Trust Services Criteria
CC1–CC9 plus Availability and Confidentiality criteria, with owners, test results and evidence counts.
Criteria
12
12
Operating
9
9
Exceptions
1
1
Evidence items
40
40
All criterions
| TSC | Criterion | Category | Owner | Test result | Status | Evidence | Actions |
|---|---|---|---|---|---|---|---|
| CC1.1 | Commitment to integrity and ethical values | Control Environment | Priya Menon | Pass | Operating | 4 | |
| CC2.1 | Quality information for internal control | Communication | Priya Menon | Pass | Operating | 3 | |
| CC3.2 | Identification and analysis of risk | Risk Assessment | Arjun Rao | Pass | Operating | 5 | |
| CC4.1 | Ongoing and separate evaluations | Monitoring | Arjun Rao | Not tested | In progress | 1 | |
| CC5.2 | Technology general controls | Control Activities | Daniel Chen | Pass | Operating | 6 | |
| CC6.1 | Logical access security software | Logical Access | Arjun Rao | Pass | Operating | 8 | |
| CC6.6 | Boundary protection measures | Logical Access | Daniel Chen | Exception | Operating | 2 | |
| CC7.2 | Security incident monitoring | System Operations | Arjun Rao | Pass | Operating | 4 | |
| CC8.1 | Change management procedures | Change Management | Arjun Rao | Not tested | In progress | 2 | |
| CC9.2 | Vendor and business partner risk | Risk Mitigation | Unassigned | Not tested | Not started | 0 | |
| A1.2 | Environmental protections and recovery | Availability | Daniel Chen | Pass | Operating | 3 | |
| C1.1 | Confidential information identified | Confidentiality | Priya Menon | Pass | Operating | 2 |