| SOC 2 | An assurance examination, not simply a checklist. You assess whether controls support the applicable Trust Services Criteria. | Security is the core/common criterion. Learn: access controls, logical access, authentication, change management, risk assessment, monitoring, incident management, vendor management, system operations, data protection. Additional criteria: Availability, Processing Integrity, Confidentiality, Privacy. | AICPA SOC 2 / Trust Services Criteria (AICPA & CIMA) |
| PCI DSS v4.0.1 | One of the most important actual control/requirement frameworks for payment-card environments. Learn the requirements and testing procedures. | 1: Network security controls. 2: Secure configurations. 3: Protect stored account data. 4: Protect data in transit. 5: Malware protection. 6: Secure development/vulnerability management. 7: Restrict access. 8: Identify/authenticate users. 9: Physical access. 10: Logging & monitoring. 11: Security testing. 12: Security policies, governance, risk, third parties. | PCI SSC official PCI DSS document library (PCI Perspectives) |