Home/Compliance
soc2-tsc

SOC 2 TSC. Security Controls

57 controls · cross-mapped to ATT&CK techniques
Translate between regulatory language and what attackers actually do. Each control maps to MITRE ATT&CK techniques; open a control to see those techniques and whether we hold detection coverage for them.
Audit answer: every control + the techniques it defends + what you can detect (exportable)
▤ Generate threat-informed coverage report
⇄ Self-assessment: pick what you have, see your coverage

Controls

57 shown of 57
family CC1 · Control Environment framework soc2-tsc
family CC1 · Control Environment framework soc2-tsc
family CC1 · Control Environment framework soc2-tsc
family CC1 · Control Environment framework soc2-tsc
family CC1 · Control Environment framework soc2-tsc
family CC2 · Communication & Information framework soc2-tsc
family CC2 · Communication & Information framework soc2-tsc
family CC2 · Communication & Information framework soc2-tsc
family CC3 · Risk Assessment framework soc2-tsc
family CC3 · Risk Assessment framework soc2-tsc
family CC3 · Risk Assessment framework soc2-tsc
family CC3 · Risk Assessment framework soc2-tsc
family CC4 · Monitoring framework soc2-tsc
family CC4 · Monitoring framework soc2-tsc
family CC5 · Control Activities framework soc2-tsc
family CC5 · Control Activities framework soc2-tsc
family CC5 · Control Activities framework soc2-tsc
family CC6 · Logical & Physical Access framework soc2-tsc
family CC6 · Logical & Physical Access framework soc2-tsc
family CC6 · Logical & Physical Access framework soc2-tsc
family CC6 · Logical & Physical Access framework soc2-tsc
family CC6 · Logical & Physical Access framework soc2-tsc
family CC6 · Logical & Physical Access framework soc2-tsc
family CC6 · Logical & Physical Access framework soc2-tsc
family CC7 · System Operations framework soc2-tsc
family CC7 · System Operations framework soc2-tsc
family CC7 · System Operations framework soc2-tsc
family CC9 · Risk Mitigation framework soc2-tsc
family CC9 · Risk Mitigation framework soc2-tsc
family Privacy framework soc2-tsc
family Processing Integrity framework soc2-tsc
family Processing Integrity framework soc2-tsc
Showing 1-57 of 57
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin