Controls
This is the full index of individual control and clause reference pages across SOC 2, ISO 27001, GDPR, and HIPAA. Each entry below links to a page built around one control number — CC6.1, A.8.24, Article 32, or §164.312(a)(1) — with the exact requirement text, what auditors want as evidence, common implementation gaps, and where that same requirement shows up in the other three frameworks.
The list is sorted by control ID within each framework, not grouped by topic, so use it when you already know the control number you are looking for. If you are starting from a framework you do not know well, the Frameworks overview pages are a better entry point — they explain the structure (Trust Services Categories, Annex A domains, GDPR chapters, HIPAA rule parts) before you drop into individual controls.
This index is for engineers and compliance leads mid-audit-prep who need a specific control's evidence list, and for anyone building a cross-framework control matrix who needs to confirm which controls map to which.
- HIPAA§164.306
Security Standards — General Rules · HIPAA · 164.306
- HIPAA§164.308(a)(1)
Security Management Process and Risk Analysis · HIPAA · 164.308
- HIPAA§164.308(a)(3)
Workforce Security · HIPAA · 164.308
- HIPAA§164.308(a)(4)
Information Access Management · HIPAA · 164.308
- HIPAA§164.308(a)(5)
Security Awareness and Training · HIPAA · 164.308
- HIPAA§164.308(a)(6)
Security Incident Procedures · HIPAA · 164.308
- HIPAA§164.308(a)(7)
Contingency Plan · HIPAA · 164.308
- HIPAA§164.312(a)(1)
Access Control · HIPAA · 164.312
- HIPAA§164.312(a)(2)(iv)
Encryption and Decryption · HIPAA · 164.312
- HIPAA§164.312(b)
Audit Controls · HIPAA · 164.312
- HIPAA§164.312(c)(1)
Integrity of ePHI · HIPAA · 164.312
- HIPAA§164.312(d)
Person or Entity Authentication · HIPAA · 164.312
- HIPAA§164.312(e)(1)
Transmission Security · HIPAA · 164.312
- ISO 27001A.5.1
Policies for information security · ISO 27001 · A.5
- ISO 27001A.5.2
Information security roles and responsibilities · ISO 27001 · A.5
- ISO 27001A.5.3
Segregation of duties · ISO 27001 · A.5
- ISO 27001A.5.4
Management responsibilities · ISO 27001 · A.5
- ISO 27001A.5.5
Contact with authorities · ISO 27001 · A.5
- ISO 27001A.5.6
Contact with special interest groups · ISO 27001 · A.5
- ISO 27001A.5.7
Threat intelligence · ISO 27001 · A.5
- ISO 27001A.5.8
Information security in project management · ISO 27001 · A.5
- ISO 27001A.5.9
Inventory of information and other assets · ISO 27001 · A.5
- ISO 27001A.5.10
Acceptable use of information and other assets · ISO 27001 · A.5
- ISO 27001A.5.11
Return of assets · ISO 27001 · A.5
- ISO 27001A.5.12
Classification of information · ISO 27001 · A.5
- ISO 27001A.5.13
Labelling of information · ISO 27001 · A.5
- ISO 27001A.5.14
Information transfer · ISO 27001 · A.5
- ISO 27001A.5.15
Access control · ISO 27001 · A.5
- ISO 27001A.5.16
Identity management · ISO 27001 · A.5
- ISO 27001A.5.17
Authentication information · ISO 27001 · A.5
- ISO 27001A.5.18
Access rights · ISO 27001 · A.5
- ISO 27001A.5.19
Information security in supplier relationships · ISO 27001 · A.5
- ISO 27001A.5.20
Addressing information security within supplier agreements · ISO 27001 · A.5
- ISO 27001A.5.21
Managing information security in the ICT supply chain · ISO 27001 · A.5
- ISO 27001A.5.22
Monitoring, review and change management of supplier services · ISO 27001 · A.5
- ISO 27001A.5.23
Information security for use of cloud services · ISO 27001 · A.5
- ISO 27001A.5.24
Information security incident management planning and preparation · ISO 27001 · A.5
- ISO 27001A.5.25
Assessment and decision on information security events · ISO 27001 · A.5
- ISO 27001A.5.26
Response to information security incidents · ISO 27001 · A.5
- ISO 27001A.5.27
Learning from information security incidents · ISO 27001 · A.5
- ISO 27001A.5.28
Collection of evidence · ISO 27001 · A.5
- ISO 27001A.5.29
Information security during disruption · ISO 27001 · A.5
