3 Institute for access.
Record GAISSF TSC Rel. Confidence Rationale / Gap
CRO031-MAP-0001 D1-CTL-01 CC7.5 — Recovery from incidents P Medium GAISSF D1-CTL-01 provides governance, technical, or evidentiary capability relevant to CC7.5 (Recovery from incidents). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement. A service organization must define the system, applicable trust services categories, control objectives, complementary user-entity controls, subservice-organization treatment, evidence period, and management assertion. An independent CPA must perform the examination.
CRO031-MAP-0002 D1-CTL-01 CC7.4 — Incident response P Medium GAISSF D1-CTL-01 provides governance, technical, or evidentiary capability relevant to CC7.4 (Incident response). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement. A service organization must define the system, applicable trust services categories, control objectives, complementary user-entity controls, subservice-organization treatment, evidence period, and management assertion. An independent CPA must perform the examination.
CRO031-MAP-0003 D1-CTL-01 CC7.3 — Security event evaluation P Medium GAISSF D1-CTL-01 provides governance, technical, or evidentiary capability relevant to CC7.3 (Security event evaluation). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement. A service organization must define the system, applicable trust services categories, control objectives, complementary user-entity controls, subservice-organization treatment, evidence period, and management assertion. An independent CPA must perform the examination.
CRO031-MAP-0004 D1-CTL-01 CC7.2 — Security event monitoring P Medium GAISSF D1-CTL-01 provides governance, technical, or evidentiary capability relevant to CC7.2 (Security event monitoring). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement. A service organization must define the system, applicable trust services categories, control objectives, complementary user-entity controls, subservice-organization treatment, evidence period, and management assertion. An independent CPA must perform the examination.
CRO031-MAP-0005 D1-CTL-02 PI1.5 — Data storage integrity S Medium GAISSF D1-CTL-02 provides governance, technical, or evidentiary capability relevant to PI1.5 (Data storage integrity). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement. A service organization must define the system, applicable trust services categories, control objectives, complementary user-entity controls, subservice-organization treatment, evidence period, and management assertion. An independent CPA must perform the examination.
CRO031-MAP-0006 D1-CTL-02 PI1.4 — Output completeness and accuracy S Medium GAISSF D1-CTL-02 provides governance, technical, or evidentiary capability relevant to PI1.4 (Output completeness and accuracy). The relationship concerns criterion outcomes and does not determine the suitability of system boundaries, management assertions, control design, or operating effectiveness for a SOC 2 engagement. A service organization must define the system, applicable trust services categories, control objectives, complementary user-entity controls, subservice-organization treatment, evidence period, and management assertion. An independent CPA must perform the examination.

Annex B — Source Register

Source Role Status
GAISSF-NOR-001 v1.0 Framework and conformance baseline Normative
GAISSF-NOR-004 v1.0 Authoritative 59-control catalogue Normative
2017 Trust Services Criteria, revised points of focus 2022 Primary criterion baseline AICPA criteria
2018 SOC 2 Description Criteria, revised implementation guidance 2022 System-description layer Separate from criterion mapping
SOC 2 Guide and attestation standards Examination and reporting layer Independent practitioner application

Limitations and Reliance Notice

  • Mapping is not a SOC 2 report, attestation, certification, readiness conclusion, or CPA opinion.

  • The Security category is generally common to SOC 2 engagements; selection of Availability, Processing Integrity, Confidentiality, and Privacy depends on engagement scope.

  • The 2018 SOC 2 Description Criteria and management system description must be addressed separately.

  • Type I and Type II conclusions depend on independent examination procedures and evidence.

  • Points of focus are implementation guidance and are not a separate checklist of mandatory controls.

  • AICPA copyrighted criteria must be used under applicable terms; this publication uses identifiers and concise functional summaries.

© 2026 ODA3 Pvt Ltd. Published by ODA3 Institute. AICPA, SOC 2 and related names and materials remain the property of their respective owners. No endorsement, affiliation or assurance conclusion is implied.