Contractual / Assurance / Industry Requirements

FrameworkWhat you need to know as a GRC AnalystKey control areas you should learnOfficial documentation
SOC 2An assurance examination, not simply a checklist. You assess whether controls support the applicable Trust Services Criteria.Security is the core/common criterion. Learn: access controls, logical access, authentication, change management, risk assessment, monitoring, incident management, vendor management, system operations, data protection. Additional criteria: Availability, Processing Integrity, Confidentiality, Privacy.AICPA SOC 2 / Trust Services Criteria (AICPA & CIMA)
PCI DSS v4.0.1One of the most important actual control/requirement frameworks for payment-card environments. Learn the requirements and testing procedures.1: Network security controls. 2: Secure configurations. 3: Protect stored account data. 4: Protect data in transit. 5: Malware protection. 6: Secure development/vulnerability management. 7: Restrict access. 8: Identify/authenticate users. 9: Physical access. 10: Logging & monitoring. 11: Security testing. 12: Security policies, governance, risk, third parties.PCI SSC official PCI DSS document library (PCI Perspectives)