NIST 800-53 → SOC 2 crosswalk
A control-by-control mapping between NIST SP 800-53 Rev. 5 and SOC 2 (AICPA Trust Services Criteria). 6 mappings.
| NIST 800-53 | SOC 2 | Relationship | Notes |
|---|---|---|---|
| AC-2 Account management | CC6.1 Logical access security controls | EquivalentCurated | Access control & identity |
| AU-2 Event logging | CC7.2 Security event monitoring | EquivalentCurated | Logging, monitoring & detection |
| PM-1 Information security program plan | CC1.1 Integrity and ethical values | RelatedCurated | Governance & security policy |
| RA-5 Vulnerability monitoring and scanning | CC7.1 Vulnerability detection and monitoring | EquivalentCurated | Vulnerability management |
| SC-28 Protection of information at rest | CC6.7 Restricting data transmission | PartialCurated | Cryptography & data protection |
| SC-8 Transmission confidentiality and integrity | CC6.7 Restricting data transmission | PartialCurated | Cryptography & data protection |
Mappings marked “Official” derive from standards-body informative references; “Curated” mappings are authored by Cyber Compliance and provided for guidance only.