Skip to content
compliancebase

Controls

This is the full index of individual control and clause reference pages across SOC 2, ISO 27001, GDPR, and HIPAA. Each entry below links to a page built around one control number — CC6.1, A.8.24, Article 32, or §164.312(a)(1) — with the exact requirement text, what auditors want as evidence, common implementation gaps, and where that same requirement shows up in the other three frameworks.

The list is sorted by control ID within each framework, not grouped by topic, so use it when you already know the control number you are looking for. If you are starting from a framework you do not know well, the Frameworks overview pages are a better entry point — they explain the structure (Trust Services Categories, Annex A domains, GDPR chapters, HIPAA rule parts) before you drop into individual controls.

This index is for engineers and compliance leads mid-audit-prep who need a specific control's evidence list, and for anyone building a cross-framework control matrix who needs to confirm which controls map to which.

  • Security Standards — General Rules · HIPAA · 164.306

  • Security Management Process and Risk Analysis · HIPAA · 164.308

  • Workforce Security · HIPAA · 164.308

  • Information Access Management · HIPAA · 164.308

  • Security Awareness and Training · HIPAA · 164.308

  • Security Incident Procedures · HIPAA · 164.308

  • Contingency Plan · HIPAA · 164.308

  • Access Control · HIPAA · 164.312

  • Encryption and Decryption · HIPAA · 164.312

  • Audit Controls · HIPAA · 164.312

  • Integrity of ePHI · HIPAA · 164.312

  • Person or Entity Authentication · HIPAA · 164.312

  • Transmission Security · HIPAA · 164.312

  • ISO 27001A.5.1

    Policies for information security · ISO 27001 · A.5

  • ISO 27001A.5.2

    Information security roles and responsibilities · ISO 27001 · A.5

  • ISO 27001A.5.3

    Segregation of duties · ISO 27001 · A.5

  • ISO 27001A.5.4

    Management responsibilities · ISO 27001 · A.5

  • ISO 27001A.5.5

    Contact with authorities · ISO 27001 · A.5

  • ISO 27001A.5.6

    Contact with special interest groups · ISO 27001 · A.5

  • ISO 27001A.5.7

    Threat intelligence · ISO 27001 · A.5

  • ISO 27001A.5.8

    Information security in project management · ISO 27001 · A.5

  • ISO 27001A.5.9

    Inventory of information and other assets · ISO 27001 · A.5

  • ISO 27001A.5.10

    Acceptable use of information and other assets · ISO 27001 · A.5

  • ISO 27001A.5.11

    Return of assets · ISO 27001 · A.5

  • ISO 27001A.5.12

    Classification of information · ISO 27001 · A.5

  • ISO 27001A.5.13

    Labelling of information · ISO 27001 · A.5

  • ISO 27001A.5.14

    Information transfer · ISO 27001 · A.5

  • ISO 27001A.5.15

    Access control · ISO 27001 · A.5

  • ISO 27001A.5.16

    Identity management · ISO 27001 · A.5

  • ISO 27001A.5.17

    Authentication information · ISO 27001 · A.5

  • ISO 27001A.5.18

    Access rights · ISO 27001 · A.5

  • ISO 27001A.5.19

    Information security in supplier relationships · ISO 27001 · A.5

  • ISO 27001A.5.20

    Addressing information security within supplier agreements · ISO 27001 · A.5

  • ISO 27001A.5.21

    Managing information security in the ICT supply chain · ISO 27001 · A.5

  • ISO 27001A.5.22

    Monitoring, review and change management of supplier services · ISO 27001 · A.5

  • ISO 27001A.5.23

    Information security for use of cloud services · ISO 27001 · A.5

  • ISO 27001A.5.24

    Information security incident management planning and preparation · ISO 27001 · A.5

  • ISO 27001A.5.25

    Assessment and decision on information security events · ISO 27001 · A.5

  • ISO 27001A.5.26

    Response to information security incidents · ISO 27001 · A.5

  • ISO 27001A.5.27

    Learning from information security incidents · ISO 27001 · A.5

  • ISO 27001A.5.28

    Collection of evidence · ISO 27001 · A.5

  • ISO 27001A.5.29

    Information security during disruption · ISO 27001 · A.5

  • ISO 27001A.5.30

    ICT readiness for business continuity · ISO 27001 · A.5

  • ISO 27001A.5.31

    Legal, statutory, regulatory and contractual requirements · ISO 27001 · A.5

  • ISO 27001A.5.32

    Intellectual property rights · ISO 27001 · A.5

  • ISO 27001A.5.33

    Protection of records · ISO 27001 · A.5

  • ISO 27001A.5.34

    Privacy and protection of PII · ISO 27001 · A.5

  • ISO 27001A.5.35

    Independent review of information security · ISO 27001 · A.5

  • ISO 27001A.5.36

    Compliance with policies, rules and standards for information security · ISO 27001 · A.5

