# CRO-031 — GAISSF–SOC 2 Mapping v1.0 > Status: Publication Candidate This crosswalk maps 59 GAISSF controls to all 60 Trust Services Criteria identifiers through 215 outcome-based records. It is not a SOC 2 examination or report. ## Source baseline - GAISSF-NOR-001 and GAISSF-NOR-004 v1.0 - 2017 Trust Services Criteria with revised points of focus (2022) - Verification date: 29 June 2026 ## Criterion coverage | Criterion | Functional summary | Category | Mapped controls | Coverage | |---|---|---|---:|---| | CC1.1 | Integrity and ethical values | Security / Common Criteria - Control Environment | 0 | Not Addressed | | CC1.2 | Board oversight | Security / Common Criteria - Control Environment | 3 | Partially Addressed | | CC1.3 | Structures, reporting lines, authority and responsibility | Security / Common Criteria - Control Environment | 3 | Partially Addressed | | CC1.4 | Commitment to competence | Security / Common Criteria - Control Environment | 5 | Substantially Addressed | | CC1.5 | Accountability | Security / Common Criteria - Control Environment | 6 | Substantially Addressed | | CC2.1 | Quality information | Security / Common Criteria - Communication and Information | 1 | Indirectly Supported | | CC2.2 | Internal communication | Security / Common Criteria - Communication and Information | 1 | Indirectly Supported | | CC2.3 | External communication | Security / Common Criteria - Communication and Information | 1 | Indirectly Supported | | CC3.1 | Suitable objectives | Security / Common Criteria - Risk Assessment | 1 | Indirectly Supported | | CC3.2 | Risk identification and analysis | Security / Common Criteria - Risk Assessment | 1 | Indirectly Supported | | CC3.3 | Fraud risk | Security / Common Criteria - Risk Assessment | 2 | Partially Addressed | | CC3.4 | Significant change | Security / Common Criteria - Risk Assessment | 2 | Partially Addressed | | CC4.1 | Ongoing and separate evaluations | Security / Common Criteria - Monitoring | 1 | Indirectly Supported | | CC4.2 | Deficiency evaluation and communication | Security / Common Criteria - Monitoring | 1 | Indirectly Supported | | CC5.1 | Control activity selection and development | Security / Common Criteria - Control Activities | 0 | Not Addressed | | CC5.2 | Technology general controls | Security / Common Criteria - Control Activities | 0 | Not Addressed | | CC5.3 | Policies and procedures | Security / Common Criteria - Control Activities | 0 | Not Addressed | | CC6.1 | Logical access security architecture | Security / Common Criteria - Logical and Physical Access | 0 | Not Addressed | | CC6.2 | User registration and authorization | Security / Common Criteria - Logical and Physical Access | 0 | Not Addressed | | CC6.3 | Access modification and removal | Security / Common Criteria - Logical and Physical Access | 0 | Not Addressed | | CC6.4 | Physical access restrictions | Security / Common Criteria - Logical and Physical Access | 0 | Not Addressed | | CC6.5 | Asset disposal and removal | Security / Common Criteria - Logical and Physical Access | 4 | Partially Addressed | | CC6.6 | System boundary protection | Security / Common Criteria - Logical and Physical Access | 4 | Partially Addressed | | CC6.7 | Secure transmission and movement | Security / Common Criteria - Logical and Physical Access | 4 | Partially Addressed | | CC6.8 | Malicious software prevention and detection | Security / Common Criteria - Logical and Physical Access | 6 | Substantially Addressed | | CC7.1 | Configuration and vulnerability management | Security / Common Criteria - System Operations | 0 | Not Addressed | | CC7.2 | Security event monitoring | Security / Common Criteria - System Operations | 13 | Substantially Addressed | | CC7.3 | Security event evaluation | Security / Common Criteria - System Operations | 13 | Substantially Addressed | | CC7.4 | Incident response | Security / Common Criteria - System Operations | 13 | Substantially Addressed | | CC7.5 | Recovery from incidents | Security / Common Criteria - System Operations | 13 | Substantially Addressed | | CC8.1 | Authorized and controlled changes | Security / Common Criteria - Change Management | 2 | Partially Addressed | | CC9.1 | Risk mitigation activities | Security / Common Criteria - Risk Mitigation | 2 | Partially Addressed | | CC9.2 | Vendor and business-partner risk | Security / Common Criteria - Risk Mitigation | 2 | Partially Addressed | | A1.1 | Capacity and availability commitments | Availability | 2 | Partially Addressed | | A1.2 | Environmental protections and recovery infrastructure | Availability | 2 | Partially Addressed | | A1.3 | Recovery plan testing | Availability | 3 | Partially Addressed | | PI1.1 | Processing objectives and specifications | Processing Integrity | 0 | Not Addressed | | PI1.2 | Input completeness and accuracy | Processing Integrity | 11 | Substantially Addressed | | PI1.3 | Processing completeness and accuracy | Processing Integrity | 12 | Substantially Addressed | | PI1.4 | Output completeness and accuracy | Processing Integrity | 14 | Substantially Addressed | | PI1.5 | Data storage integrity | Processing Integrity | 14 | Substantially Addressed | | C1.1 | Identification and protection of confidential information | Confidentiality | 0 | Not Addressed | | C1.2 | Confidential information disposal | Confidentiality | 0 | Not Addressed | | P1.1 | Privacy notice and communication | Privacy | 2 | Partially Addressed | | P2.1 | Choice and consent | Privacy | 2 | Partially Addressed | | P3.1 | Collection limitation | Privacy | 1 | Indirectly Supported | | P3.2 | Collection from third parties | Privacy | 1 | Indirectly Supported | | P4.1 | Use limitation | Privacy | 5 | Substantially Addressed | | P4.2 | Retention | Privacy | 5 | Substantially Addressed | | P4.3 | Disposal | Privacy | 7 | Substantially Addressed | | P5.1 | Data-subject access | Privacy | 0 | Not Addressed | | P6.1 | Disclosure to third parties | Privacy | 0 | Not Addressed | | P6.2 | Third-party data handling agreements | Privacy | 0 | Not Addressed | | P6.3 | Third-party monitoring | Privacy | 0 | Not Addressed | | P6.4 | Unauthorized disclosure response | Privacy | 6 | Substantially Addressed | | P6.5 | Data quality communication | Privacy | 7 | Substantially Addressed | | P6.6 | Correction and amendment | Privacy | 8 | Substantially Addressed | | P6.7 | Disclosure accounting | Privacy | 8 | Substantially Addressed | | P7.1 | Privacy data quality | Privacy | 0 | Not Addressed | | P8.1 | Privacy inquiry, complaint and dispute handling | Privacy | 1 | Indirectly Supported | ## Limitations - Mapping is not a SOC 2 report, attestation, certification, readiness conclusion, or CPA opinion. - The Security category is generally common to SOC 2 engagements; selection of Availability, Processing Integrity, Confidentiality, and Privacy depends on engagement scope. - The 2018 SOC 2 Description Criteria and management system description must be addressed separately. - Type I and Type II conclusions depend on independent examination procedures and evidence. - Points of focus are implementation guidance and are not a separate checklist of mandatory controls. - AICPA copyrighted criteria must be used under applicable terms; this publication uses identifiers and concise functional summaries. ## Notably Absent No SOC 2 certification, CPA opinion, auditor acceptance, operating-effectiveness conclusion, or AICPA endorsement is claimed.