Bidda Sovereign Intelligence · 10,108 Verified Nodes · 39 Sovereign Pillars

AICPA SOC 2 Trust Services Criteria - Confidentiality Category (C1.1-C1.2)

The AICPA SOC 2 Confidentiality principle requires entities to protect information designated as confidential throughout its lifecycle, from creation to…

What AICPA SOC 2 Trust Services Criteria - Confidentiality Category (C1.1-C1.2) requires

The AICPA SOC 2 Confidentiality principle requires entities to protect information designated as confidential throughout its lifecycle, from creation to destruction, as committed or agreed. The Confidentiality category comprises criteria C1.1 (the entity identifies and maintains confidential information) and C1.2 (the entity disposes of confidential information), supported by the Logical and Physical Access Controls common criteria CC6.1 through CC6.8, which protect confidential information against unauthorized access and disclosure.

Pillar: Cybersecurity · Authority: American Institute of Certified Public Accountants (AICPA) · Version: 1.1.0 · Last updated:

Primary source: https://www.aicpa-cima.com/resources/download/2017-trust-services-criteria-with-revised-points-of-focus-2022

SHA-256 integrity: 911afa634a2e09ca0b6bc6894bed3c7ad773a5267ecc723a97ff952dc196bce8

Primary Citations — 7 traced to source

  • AICPA Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy (2017, TSP Section 100), C1.1: The entity identifies and maintains confidential information to meet the entity's objectives related to confidentiality.
  • AICPA Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy (2017, TSP Section 100), C1.2: The entity disposes of confidential information to meet the entity's objectives related to confidentiality.

+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.

Access

⚠ Important: Human Verification Required

Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.