- ISO 27001A.5.30
ICT readiness for business continuity · ISO 27001 · A.5
- ISO 27001A.5.31
Legal, statutory, regulatory and contractual requirements · ISO 27001 · A.5
- ISO 27001A.5.32
Intellectual property rights · ISO 27001 · A.5
- ISO 27001A.5.33
Protection of records · ISO 27001 · A.5
- ISO 27001A.5.34
Privacy and protection of PII · ISO 27001 · A.5
- ISO 27001A.5.35
Independent review of information security · ISO 27001 · A.5
- ISO 27001A.5.36
Compliance with policies, rules and standards for information security · ISO 27001 · A.5
- ISO 27001A.5.37
Documented operating procedures · ISO 27001 · A.5
- ISO 27001A.6.1
Screening · ISO 27001 · A.6
- ISO 27001A.6.2
Terms and conditions of employment · ISO 27001 · A.6
- ISO 27001A.6.3
Information security awareness, education and training · ISO 27001 · A.6
- ISO 27001A.6.4
Disciplinary process · ISO 27001 · A.6
- ISO 27001A.6.5
Responsibilities after termination or change of employment · ISO 27001 · A.6
- ISO 27001A.6.6
Confidentiality or non-disclosure agreements · ISO 27001 · A.6
- ISO 27001A.6.7
Remote working · ISO 27001 · A.6
- ISO 27001A.6.8
Information security event reporting · ISO 27001 · A.6
- ISO 27001A.7.1
Physical security perimeters · ISO 27001 · A.7
- ISO 27001A.7.2
Physical entry · ISO 27001 · A.7
- ISO 27001A.7.3
Securing offices, rooms and facilities · ISO 27001 · A.7
- ISO 27001A.7.4
Physical security monitoring · ISO 27001 · A.7
- ISO 27001A.7.5
Protecting against physical and environmental threats · ISO 27001 · A.7
- ISO 27001A.7.6
Working in secure areas · ISO 27001 · A.7
- ISO 27001A.7.7
Clear desk and clear screen · ISO 27001 · A.7
- ISO 27001A.7.8
Equipment siting and protection · ISO 27001 · A.7
- ISO 27001A.7.9
Security of assets off-premises · ISO 27001 · A.7
- ISO 27001A.7.10
Storage media · ISO 27001 · A.7
- ISO 27001A.7.11
Supporting utilities · ISO 27001 · A.7
- ISO 27001A.7.12
Cabling security · ISO 27001 · A.7
- ISO 27001A.7.13
Equipment maintenance · ISO 27001 · A.7
- ISO 27001A.7.14
Secure disposal or re-use of equipment · ISO 27001 · A.7
- ISO 27001A.8.1
User endpoint devices · ISO 27001 · A.8
- ISO 27001A.8.2
Privileged access rights · ISO 27001 · A.8
- ISO 27001A.8.3
Information access restriction · ISO 27001 · A.8
- ISO 27001A.8.4
Access to source code · ISO 27001 · A.8
- ISO 27001A.8.5
Secure authentication · ISO 27001 · A.8
- ISO 27001A.8.6
Capacity management · ISO 27001 · A.8
- ISO 27001A.8.7
Protection against malware · ISO 27001 · A.8
- ISO 27001A.8.8
Management of technical vulnerabilities · ISO 27001 · A.8
- ISO 27001A.8.9
Configuration management · ISO 27001 · A.8
- ISO 27001A.8.10
Information deletion · ISO 27001 · A.8
- ISO 27001A.8.11
Data masking · ISO 27001 · A.8
- ISO 27001A.8.12
Data leakage prevention · ISO 27001 · A.8
- ISO 27001A.8.13
Information backup · ISO 27001 · A.8
- ISO 27001A.8.14
Redundancy of information processing facilities · ISO 27001 · A.8
- ISO 27001A.8.15
Logging · ISO 27001 · A.8
- ISO 27001A.8.16
Monitoring activities · ISO 27001 · A.8
- ISO 27001A.8.17
Clock synchronization · ISO 27001 · A.8
- ISO 27001A.8.18
Use of privileged utility programs · ISO 27001 · A.8
- ISO 27001A.8.19
Installation of software on operational systems · ISO 27001 · A.8
- ISO 27001A.8.20
Networks security · ISO 27001 · A.8
- ISO 27001A.8.21
Security of network services · ISO 27001 · A.8
- ISO 27001A.8.22
Segregation of networks · ISO 27001 · A.8
- ISO 27001A.8.23
Web filtering · ISO 27001 · A.8
- ISO 27001A.8.24
Use of cryptography · ISO 27001 · A.8
- ISO 27001A.8.25
Secure development life cycle · ISO 27001 · A.8
- ISO 27001A.8.26
Application security requirements · ISO 27001 · A.8
- ISO 27001A.8.27
Secure system architecture and engineering principles · ISO 27001 · A.8
- ISO 27001A.8.28
Secure coding · ISO 27001 · A.8
- ISO 27001A.8.29
Security testing in development and acceptance · ISO 27001 · A.8
- ISO 27001A.8.30
Outsourced development · ISO 27001 · A.8
- ISO 27001A.8.31
