SOC for Cybersecurity - Cybersecurity Risk Management Examination
Evidence request list. 22 controls, 22 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Detect
Per CSF Detect: Anomalies and Events + Security Continuous Monitoring + Detection Processes.
- SOC Cyber evidence for SOCCYB-3
- CSF coverage + examination partial
Examination
Per AICPA SOC for Cybersecurity: examination by CPA + criteria including management's description + effectiveness of controls + report types + maintain documentation.
- SOC Cyber evidence for SOCCYB-6
- CSF coverage + examination partial
Identify
Per AICPA SOC for Cybersecurity NIST CSF-aligned: Identify function. Requirements include (a) Asset Management + (b) Business Environment + (c) Governance + (d) Risk Assessment + (e) Risk Management Strategy + (f) Supply Chain Risk Management.
- SOC Cyber evidence for SOCCYB-1
- CSF coverage + examination partial
Protect
Per CSF Protect: Identity Management + Access Control + Awareness/Training + Data Security + Info Protection Processes + Maintenance + Protective Technology.
- SOC Cyber evidence for SOCCYB-2
- CSF coverage + examination partial
Recover
Per CSF Recover: Recovery Planning + Improvements + Communications.
- SOC Cyber evidence for SOCCYB-5
- CSF coverage + examination partial
Respond
Per CSF Respond: Response Planning + Communications + Analysis + Mitigation + Improvements.
- SOC Cyber evidence for SOCCYB-4
- CSF coverage + examination partial
SOC for Cybersecurity: Availability Criteria
System availability performance monitoring and commitments related to cybersecurity infrastructure
- Availability commitments documented
- Disaster recovery plan and exercise records
- Capacity reports
- RTO and RPO definitions and test evidence
- Commitments unwritten
- DR exercises overdue
- Objectives unmet
- Dependencies undocumented
Disaster recovery planning and testing for cybersecurity systems and infrastructure
- Availability commitments documented
- Disaster recovery plan and exercise records
- Capacity reports
- RTO and RPO definitions and test evidence
- Commitments unwritten
- DR exercises overdue
- Objectives unmet
- Dependencies undocumented
SOC for Cybersecurity: Confidentiality Criteria
Identification and protection of confidential information within the cybersecurity program
- Confidential information inventory
- Encryption configuration baselines
- Access logs for sensitive data
- Disposal records
- Inventory incomplete
- Encryption gaps
- Access not least privilege
- Disposal undocumented
Encryption and data protection mechanisms for data at rest and in transit
- Confidential information inventory
- Encryption configuration baselines
- Access logs for sensitive data
- Disposal records
- Inventory incomplete
- Encryption gaps
- Access not least privilege
- Disposal undocumented
SOC for Cybersecurity: Description Criteria
Description of the entity's business and operations relevant to its cybersecurity risk management program
- Description of business operations
- Sensitive information inventory and classification
- Cybersecurity risk management objectives statement
- Cybersecurity programme description
- Objectives boilerplate
- Sensitive data not classified
- Programme description outdated
- Boundaries unclear
Types of sensitive information at risk, including PII, PHI, financial data, and intellectual property
- Description of business operations
- Sensitive information inventory and classification
- Cybersecurity risk management objectives statement
- Cybersecurity programme description
- Objectives boilerplate
- Sensitive data not classified
- Programme description outdated
- Boundaries unclear
Entity's objectives for its cybersecurity risk management program
- Description of business operations
- Sensitive information inventory and classification
- Cybersecurity risk management objectives statement
- Cybersecurity programme description
- Objectives boilerplate
- Sensitive data not classified
- Programme description outdated
- Boundaries unclear
Board and management oversight of the cybersecurity risk management program
- Governance charter and committee minutes
- Risk assessment methodology and results
- Internal and external reporting templates
- Roles and responsibilities matrix
- Governance committee inactive
- Risk methodology unfollowed
- Reports not retained
- Roles overlap or gaps
Process for identifying, assessing, and managing cybersecurity risks and threats
- Governance charter and committee minutes
- Risk assessment methodology and results
- Internal and external reporting templates
- Roles and responsibilities matrix
- Governance committee inactive
- Risk methodology unfollowed
- Reports not retained
- Roles overlap or gaps
Internal and external communication and reporting about cybersecurity matters
- Governance charter and committee minutes
- Risk assessment methodology and results
- Internal and external reporting templates
- Roles and responsibilities matrix
- Governance committee inactive
- Risk methodology unfollowed
- Reports not retained
- Roles overlap or gaps
Design and implementation of cybersecurity controls aligned with objectives
- Control environment documentation
- Continuous monitoring evidence
- Third party risk assessment records
- Control deficiency and remediation log
- Monitoring narrow
- Third party reviews stale
- Deficiencies aging
- Control owners undefined
Processes for monitoring and evaluating the effectiveness of cybersecurity controls
- Control environment documentation
- Continuous monitoring evidence
- Third party risk assessment records
- Control deficiency and remediation log
- Monitoring narrow
- Third party reviews stale
- Deficiencies aging
- Control owners undefined
Process for managing cybersecurity risks associated with third-party service providers
- Control environment documentation
- Continuous monitoring evidence
- Third party risk assessment records
- Control deficiency and remediation log
- Monitoring narrow
- Third party reviews stale
- Deficiencies aging
- Control owners undefined
SOC for Cybersecurity: Security Criteria
Controls to restrict logical and physical access to the cybersecurity infrastructure
- Logical and physical access records
- System operations procedures and runbooks
- Change management workflow records
- Monitoring dashboards
- Access reviews skipped
- Operations runbooks outdated
- Changes lack approvals
- Monitoring alert fatigue
Controls over system operations to detect and mitigate processing deviations and security incidents
- Logical and physical access records
- System operations procedures and runbooks
- Change management workflow records
- Monitoring dashboards
- Access reviews skipped
- Operations runbooks outdated
- Changes lack approvals
- Monitoring alert fatigue
Controls over changes to the cybersecurity infrastructure to prevent unauthorized modifications
- Logical and physical access records
- System operations procedures and runbooks
- Change management workflow records
- Monitoring dashboards
- Access reviews skipped
- Operations runbooks outdated
- Changes lack approvals
- Monitoring alert fatigue
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the SOC for Cybersecurity - Cybersecurity Risk Management Examination framework page.