{"id":4231,"date":"2024-04-27T06:11:03","date_gmt":"2024-04-27T12:11:03","guid":{"rendered":"https:\/\/trustarc.com\/?post_type=regulations&#038;p=4231"},"modified":"2024-06-03T13:53:11","modified_gmt":"2024-06-03T19:53:11","slug":"soc2-ics","status":"publish","type":"regulations","link":"https:\/\/trustarc.com\/regulations\/soc2-ics\/","title":{"rendered":"SOC2 &#8211; International Cybersecurity Standard"},"content":{"rendered":"\t\t<section id=\"block_00d156187c93be3899d2b125e700f65f\" class=\"hero-section-colors text-center bg-navy-gradient\">\n\t\t\t<div class=\"container\">\n\t\t\t\t\t\t\t\t\t<span class=\"sub-title block font-bold \">Standard<\/span>\n\t\t\t\t\t\t\t\t\t\t<h1>SOC2<\/h1>\n\t\t\t\t\t<p>Developed by the American Institution of Certified Public Accountants (AICPA), the SOC 2 (System and Organization Controls, and Service Organization Controls), also known as the 2017 Trust Services Criteria, is a international cybersecurity standard establishing guidelines for the secure management of client data.<\/p>\n\t\t\t<\/div>\n\t\t<\/section>\n\t\t\n\n\t\t<section id=\"block_f641623491902b904f6111034e891e94\" class=\"columns-one text-center\" style=\"\">\n\t\t\t<div class=\"container\">\n\t\t\t\t\t\t\t\t\t<div class=\"text-holder\">\n\t\t\t\t\t\t<h2 style=\"text-align: center\">Are you subject to SOC2?<\/h2>\n<p style=\"text-align: center\">SOC 2 is applicable to any organization who prioritizes data protection, privacy and security, and may not be narrowly restricted to financial institutions or organizations who process large volumes of financial data, including: cloud service providers, healthcare providers, and software as a service (SaaS) providers.<\/p>\n\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\n\n\t<section id=\"block_46407a290a75762aeda987f34f605eaf\" class=\"columns-two\" style=\"padding-top:0;padding-bottom:0;\">\n\t\t<div class=\"container\">\n\t\t\t\t\t\t\t<div class=\"heading text-center max-width\">\n\t\t\t\t\t\t\t\t\t\t\t<h2>Key obligations of SOC2<\/h2>\n\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<div class=\"col-wrap\">\n\t\t\t\t\t\t\t\t\t\t<div class=\"col\">\n\t\t\t\t\t\t\t<h4>Privacy notice<\/h4>\n<p>Organizations must create and make available privacy notices covering the purposes for collecting personal information, choice and consent processes, categories of personal information collected, data collection methods (e.g., cookies), and use, retention, and disposal periods. Notices should also detail whether information will be disclosed to third parties, security measures, breach notification processes, and if new information about the individual will be developed.<\/p>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t\t<div class=\"col\">\n\t\t\t\t\t\t\t<h4>Vendor management<\/h4>\n<p>Where vendors and business partners are outsourced to support organizational operations, organizations must establish mechanisms to periodically assess their compliance with organizational privacy and data confidentiality standards and requirements. An assessment should also evaluate the level of performance and potential risk posed by vendors and business partners to organizational operations. All assessments shall be documented and retained.<\/p>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t<\/section>\n\t\n\n\t<section id=\"block_2c1fbe626b488d4fa769bd22b88bc5d5\" class=\"columns-two\" style=\"padding-top:0;padding-bottom:0;\">\n\t\t<div class=\"container\">\n\t\t\t\t\t\t<div class=\"col-wrap\">\n\t\t\t\t\t\t\t\t\t\t<div class=\"col\">\n\t\t\t\t\t\t\t<h4>Obtainment of consent<\/h4>\n<p>Organizations must obtain clear and explicit consent from individuals at or before the time sensitive personal information is collected. Where personal information is intended to be transferred to or from an individual\u2019s device, obtain prior consent and document the individual\u2019s consent to data transfers.<\/p>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t\t<div class=\"col\">\n\t\t\t\t\t\t\t<h4>Performance of risk assessment<\/h4>\n<p>Organizations must identify potential risks to organizational operations by establishing a risk assessment procedure and management plan, and execute an entity-wide risk assessment. Assess the severity of known risks to the entity and develop mitigation measures to remediate the risk. All risk assessment results must be retained.