← SOC 2 Trust Services Criteria in plain English

CC3.2 CC3

Risk Assessment / CC3.2

Identifying and analyzing risk to those objectives

Think of it likeWalking the house looking for what could actually go wrong, then deciding which worries earn action.

In plain English

Risks are identified across the organization, analyzed for likelihood and impact, and used to decide how they will be managed. This is where the threats become a ranked list rather than a vague unease.

Related CSF, CIS and ISO controls (unofficial mapping)