Compliance Node Overview
The AICPA SOC 2 Availability Trust Services Category requires an entity to maintain controls ensuring its information and systems are available for operation and use to meet its objectives, as committed or agreed. This is primarily achieved through processing capacity monitoring, environmental protections, data backup processes, recovery infrastructure, and recovery plan testing, as detailed in the additional availability criteria A1.1, A1.2, and A1.3, which supplement the common criteria including the Risk Mitigation criteria CC9.1 and CC9.2.
Pillar: Cybersecurity · Authority: American Institute of Certified Public Accountants (AICPA) · Version: 1.1.0 · Last updated:
Primary source: https://www.aicpa-cima.com/resources/download/2017-trust-services-criteria-with-revised-points-of-focus-2022
SHA-256 integrity: 8ca1a0da5ebeaf9e8bf3ea6fb829daeb41d5164f80e9b605147d1c5ae993a162
Primary Citations — 5 traced to source
- AICPA 2017 Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy (With Revised Points of Focus, 2022), Additional Criteria for Availability, A1.1: The entity maintains, monitors, and evaluates current processing capacity and use of system components (infrastructure, data, and software) to manage capacity demand and to enable the implementation of additional capacity to help meet its objectives.
- AICPA 2017 Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy (With Revised Points of Focus, 2022), Additional Criteria for Availability, A1.2: The entity authorizes, designs, develops or acquires, implements, operates, approves, maintains, and monitors environmental protections, software, data backup processes, and recovery infrastructure to meet its objectives.
+ 3 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access