<\/p>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t<\/section>\n\t\n\n\t<section id=\"block_363bc1023a0b55302553d293938a84c1\" class=\"columns-two\" style=\"padding-top:0;\">\n\t\t<div class=\"container\">\n\t\t\t\t\t\t<div class=\"col-wrap\">\n\t\t\t\t\t\t\t\t\t\t<div class=\"col\">\n\t\t\t\t\t\t\t<h4>Implementation or technical security controls<\/h4>\n<p>Personal information in use, transit and at rest, and information assets must be protected by safeguards through implementing access controls, authentication methods, encryption and encryption keys, and malware detection mechanisms. <\/p>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t<\/section>\n\t\n\n\t\t<section id=\"block_aa943c502189a7bfb9a90c9319df0c86\" class=\"cta-section has-gradient-dark color-white\">\n\t\t\t<div class=\"bg\">\n\t\t\t\t<img decoding=\"async\" src=\"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/02\/bg-cta-plus-full-blue.png\" class=\"attachment-full size-full\" alt=\"\" srcset=\"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/02\/bg-cta-plus-full-blue.png 1440w, https:\/\/trustarc.com\/wp-content\/uploads\/2024\/02\/bg-cta-plus-full-blue-300x102.png 300w, https:\/\/trustarc.com\/wp-content\/uploads\/2024\/02\/bg-cta-plus-full-blue-1024x347.png 1024w, https:\/\/trustarc.com\/wp-content\/uploads\/2024\/02\/bg-cta-plus-full-blue-768x260.png 768w\" sizes=\"(max-width: 1440px) 100vw, 1440px\" \/>\t\t\t<\/div>\n\t\t\t<div class=\"container\">\n\t\t\t\t<div class=\"text-block\">\n\t\t\t\t\t\t\t\t\t\t\t<span class=\"block h6\">Whitepaper<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t<h2 class=\"h1\">Privacy and Data Security in Mergers &amp; Acquisitions<\/h2>\n\t\t\t\t\t\t<p>Proactive data privacy practices are strategically critical in this data economy because of the extreme cost of mistakes today. <\/p>\n\t\t\t\t\t\t<ul class=\"btn-list\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<li>\n\t\t\t\t\t\t\t\t\t<a href=\"\/resource\/privacy-and-data-security-in-mergers-acquisitions\/\" class=\"btn\"><span>Learn More<\/span><\/a>\t\t\t\t\t\t\t\t<\/li>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/ul>\n\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t<\/section>\n\t\t\n\n\t\t<section id=\"block_afa5bb21f8512e2166dc5eef6995b889\" class=\"columns-one text-center\" style=\"padding-bottom:0;overflow:hidden;\">\n\t\t\t<div class=\"container\">\n\t\t\t\t\t\t\t\t\t<div class=\"img-holder\">\n\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/02\/icon_Check.svg\" class=\"attachment-full size-full\" alt=\"Global protection icon for ensuring privacy compliance worldwide\" \/>\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t<div class=\"text-holder\">\n\t\t\t\t\t\t<h2 style=\"text-align: center\">Achieve compliance<\/h2>\n\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\n\n\t\t<section id=\"block_6504b7fc2db679db0fa521b0e6f15110\" class=\"cards-block\">\n\t\t\t<div class=\"container\">\n\t\t\t\t<div class=\"cards-holder\">\n\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"card-no-img\" href=\"\/products\/privacy-data-governance\/privacycentral\/\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<h6>Privacy Central<\/h6>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<h4>Privacy program development and compliance management<\/h4>\n\t\t\t\t\t\t\t\t\t<p>Automatically identify gaps and track compliance with PrivacyCentral for SOC2, ISO, NIST, and other privacy and security standards.<\/p>\n\t\t\t\t\t\t\t\t<span class=\"arrow\">\n\t\t\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/trustarc.com\/wp-content\/themes\/trustarc\/assets\/dist\/images\/icon-long-arrow.svg\" alt=\"\" \/>\n\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t<\/a>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"card-no-img\" href=\"\/products\/privacy-data-governance\/data-inventory-mapping\/\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<h6>Data Inventory Hub &amp; Risk Profile<\/h6>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<h4>Complete and maintain a data inventory<\/h4>\n\t\t\t\t\t\t\t\t\t<p>Automate with a Data Inventory Hub. Save time and reduce risk with automated data flow mapping, risk analysis, and remediation for personal data processes and general activities associated.<\/p>\n\t\t\t\t\t\t\t\t<span class=\"arrow\">\n\t\t\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/trustarc.com\/wp-content\/themes\/trustarc\/assets\/dist\/images\/icon-long-arrow.svg\" alt=\"\" \/>\n\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t<\/a>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"card-no-img\" href=\"\/products\/privacy-data-governance\/assessment-manager\/\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<h6>Assessment Manager<\/h6>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<h4>Mitigate Risks<\/h4>\n\t\t\t\t\t\t\t\t\t<p>Mitigate risks efficiently with TrustArc&#8217;s Assessment Manager. Utilize pre-built Data Protection Impact Assessments (DPIAs) and vendor assessments to ensure thorough risk management and compliance with industry standards.<\/p>\n\t\t\t\t\t\t\t\t<span class=\"arrow\">\n\t\t\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/trustarc.com\/wp-content\/themes\/trustarc\/assets\/dist\/images\/icon-long-arrow.svg\" alt=\"\" \/>\n\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t<\/a>\n\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t<\/section>\n\t\t\n\n\t\t<section id=\"block_fa6571f324edd703db58790eb497426a\" class=\"accordions-section\" style=\"\">\n\t\t\t<div class=\"container\">\n\t\t\t\t<div class=\"max-width\">\n\t\t\t\t\t\t\t\t\t\t  <h2>FAQs<\/h2>\n\t\t\t\t\t\t\t\t\t\t\t<ul class=\"accordion\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<li>\n\t\t\t\t\t\t\t\t\t<a href=\"#\" class=\"opener\">What are the benefits for being SOC 2-compliant?