Skip to main content

Control Evidence Mappings

Each control mapping documents what evidence Vallum produces to support your compliance program, what it does not produce, known limitations, and what remains your responsibility.

In Progress (15)

These mappings are under editorial review and will be published after quality verification.

SOC2-CC1.1: Control environment demonstrates commitment to integrity and ethical values

SOC 2 · Under review

SOC2-CC1.2: Board of directors demonstrates independence and oversight of internal controls

SOC 2 · Under review

SOC2-CC2.1: Management communicates information about internal control objectives and responsibilities

SOC 2 · Under review

SOC2-CC3.1: Entity identifies and assesses risks to achievement of objectives

SOC 2 · Under review

SOC2-CC5.1: Entity selects and develops control activities to mitigate risks

SOC 2 · Under review

SOC2-CC6.1: Entity implements logical and physical access controls over information assets

SOC 2 · Under review

SOC2-CC6.2: Entity restricts logical access to systems and data to authorized users

SOC 2 · Under review

SOC2-CC7.1: Entity detects and responds to system anomalies and security events

SOC 2 · Under review

SOC2-CC8.1: Entity manages changes to system components in a controlled manner

SOC 2 · Under review

SOC2-CC9.1: Entity identifies and mitigates risks from business disruptions

SOC 2 · Under review

SOC2-CC4.1: Entity evaluates and communicates internal control deficiencies in a timely manner

SOC 2 · Under review

SOC2-CC4.2: Entity obtains reasonable assurance about whether controls are operating effectively

SOC 2 · Under review

SOC2-CC6.3: Entity implements controls over system boundaries and data classification

SOC 2 · Under review

SOC2-CC7.2: Entity monitors system capacity and performance against defined thresholds

SOC 2 · Under review

SOC2-CC9.2: Entity implements data retention and disposal controls per policy requirements

SOC 2 · Under review