risk
risk Controls
6 controls across 2 frameworks.
NIST CSF
SOC2
cc1-2
Board or equivalent body oversees security risk
Security / Control Environment
high 4h
cc3-1
Security objectives are defined to enable risk identification
Security / Risk Assessment
high 6h
cc3-2
Security risks are identified and analyzed
Security / Risk Assessment
critical 16h
cc3-3
Fraud risk is identified and assessed
Security / Risk Assessment
medium 4h
cc3-4
Significant changes are assessed for security impact
Security / Risk Assessment
medium 4h