Managed SOC
SOC2 CISO level security control domains to consider
| Control Domain | Key Objective | Typical Controls |
|---|---|---|
| Governance | Establish security oversight | Security policies, risk management, security committee, defined roles and responsibilities |
| Asset Management | Know what you own | Asset inventory, ownership, lifecycle management, CMDB |
| Identity & Access Management (IAM) | Control access | MFA, SSO, RBAC, Joiner-Mover-Leaver (JML) process, privileged access management |
| Endpoint Security | Protect user devices | EDR, encryption, patching, device hardening, MDM |
| Network Security | Secure communications | Firewalls, VPN, network segmentation, IDS/IPS, secure Wi-Fi |
| Server & Infrastructure Security | Secure servers and platforms | Hardening, patching, configuration baselines, vulnerability remediation |
| Cloud Security | Secure cloud environments | Secure configurations, IAM, logging, storage security, CSPM (where applicable) |
| Email Security | Prevent phishing and email threats | SPF, DKIM, DMARC, anti-phishing, malware protection |
| Application Security | Secure software and applications | Secure SDLC, code reviews, SAST/DAST, dependency scanning, secrets management |
| Data Protection | Protect sensitive information | Data classification, encryption, DLP, retention, secure disposal |
| Logging & Monitoring | Detect threats | Centralized logging, SIEM, alerting, log retention |
| Vulnerability Management | Identify and remediate weaknesses | Regular scanning, risk-based remediation, penetration testing |
| Incident Response | Respond to security events | IR plan, incident handling, forensic readiness, post-incident reviews |
| Backup & Disaster Recovery | Ensure business continuity | Backups, restore testing, disaster recovery plan, business continuity plan |
| Third-Party Risk Management | Manage vendor risk | Vendor assessments, contracts, security reviews, monitoring |
| Security Awareness | Reduce human risk | User training, phishing simulations, policy acknowledgements |
| Compliance & Audit | Meet regulatory and contractual obligations | Internal audits, evidence collection, policy reviews, SOC 2 readiness |
| Physical Security | Protect facilities and hardware | Office access control, visitor management, CCTV, secure equipment disposal |

Comments 0
Email-verified comments are reviewed before they are published.