Security
In SOC 2, Security is the core set of expectations that an organization protects its systems and information against unauthorized access, use, or changes. It is the one category every SOC 2 examination must include, and the other categories are added only if they fit the organization's scope. Because the provided evidence covers only general, dictionary, and legal meanings of the word 'security', the SOC 2-specific characterization here reflects framework structure rather than the cited sources.
Within the AICPA Trust Services Criteria, Security is designated as the Common Criteria and is the only category required in every SOC 2 attestation examination; the remaining categories (Availability, Processing Integrity, Confidentiality, and Privacy) are optional and selected based on the engagement's scope. The Security category addresses protection of information and systems against unauthorized access, unauthorized disclosure, and damage that could compromise the availability, integrity, and confidentiality of information or systems. It should not be conflated with ISO/IEC 27001 Annex A reference controls; the Trust Services Criteria are a distinct AICPA framework evaluated in an SSAE 18 attestation report rather than an ISO management-system certification. Note that the sources in the evidence packet address only the general lexical, philosophical, and legal senses of 'security' and do not substantiate the SOC 2-specific details stated here, which derive from the framework's own structure.
Why it matters
Security occupies a uniquely foundational position in the SOC 2 framework: it is the Common Criteria, the one Trust Services Criteria category that every SOC 2 examination must include. The other four categories, Availability, Processing Integrity, Confidentiality, and Privacy, are optional and are added only when they fit an organization's scope. This means that regardless of what an organization chooses to emphasize, the Security category always forms the baseline against which its controls are evaluated. Understanding this structure is essential for anyone scoping an engagement, because omitting Security is not an option, whereas including additional categories is a deliberate scoping decision.
For compliance and GRC teams, the practical importance of Security lies in what it does and does not represent. A SOC 2 report covering the Security category attests to the controls in scope over the period examined (for a Type II) or their design at a point in time (for a Type I); it does not guarantee that an organization is immune from breaches or that no unauthorized access will ever occur. Treating a favorable report as a blanket assurance of safety is a common misreading that can create false confidence among stakeholders and customers.
It is also worth keeping the frameworks distinct. The Security category belongs to the AICPA Trust Services Criteria and is evaluated in an SSAE 18 attestation report, not an ISO management-system certification. While it may be tempting to equate the SOC 2 Security category with ISO/IEC 27001 Annex A reference controls, they are separate constructs, and satisfying one does not automatically satisfy the other. Any mapping between them is partial and should be treated with care.
Who it's relevant to
Inside Security
Common questions
Answers to the questions practitioners most commonly ask about Security.