Separation of development, test and production environments · ISO 27001 · A.8
- ISO 27001A.8.32
Change management · ISO 27001 · A.8
- ISO 27001A.8.33
Test information · ISO 27001 · A.8
- ISO 27001A.8.34
Protection of information systems during audit testing · ISO 27001 · A.8
- GDPRArticle 5
Principles Relating to Processing of Personal Data · GDPR · Chapter II
- GDPRArticle 6
Lawfulness of processing · GDPR · Chapter II
- GDPRArticle 7
Conditions for Consent · GDPR · Chapter II
- GDPRArticle 12
Transparent Information and Data-Subject Communications · GDPR · Chapter III
- GDPRArticle 13
Information When Data Is Collected from the Individual · GDPR · Chapter III
- GDPRArticle 14
Information When Data Is Obtained Indirectly · GDPR · Chapter III
- GDPRArticle 15
Right of Access · GDPR · Chapter III
- GDPRArticle 16
Right to Rectification · GDPR · Chapter III
- GDPRArticle 17
Right to Erasure · GDPR · Chapter III
- GDPRArticle 20
Right to Data Portability · GDPR · Chapter III
- GDPRArticle 21
Right to Object · GDPR · Chapter III
- GDPRArticle 25
Data protection by design and by default · GDPR · Chapter IV
- GDPRArticle 28
Processor · GDPR · Chapter IV
- GDPRArticle 30
Records of Processing Activities · GDPR · Chapter IV
- GDPRArticle 32
Security of processing · GDPR · Chapter IV
- GDPRArticle 33
Notification of a personal data breach to the supervisory authority · GDPR · Chapter IV
- GDPRArticle 34
Communication of a Personal Data Breach · GDPR · Chapter IV
- GDPRArticle 35
Data Protection Impact Assessment · GDPR · Chapter IV
- GDPRArticle 37
Designation of a Data Protection Officer · GDPR · Chapter IV
- GDPRArticle 44
General Principle for International Transfers · GDPR · Chapter V
- GDPRArticle 46
Transfers Subject to Appropriate Safeguards · GDPR · Chapter V
- HIPAABAA Requirements
Business Associate Agreement Requirements · HIPAA · Topics
- SOC 2CC1.1
Control Environment — Integrity and Ethical Values · SOC 2 · CC1
- SOC 2CC1.2
Board Independence and Oversight · SOC 2 · CC1
- SOC 2CC1.3
Management Establishes Structures, Reporting Lines, and Authorities · SOC 2 · CC1
- SOC 2CC1.4
Commitment to Competence · SOC 2 · CC1
- SOC 2CC1.5
Accountability · SOC 2 · CC1
- SOC 2CC2.1
Communicates Information Internally · SOC 2 · CC2
- SOC 2CC2.2
Communicates with External Parties · SOC 2 · CC2
- SOC 2CC2.3
Communicates Quality Information · SOC 2 · CC2
- SOC 2CC3.1
Specifies Suitable Objectives · SOC 2 · CC3
- SOC 2CC3.2
Identifies and Analyzes Risk · SOC 2 · CC3
- SOC 2CC3.3
Considers Fraud Risk · SOC 2 · CC3
- SOC 2CC3.4
Identifies and Analyzes Significant Change · SOC 2 · CC3
- SOC 2CC4.1
Conducts Ongoing and Separate Evaluations · SOC 2 · CC4
- SOC 2CC4.2
Evaluates and Communicates Deficiencies · SOC 2 · CC4
- SOC 2CC5.1
Selects and Develops Control Activities · SOC 2 · CC5
- SOC 2CC5.2
Technology Controls · SOC 2 · CC5
- SOC 2CC5.3
Policies and Procedures · SOC 2 · CC5
- SOC 2CC6.1
Logical and Physical Access Controls · SOC 2 · CC6
- SOC 2CC6.2
Prior to Issuing System Credentials · SOC 2 · CC6
- SOC 2CC6.3
Removes Access When Appropriate · SOC 2 · CC6
- SOC 2CC6.4
Restricts Access to Physical Assets · SOC 2 · CC6
- SOC 2CC6.5
Discontinues Physical Access · SOC 2 · CC6
- SOC 2CC6.6
Limits Access to System Components · SOC 2 · CC6
- SOC 2CC6.7
Restricts Transmission of Information · SOC 2 · CC6
- SOC 2CC6.8
Prevents Unauthorized Software · SOC 2 · CC6
- SOC 2CC7.1
Detection of Security Vulnerabilities · SOC 2 · CC7
- SOC 2CC7.2
Monitoring of System Components · SOC 2 · CC7
- SOC 2CC7.3
Evaluation of Security Events · SOC 2 · CC7
- SOC 2CC7.4
Response to Security Incidents · SOC 2 · CC7
- SOC 2CC7.5
Recovery from Security Incidents · SOC 2 · CC7
- SOC 2CC8.1
Change Management · SOC 2 · CC8
- SOC 2CC9.1
Risk Mitigation · SOC 2 · CC9
- SOC 2CC9.2
Vendor and Business Partner Risks · SOC 2 · CC9
Covered Entity and Business Associate Roles · HIPAA · Topics
- HIPAAPHI vs. ePHI
PHI and ePHI Scope · HIPAA · Topics