← SOC 2 Trust Services Criteria in plain English

CC3.1 CC3

Risk Assessment / CC3.1

Stating objectives clearly enough that risk can be judged against them

Think of it likeYou cannot say the trip went wrong until you have said where you were going.

In plain English

Objectives are specified with enough clarity that the organization can identify what would threaten them. Vague goals make risk assessment meaningless.

Related CSF, CIS and ISO controls (unofficial mapping)