{
  "node_id": "soc2-cc4-monitoring-activities",
  "title": "AICPA SOC 2 Common Criteria CC4 - Monitoring Activities (COSO Principles 16-17)",
  "domain": "Cybersecurity",
  "version": "1.0.0",
  "last_updated": "2026-06-26",
  "bluf": "CC4 is the Monitoring Activities series of the SOC 2 Common Criteria (COSO Principles 16-17). It requires the entity to select, develop, and perform ongoing and separate evaluations to ascertain whether the components of internal control are present and functioning, and to evaluate and communicate internal control deficiencies in a timely manner to those responsible for corrective action. The criteria are CC4.1-CC4.2.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework",
      "iso_standard",
      "industry_mapping",
      "ai_overlay_2026"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "soc-2-type-ii-trust-services-criteria-2024",
    "soc2-security-criterion"
  ],
  "primary_citations_count": 5
}