  • ISO 27001A.5.37

    Documented operating procedures · ISO 27001 · A.5

  • ISO 27001A.6.1

    Screening · ISO 27001 · A.6

  • ISO 27001A.6.2

    Terms and conditions of employment · ISO 27001 · A.6

  • ISO 27001A.6.3

    Information security awareness, education and training · ISO 27001 · A.6

  • ISO 27001A.6.4

    Disciplinary process · ISO 27001 · A.6

  • ISO 27001A.6.5

    Responsibilities after termination or change of employment · ISO 27001 · A.6

  • ISO 27001A.6.6

    Confidentiality or non-disclosure agreements · ISO 27001 · A.6

  • ISO 27001A.6.7

    Remote working · ISO 27001 · A.6

  • ISO 27001A.6.8

    Information security event reporting · ISO 27001 · A.6

  • ISO 27001A.7.1

    Physical security perimeters · ISO 27001 · A.7

  • ISO 27001A.7.2

    Physical entry · ISO 27001 · A.7

  • ISO 27001A.7.3

    Securing offices, rooms and facilities · ISO 27001 · A.7

  • ISO 27001A.7.4

    Physical security monitoring · ISO 27001 · A.7

  • ISO 27001A.7.5

    Protecting against physical and environmental threats · ISO 27001 · A.7

  • ISO 27001A.7.6

    Working in secure areas · ISO 27001 · A.7

  • ISO 27001A.7.7

    Clear desk and clear screen · ISO 27001 · A.7

  • ISO 27001A.7.8

    Equipment siting and protection · ISO 27001 · A.7

  • ISO 27001A.7.9

    Security of assets off-premises · ISO 27001 · A.7

  • ISO 27001A.7.10

    Storage media · ISO 27001 · A.7

  • ISO 27001A.7.11

    Supporting utilities · ISO 27001 · A.7

  • ISO 27001A.7.12

    Cabling security · ISO 27001 · A.7

  • ISO 27001A.7.13

    Equipment maintenance · ISO 27001 · A.7

  • ISO 27001A.7.14

    Secure disposal or re-use of equipment · ISO 27001 · A.7

  • ISO 27001A.8.1

    User endpoint devices · ISO 27001 · A.8

  • ISO 27001A.8.2

    Privileged access rights · ISO 27001 · A.8

  • ISO 27001A.8.3

    Information access restriction · ISO 27001 · A.8

  • ISO 27001A.8.4

    Access to source code · ISO 27001 · A.8

  • ISO 27001A.8.5

    Secure authentication · ISO 27001 · A.8

  • ISO 27001A.8.6

    Capacity management · ISO 27001 · A.8

  • ISO 27001A.8.7

    Protection against malware · ISO 27001 · A.8

  • ISO 27001A.8.8

    Management of technical vulnerabilities · ISO 27001 · A.8

  • ISO 27001A.8.9

    Configuration management · ISO 27001 · A.8

  • ISO 27001A.8.10

    Information deletion · ISO 27001 · A.8

  • ISO 27001A.8.11

    Data masking · ISO 27001 · A.8

  • ISO 27001A.8.12

    Data leakage prevention · ISO 27001 · A.8

  • ISO 27001A.8.13

    Information backup · ISO 27001 · A.8

  • ISO 27001A.8.14

    Redundancy of information processing facilities · ISO 27001 · A.8

  • ISO 27001A.8.15

    Logging · ISO 27001 · A.8

  • ISO 27001A.8.16

    Monitoring activities · ISO 27001 · A.8

  • ISO 27001A.8.17

    Clock synchronization · ISO 27001 · A.8

  • ISO 27001A.8.18

    Use of privileged utility programs · ISO 27001 · A.8

  • ISO 27001A.8.19

    Installation of software on operational systems · ISO 27001 · A.8

  • ISO 27001A.8.20

    Networks security · ISO 27001 · A.8

  • ISO 27001A.8.21

    Security of network services · ISO 27001 · A.8

  • ISO 27001A.8.22

    Segregation of networks · ISO 27001 · A.8

  • ISO 27001A.8.23

    Web filtering · ISO 27001 · A.8

  • ISO 27001A.8.24

    Use of cryptography · ISO 27001 · A.8

  • ISO 27001A.8.25

    Secure development life cycle · ISO 27001 · A.8

  • ISO 27001A.8.26

    Application security requirements · ISO 27001 · A.8

  • ISO 27001A.8.27

    Secure system architecture and engineering principles · ISO 27001 · A.8

  • ISO 27001A.8.28

    Secure coding · ISO 27001 · A.8

  • ISO 27001A.8.29

    Security testing in development and acceptance · ISO 27001 · A.8

  • ISO 27001A.8.30

    Outsourced development · ISO 27001 · A.8

  • ISO 27001A.8.31

    Separation of development, test and production environments · ISO 27001 · A.8

