Control Evidence Mappings
Each control mapping documents what evidence Vallum produces to support your compliance program, what it does not produce, known limitations, and what remains your responsibility.
In Progress (15)
These mappings are under editorial review and will be published after quality verification.
SOC2-CC1.1: Control environment demonstrates commitment to integrity and ethical values
SOC 2 · Under review
SOC2-CC1.2: Board of directors demonstrates independence and oversight of internal controls
SOC 2 · Under review
SOC2-CC2.1: Management communicates information about internal control objectives and responsibilities
SOC 2 · Under review
SOC2-CC3.1: Entity identifies and assesses risks to achievement of objectives
SOC 2 · Under review
SOC2-CC5.1: Entity selects and develops control activities to mitigate risks
SOC 2 · Under review
SOC2-CC6.1: Entity implements logical and physical access controls over information assets
SOC 2 · Under review
SOC2-CC6.2: Entity restricts logical access to systems and data to authorized users
SOC 2 · Under review
SOC2-CC7.1: Entity detects and responds to system anomalies and security events
SOC 2 · Under review
SOC2-CC8.1: Entity manages changes to system components in a controlled manner
SOC 2 · Under review
SOC2-CC9.1: Entity identifies and mitigates risks from business disruptions
SOC 2 · Under review
SOC2-CC4.1: Entity evaluates and communicates internal control deficiencies in a timely manner
SOC 2 · Under review
SOC2-CC4.2: Entity obtains reasonable assurance about whether controls are operating effectively
SOC 2 · Under review
SOC2-CC6.3: Entity implements controls over system boundaries and data classification
SOC 2 · Under review
SOC2-CC7.2: Entity monitors system capacity and performance against defined thresholds
SOC 2 · Under review
SOC2-CC9.2: Entity implements data retention and disposal controls per policy requirements
SOC 2 · Under review