SOC 2 (TSC 2017)

How the access, approval, and audit primitives align to the Trust Services Criteria your SOC 2 report is written against.

What this is, and is not

Using Break Glass Business does not make you SOC 2 (TSC 2017)-certified — that is an assessment of your whole organisation. For the specific controls below, the records this product generates are the kind of evidence an assessor asks you to produce.

ControlTitleEvidence in the pack
CC6.1Logical access security measuressecrets, accessRequests, membership
CC6.2Registration and authorisation of new usersmembership
CC6.3Access modification and removalmembership, accessReview
CC7.4Response to identified security incidentsincidents, runs, messages
A1.2Recovery and business continuity testingdrills, tabletops, recoveryPlans

Every evidence pack carries this mapping. See the full trust and control overview or the security questionnaire.

Start free