Skip to content
Cyber Horizon
All frameworks

// US Standards

SOC 1 Service Organisation Control Compliance Software

ICFR focused report on controls relevant to user entities financial reporting.

Framework at a glance

Short name

SOC 1

Version

Category

US Standards

Controls

25

What SOC 1 covers

25 controls across 18 domains — every one tracked, owned and evidenced in Cyber Horizon.

Governance

3 controls
  • CC1.1 Control Environment — Integrity and Ethical Values
  • CC1.2 Board Independence and Oversight
  • CC2.1 Information and Communication

Risk Management

2 controls
  • CC3.1 Risk Assessment — Specify Objectives
  • CC9.1 Risk Mitigation

Operations

5 controls
  • CC4.1 Monitoring Activities
  • CC5.1 Control Activities — Policies and Procedures
  • CC8.1 Change Management
  • A1.1 Availability — Capacity Management
  • ITGC.3 Computer operations

Identity & Access

1 controls
  • CC6.1 Logical Access Controls

Vulnerability Management

1 controls
  • CC7.1 System Operations — Vulnerability Detection

Access Control

1 controls
  • ITGC.1 Logical access controls

Change Management

1 controls
  • ITGC.2 Change management

Backup

1 controls
  • ITGC.4 Data backup and recovery

Incident Response

1 controls
  • ITGC.5 Incident management

Segregation

1 controls
  • ITGC.6 Segregation of duties

Vulnerabilities

1 controls
  • ITGC.7 Vulnerability management

Patch Management

1 controls
  • ITGC.8 Patch management

Authentication

1 controls
  • ITGC.9 Password controls

Network

1 controls
  • ITGC.10 Network security

Physical

1 controls
  • ITGC.11 Physical security

Third-Party

1 controls
  • ITGC.12 Vendor management

Monitoring

1 controls
  • ITGC.13 Security monitoring

Training

1 controls
  • ITGC.14 Training and awareness

How Cyber Horizon automates SOC 1

Every SOC 1 control lives in a shared control library, crosswalked to the other frameworks you run — evidence collected once counts everywhere it applies.

Evidence is collected automatically from your connected tools, with owners, review cadences and gaps tracked continuously instead of at audit time.

Audit packs generate on demand, and the risk register, vendor risk and threat intelligence sit in the same platform — one evidence trail across your whole programme.

Frequently asked questions

What is SOC 1 Service Organisation Control?

ICFR focused report on controls relevant to user entities financial reporting.

How many controls does SOC 1 Service Organisation Control have?

SOC 1 Service Organisation Control has 25 controls in Cyber Horizon's catalogue, organised across 18 domains.

How does Cyber Horizon help with SOC 1 Service Organisation Control?

Cyber Horizon maps SOC 1 Service Organisation Control into a shared control library alongside every other framework you run, so evidence collected once counts towards SOC 1 and everything else it overlaps with. Controls, evidence status and audit packs live in one place, with automated collection from your connected tools.

See SOC 1 mapped to your environment

Start with the free 20-question readiness check — no signup — or get a personal walkthrough of SOC 1 in Cyber Horizon.