Skip to content

Evidence request lists

SOC for Cybersecurity - Cybersecurity Risk Management Examination

Evidence request list. 22 controls, 22 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Detect

SOCCYB-3
Detect Function: Anomalies, Continuous Monitoring, Processes

Per CSF Detect: Anomalies and Events + Security Continuous Monitoring + Detection Processes.

Artefacts an auditor will ask for
  • SOC Cyber evidence for SOCCYB-3
Where this commonly fails
  • CSF coverage + examination partial

Examination

SOCCYB-6
SOC for Cybersecurity Examination Process

Per AICPA SOC for Cybersecurity: examination by CPA + criteria including management's description + effectiveness of controls + report types + maintain documentation.

Artefacts an auditor will ask for
  • SOC Cyber evidence for SOCCYB-6
Where this commonly fails
  • CSF coverage + examination partial

Identify

SOCCYB-1
Identify Function: Asset, Risk, Governance, Business Environment

Per AICPA SOC for Cybersecurity NIST CSF-aligned: Identify function. Requirements include (a) Asset Management + (b) Business Environment + (c) Governance + (d) Risk Assessment + (e) Risk Management Strategy + (f) Supply Chain Risk Management.

Artefacts an auditor will ask for
  • SOC Cyber evidence for SOCCYB-1
Where this commonly fails
  • CSF coverage + examination partial

Protect

SOCCYB-2
Protect Function: Access Control, Awareness, Data Security, Processes

Per CSF Protect: Identity Management + Access Control + Awareness/Training + Data Security + Info Protection Processes + Maintenance + Protective Technology.

Artefacts an auditor will ask for
  • SOC Cyber evidence for SOCCYB-2
Where this commonly fails
  • CSF coverage + examination partial

Recover

SOCCYB-5
Recover Function: Recovery Planning, Improvements, Communications

Per CSF Recover: Recovery Planning + Improvements + Communications.

Artefacts an auditor will ask for
  • SOC Cyber evidence for SOCCYB-5
Where this commonly fails
  • CSF coverage + examination partial

Respond

SOCCYB-4
Respond Function: Planning, Communications, Analysis, Mitigation, Improvements

Per CSF Respond: Response Planning + Communications + Analysis + Mitigation + Improvements.

Artefacts an auditor will ask for
  • SOC Cyber evidence for SOCCYB-4
Where this commonly fails
  • CSF coverage + examination partial

SOC for Cybersecurity: Availability Criteria

SOC-CY-A1
Availability Commitments

System availability performance monitoring and commitments related to cybersecurity infrastructure

Artefacts an auditor will ask for
  • Availability commitments documented
  • Disaster recovery plan and exercise records
  • Capacity reports
  • RTO and RPO definitions and test evidence
Where this commonly fails
  • Commitments unwritten
  • DR exercises overdue
  • Objectives unmet
  • Dependencies undocumented
SOC-CY-A2
Disaster Recovery

Disaster recovery planning and testing for cybersecurity systems and infrastructure

Artefacts an auditor will ask for
  • Availability commitments documented
  • Disaster recovery plan and exercise records
  • Capacity reports
  • RTO and RPO definitions and test evidence
Where this commonly fails
  • Commitments unwritten
  • DR exercises overdue
  • Objectives unmet
  • Dependencies undocumented

SOC for Cybersecurity: Confidentiality Criteria

SOC-CY-C1
Confidential Information Protection

Identification and protection of confidential information within the cybersecurity program

Artefacts an auditor will ask for
  • Confidential information inventory
  • Encryption configuration baselines
  • Access logs for sensitive data
  • Disposal records
Where this commonly fails
  • Inventory incomplete
  • Encryption gaps
  • Access not least privilege
  • Disposal undocumented
SOC-CY-C2
Encryption and Data Protection

Encryption and data protection mechanisms for data at rest and in transit

Artefacts an auditor will ask for
  • Confidential information inventory
  • Encryption configuration baselines
  • Access logs for sensitive data
  • Disposal records
Where this commonly fails
  • Inventory incomplete
  • Encryption gaps
  • Access not least privilege
  • Disposal undocumented

SOC for Cybersecurity: Description Criteria

SOC-CY-DC1
Nature of Business and Operations

Description of the entity's business and operations relevant to its cybersecurity risk management program

Artefacts an auditor will ask for
  • Description of business operations
  • Sensitive information inventory and classification
  • Cybersecurity risk management objectives statement
  • Cybersecurity programme description
Where this commonly fails
  • Objectives boilerplate
  • Sensitive data not classified
  • Programme description outdated
  • Boundaries unclear
SOC-CY-DC2
Nature of Sensitive Information

