The Security criterion (Common Criteria)
The Security criterion requires an organization to implement a framework of controls that protects its systems against unauthorized access and prevents the unauthorized disclosure or modification of data. It establishes the mandatory baseline for all SOC 2 reports, focusing on risk management, operational oversight, and technical safeguards.
What it means
In practice, this criterion is not just about technical tools but encompasses people, processes, and technology. The intent is to demonstrate that an organization has a systematic approach to identifying potential threats to its environment and has implemented specific controls to mitigate those risks.
The scope extends across the entire lifecycle of system operations. This includes how employees are vetted during hiring, how their access is managed throughout their tenure, how software changes are deployed into production, and how the organization detects and responds to security incidents in real-time.
How to meet it
- Conduct a formal annual risk assessment to identify threats and map them to specific internal controls.
- Implement an Identity and Access Management (IAM) framework based on the principle of least privilege and mandatory multi-factor authentication (MFA).
- Establish a documented incident response plan that defines how security events are detected, escalated, and remediated.
- Develop and maintain a set of core security policies—such as Information Security and Access Control policies—that are reviewed and approved by management annually.
- Deploy continuous monitoring tools to track system logs, network traffic, and unauthorized configuration changes.
- Perform regular vulnerability scans and third-party penetration tests to identify and patch technical weaknesses.
Evidence an auditor asks for
- A completed Risk Assessment matrix showing identified risks and the corresponding controls used to mitigate them.
- User access review records proving that permissions were audited by management and revoked for terminated employees.
- Screenshots or configuration reports confirming MFA is enabled across all administrative interfaces and remote access points.
- Change management tickets demonstrating that production changes were tested, approved, and documented prior to deployment.
- Onboarding checklists showing completed background checks and signed confidentiality agreements for new hires.
Common pitfalls
- "Paper compliance," where policies are formally written but the actual daily operations do not follow those procedures.
- Lack of a consistent audit trail, such as granting access via Slack or email without recording the request in a formal ticketing system.
- Neglecting security awareness training, resulting in an inability to prove that employees were trained on current threats and policy requirements.