<\/a>\n\t\t\t\t\t\t\t\t\t<div class=\"slide\">\n\t\t\t\t\t\t\t\t\t\t<div class=\"slide-wrap\">\n\t\t\t\t\t\t\t\t\t\t\t<p>Demonstrating compliance translates into holding a strong security posture, and maintaining trust with clients that their personal information is kept securely during data processing. Meeting SOC 2 requirements may overlap with other cybersecurity frameworks (e.g. ISO), which enables entities to demonstrate compliance with multiple frameworks. <\/p>\n\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t<\/li>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<li>\n\t\t\t\t\t\t\t\t\t<a href=\"#\" class=\"opener\">Will I receive a certificate (or other credential) demonstrating compliance with the SOC 2 framework?<\/a>\n\t\t\t\t\t\t\t\t\t<div class=\"slide\">\n\t\t\t\t\t\t\t\t\t\t<div class=\"slide-wrap\">\n\t\t\t\t\t\t\t\t\t\t\t<p>Cloud service providers in particular may be SOC 2-certified when they demonstrate the five trusted criterias: security measures are implemented on information systems to prevent unauthorized data processing (security), access controls are implemented to enable only the authorized personnel to access confidential data (availability), information systems demonstrate accuracy (processing integrity), sensitive data are kept confidential (confidentiality), and data privacy of information is prioritized (data privacy).<\/p>\n\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t<\/li>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<li>\n\t\t\t\t\t\t\t\t\t<a href=\"#\" class=\"opener\">What are the 17 principles that SOC 2 is based on?<\/a>\n\t\t\t\t\t\t\t\t\t<div class=\"slide\">\n\t\t\t\t\t\t\t\t\t\t<div class=\"slide-wrap\">\n\t\t\t\t\t\t\t\t\t\t\t<p>The 17 principles presented in the Committee of Sponsoring Organizations of the Treadway Commission (COSO) framework including, but not limited to: commitments to organizational integrity and ethical values, internal governance by organizational board of directors, identifying and allocating organizational responsibilities, commitments to foster skillful individuals, upholding accountability and responsibility, ensuring the use of quality information, ensuring responsible communication, establishing organizational goals, risk management initiatives, upholding internal security controls and plans, and establishing internal data governance policies.<\/p>\n\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t<\/li>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<\/ul>\n\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t<\/section>\n\t\t\n\n\t\t<section id=\"block_7dd6fce46b4446b758ebca1482203130\" class=\"resource-section bg-light-grey\">\n\t\t\t<div class=\"container\">\n\t\t\t<div class=\"resource-head\">\n\t\t\t\t\t\t\t<h2>Related Resources<\/h2>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<ul class=\"resource-lists \">\n\t\t\t\t\t\t\t<li>\n\t\t\t\t\t<a href=\"https:\/\/trustarc.com\/resource\/webinar-privacy-in-healthcare-ensuring-data-security\/\" class=\"resource-single has-icon Webinars\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<div class=\"img-holder\">\n\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"380\" height=\"120\" src=\"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/02\/res-feat-city-pink-380x120.png\" class=\"attachment-380x120 size-380x120 wp-post-image\" alt=\"\" \/>\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t\t<div class=\"text-holder\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"resource-label uppercase\">Webinars and Videos<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<h4>Privacy in Healthcare: Ensuring Data Security<\/h4>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/a>\n\t\t\t\t<\/li>\n\t\t\t\t\t\t\t\t<li>\n\t\t\t\t\t<a href=\"https:\/\/trustarc.com\/resource\/webinar-privacy-security-it-the-venn-diagram-of-compliance\/\" class=\"resource-single has-icon Webinars\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<div class=\"img-holder\">\n\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"380\" height=\"120\" src=\"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/01\/res-feat-city-gray-test-380x120.png\" class=\"attachment-380x120 size-380x120 wp-post-image\" alt=\"\" \/>\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t\t<div class=\"text-holder\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"resource-label uppercase\">Webinars and Videos<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<h4>Privacy, Security, &#038; IT: The Venn Diagram of