Skip to content

CIS Controls v8SOC 2 crosswalk

A control-by-control mapping between CIS Critical Security Controls v8 and SOC 2 (AICPA Trust Services Criteria). 4 mappings.

CIS Controls v8SOC 2RelationshipNotes
3.11
Encrypt sensitive data at rest
CC6.7
Restricting data transmission
PartialCurated
Cryptographie et protection des données
6.1
Establish an access granting process
CC6.1
Logical access security controls
EquivalentCurated
Contrôle d'accès et identité
7.1
Establish and maintain a vulnerability management process
CC7.1
Vulnerability detection and monitoring
EquivalentCurated
Gestion des vulnérabilités
8.1
Establish and maintain an audit log management process
CC7.2
Security event monitoring
EquivalentCurated
Journalisation, surveillance et détection

Mappings marked “Official” derive from standards-body informative references; “Curated” mappings are authored by Cyber Compliance and provided for guidance only.