Back

Include the subject matter to which the control is applied in the audit assertion's in scope system description.


CONTROL ID
14904
CONTROL TYPE
Establish/Maintain Documentation
CLASSIFICATION
Preventive

SUPPORTING AND SUPPORTED CONTROLS




This Control directly supports the implied Control(s):
  • Include a section regarding in scope controls related to the system in the audit assertion's in scope system description., CC ID: 14897

There are no implementation support Controls.


SELECTED AUTHORITY DOCUMENTS COMPLIED WITH




  • What: The subject matter to which the control is applied (Table 3-1 Column 1 Row 2, Reporting on Controls at a Service Organization: Relevant to Security, Availability, Processing Integrity, Confidentiality, or Privacy (SOC2), current as of January 1, 2018)
  • Although there is no prescribed format for presenting CUECs in the system description, they are typically included at the end of the system description or at the end of the section that includes the service auditor's description of tests of controls and results and are related to specific trust serv… (¶ 2.28, SOC 2® Reporting on an Examination of Controls at a Service Organization Relevant to Security, Availability, Processing Integrity, Confidentiality, or Privacy, October 15, 2022)
  • What: The subject matter to which the control is applied (Table 3-2 Column 1 Row 2, SOC 2® Reporting on an Examination of Controls at a Service Organization Relevant to Security, Availability, Processing Integrity, Confidentiality, or Privacy, October 15, 2022)