Types of sensitive information at risk, including PII, PHI, financial data, and intellectual property

Artefacts an auditor will ask for
  • Description of business operations
  • Sensitive information inventory and classification
  • Cybersecurity risk management objectives statement
  • Cybersecurity programme description
Where this commonly fails
  • Objectives boilerplate
  • Sensitive data not classified
  • Programme description outdated
  • Boundaries unclear
SOC-CY-DC3
Cybersecurity Risk Management Objectives

Entity's objectives for its cybersecurity risk management program

Artefacts an auditor will ask for
  • Description of business operations
  • Sensitive information inventory and classification
  • Cybersecurity risk management objectives statement
  • Cybersecurity programme description
Where this commonly fails
  • Objectives boilerplate
  • Sensitive data not classified
  • Programme description outdated
  • Boundaries unclear
SOC-CY-DC4
Governance Structure

Board and management oversight of the cybersecurity risk management program

Artefacts an auditor will ask for
  • Governance charter and committee minutes
  • Risk assessment methodology and results
  • Internal and external reporting templates
  • Roles and responsibilities matrix
Where this commonly fails
  • Governance committee inactive
  • Risk methodology unfollowed
  • Reports not retained
  • Roles overlap or gaps
SOC-CY-DC5
Risk Assessment Process

Process for identifying, assessing, and managing cybersecurity risks and threats

Artefacts an auditor will ask for
  • Governance charter and committee minutes
  • Risk assessment methodology and results
  • Internal and external reporting templates
  • Roles and responsibilities matrix
Where this commonly fails
  • Governance committee inactive
  • Risk methodology unfollowed
  • Reports not retained
  • Roles overlap or gaps
SOC-CY-DC6
Communication and Reporting

Internal and external communication and reporting about cybersecurity matters

Artefacts an auditor will ask for
  • Governance charter and committee minutes
  • Risk assessment methodology and results
  • Internal and external reporting templates
  • Roles and responsibilities matrix
Where this commonly fails
  • Governance committee inactive
  • Risk methodology unfollowed
  • Reports not retained
  • Roles overlap or gaps
SOC-CY-DC7
Control Environment

Design and implementation of cybersecurity controls aligned with objectives

Artefacts an auditor will ask for
  • Control environment documentation
  • Continuous monitoring evidence
  • Third party risk assessment records
  • Control deficiency and remediation log
Where this commonly fails
  • Monitoring narrow
  • Third party reviews stale
  • Deficiencies aging
  • Control owners undefined
SOC-CY-DC8
Monitoring of Controls

Processes for monitoring and evaluating the effectiveness of cybersecurity controls

Artefacts an auditor will ask for
  • Control environment documentation
  • Continuous monitoring evidence
  • Third party risk assessment records
  • Control deficiency and remediation log
Where this commonly fails
  • Monitoring narrow
  • Third party reviews stale
  • Deficiencies aging
  • Control owners undefined
SOC-CY-DC9
Third-Party Management

Process for managing cybersecurity risks associated with third-party service providers

Artefacts an auditor will ask for
  • Control environment documentation
  • Continuous monitoring evidence
  • Third party risk assessment records
  • Control deficiency and remediation log
Where this commonly fails
  • Monitoring narrow
  • Third party reviews stale
  • Deficiencies aging
  • Control owners undefined

SOC for Cybersecurity: Security Criteria

SOC-CY-S1
Logical and Physical Access Controls

Controls to restrict logical and physical access to the cybersecurity infrastructure

Artefacts an auditor will ask for
  • Logical and physical access records
  • System operations procedures and runbooks
  • Change management workflow records
  • Monitoring dashboards
Where this commonly fails
  • Access reviews skipped
  • Operations runbooks outdated
  • Changes lack approvals
  • Monitoring alert fatigue
SOC-CY-S2
System Operations

Controls over system operations to detect and mitigate processing deviations and security incidents

Artefacts an auditor will ask for
  • Logical and physical access records
  • System operations procedures and runbooks
  • Change management workflow records
  • Monitoring dashboards
Where this commonly fails
  • Access reviews skipped
  • Operations runbooks outdated
  • Changes lack approvals
  • Monitoring alert fatigue
SOC-CY-S3
Change Management

Controls over changes to the cybersecurity infrastructure to prevent unauthorized modifications

Artefacts an auditor will ask for
  • Logical and physical access records
  • System operations procedures and runbooks
  • Change management workflow records
  • Monitoring dashboards
Where this commonly fails
  • Access reviews skipped
  • Operations runbooks outdated
  • Changes lack approvals
  • Monitoring alert fatigue
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the SOC for Cybersecurity - Cybersecurity Risk Management Examination framework page.