Compliance<\/h4>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/a>\n\t\t\t\t<\/li>\n\t\t\t\t\t\t\t\t<li>\n\t\t\t\t\t<a href=\"https:\/\/trustarc.com\/resource\/what-gdpr-means-cybersecurity-strategy\/\" class=\"resource-single\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<div class=\"img-holder\">\n\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"380\" height=\"120\" src=\"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/01\/res-feat-plus-blue-test-380x120.png\" class=\"attachment-380x120 size-380x120 wp-post-image\" alt=\"\" \/>\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t\t<div class=\"text-holder\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"resource-label uppercase\">Articles<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<h4>What the GDPR Means for your Cybersecurity Strategy<\/h4>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/a>\n\t\t\t\t<\/li>\n\t\t\t\t\t\t<\/ul>\n\t\t\t\t\t<\/div>\t\t<\/section>\n\t\t\n\n\t\t<section id=\"block_38b32f36eedca7904338080f1814cc22\" class=\"columns-one text-center bg-light-grey\" style=\"padding-top:0;padding-bottom:0;overflow:hidden;\">\n\t\t\t<div class=\"container\">\n\t\t\t\t\t\t\t\t\t<div class=\"text-holder\">\n\t\t\t\t\t\t<p style=\"font-size: 80%\"><strong>The information provided does not, and is not intended to, constitute legal advice.<\/strong> Instead, all information, content, and materials presented are for general informational purposes only.<\/p>\n\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t","protected":false},"excerpt":{"rendered":"<p>SOC2 International cybersecurity standard<\/p>\n","protected":false},"template":"","regulation":[97,92],"topic-regulation":[89,87],"class_list":["post-4231","regulations","type-regulations","status-publish","hentry","regulation-international","regulation-united-states","topic-regulation-security","topic-regulation-standard"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.4 (Yoast SEO v27.4) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>SOC2 - International Cybersecurity Standard | TrustArc<\/title>\n<meta name=\"description\" content=\"The SOC 2 is a international cybersecurity standard establishing guidelines for the secure client data management.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/trustarc.com\/regulations\/soc2-ics\/\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/trustarc.com\\\/regulations\\\/soc2-ics\\\/\",\"url\":\"https:\\\/\\\/trustarc.com\\\/regulations\\\/soc2-ics\\\/\",\"name\":\"SOC2 - International Cybersecurity Standard | TrustArc\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/trustarc.com\\\/#website\"},\"datePublished\":\"2024-04-27T12:11:03+00:00\",\"dateModified\":\"2024-06-03T19:53:11+00:00\",\"description\":\"The SOC 2 is a international cybersecurity standard establishing guidelines for the secure client data management.\",\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/trustarc.com\\\/regulations\\\/soc2-ics\\\/\"]}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/trustarc.com\\\/#website\",\"url\":\"https:\\\/\\\/trustarc.com\\\/\",\"name\":\"TrustArc\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/trustarc.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"SOC2 - International Cybersecurity Standard | TrustArc","description":"The SOC 2 is a international cybersecurity standard establishing guidelines for the secure client data management.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/trustarc.com\/regulations\/soc2-ics\/","schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/trustarc.com\/regulations\/soc2-ics\/","url":"https:\/\/trustarc.com\/regulations\/soc2-ics\/","name":"SOC2 - International Cybersecurity Standard | TrustArc","isPartOf":{"@id":"https:\/\/trustarc.com\/#website"},"datePublished":"2024-04-27T12:11:03+00:00","dateModified":"2024-06-03T19:53:11+00:00","description":"The SOC 2 is a international cybersecurity standard establishing guidelines for the secure client data management.","inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/trustarc.com\/regulations\/soc2-ics\/"]}]},{"@type":"WebSite","@id":"https:\/\/trustarc.com\/#website","url":"https:\/\/trustarc.com\/","name":"TrustArc","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/trustarc.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"}]}},"_links":{"self":[{"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/regulations\/4231","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/regulations"}],"about":[{"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/types\/regulations"}],"wp:attachment":[{"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/media?parent=4231"}],"wp:term":[{"taxonomy":"regulation","embeddable":true,"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/regulation?post=4231"},{"taxonomy":"topic-regulation","embeddable":true,"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/topic-regulation?post=4231"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}