  • ISO 27001A.8.32

    Change management · ISO 27001 · A.8

  • ISO 27001A.8.33

    Test information · ISO 27001 · A.8

  • ISO 27001A.8.34

    Protection of information systems during audit testing · ISO 27001 · A.8

  • Principles Relating to Processing of Personal Data · GDPR · Chapter II

  • Lawfulness of processing · GDPR · Chapter II

  • Conditions for Consent · GDPR · Chapter II

  • Transparent Information and Data-Subject Communications · GDPR · Chapter III

  • Information When Data Is Collected from the Individual · GDPR · Chapter III

  • Information When Data Is Obtained Indirectly · GDPR · Chapter III

  • Right of Access · GDPR · Chapter III

  • Right to Rectification · GDPR · Chapter III

  • Right to Erasure · GDPR · Chapter III

  • Right to Data Portability · GDPR · Chapter III

  • Right to Object · GDPR · Chapter III

  • Data protection by design and by default · GDPR · Chapter IV

  • Processor · GDPR · Chapter IV

  • Records of Processing Activities · GDPR · Chapter IV

  • Security of processing · GDPR · Chapter IV

  • Notification of a personal data breach to the supervisory authority · GDPR · Chapter IV

  • Communication of a Personal Data Breach · GDPR · Chapter IV

  • Data Protection Impact Assessment · GDPR · Chapter IV

  • Designation of a Data Protection Officer · GDPR · Chapter IV

  • General Principle for International Transfers · GDPR · Chapter V

  • Transfers Subject to Appropriate Safeguards · GDPR · Chapter V

  • Business Associate Agreement Requirements · HIPAA · Topics

  • SOC 2CC1.1

    Control Environment — Integrity and Ethical Values · SOC 2 · CC1

  • SOC 2CC1.2

    Board Independence and Oversight · SOC 2 · CC1

  • SOC 2CC1.3

    Management Establishes Structures, Reporting Lines, and Authorities · SOC 2 · CC1

  • SOC 2CC1.4

    Commitment to Competence · SOC 2 · CC1

  • SOC 2CC1.5

    Accountability · SOC 2 · CC1

  • SOC 2CC2.1

    Communicates Information Internally · SOC 2 · CC2

  • SOC 2CC2.2

    Communicates with External Parties · SOC 2 · CC2

  • SOC 2CC2.3

    Communicates Quality Information · SOC 2 · CC2

  • SOC 2CC3.1

    Specifies Suitable Objectives · SOC 2 · CC3

  • SOC 2CC3.2

    Identifies and Analyzes Risk · SOC 2 · CC3

  • SOC 2CC3.3

    Considers Fraud Risk · SOC 2 · CC3

  • SOC 2CC3.4

    Identifies and Analyzes Significant Change · SOC 2 · CC3

  • SOC 2CC4.1

    Conducts Ongoing and Separate Evaluations · SOC 2 · CC4

  • SOC 2CC4.2

    Evaluates and Communicates Deficiencies · SOC 2 · CC4

  • SOC 2CC5.1

    Selects and Develops Control Activities · SOC 2 · CC5

  • SOC 2CC5.2

    Technology Controls · SOC 2 · CC5

  • SOC 2CC5.3

    Policies and Procedures · SOC 2 · CC5

  • SOC 2CC6.1

    Logical and Physical Access Controls · SOC 2 · CC6

  • SOC 2CC6.2

    Prior to Issuing System Credentials · SOC 2 · CC6

  • SOC 2CC6.3

    Removes Access When Appropriate · SOC 2 · CC6

  • SOC 2CC6.4

    Restricts Access to Physical Assets · SOC 2 · CC6

  • SOC 2CC6.5

    Discontinues Physical Access · SOC 2 · CC6

  • SOC 2CC6.6

    Limits Access to System Components · SOC 2 · CC6

  • SOC 2CC6.7

    Restricts Transmission of Information · SOC 2 · CC6

  • SOC 2CC6.8

    Prevents Unauthorized Software · SOC 2 · CC6

  • SOC 2CC7.1

    Detection of Security Vulnerabilities · SOC 2 · CC7

  • SOC 2CC7.2

    Monitoring of System Components · SOC 2 · CC7

  • SOC 2CC7.3

    Evaluation of Security Events · SOC 2 · CC7

  • SOC 2CC7.4

    Response to Security Incidents · SOC 2 · CC7

  • SOC 2CC7.5

    Recovery from Security Incidents · SOC 2 · CC7

  • SOC 2CC8.1

    Change Management · SOC 2 · CC8

  • SOC 2CC9.1

    Risk Mitigation · SOC 2 · CC9

  • SOC 2CC9.2

    Vendor and Business Partner Risks · SOC 2 · CC9

  • Covered Entity and Business Associate Roles · HIPAA · Topics

  • PHI and ePHI Scope · HIPAA · Topics