docs: add SOC 2 evidence sampling gates#1405
Conversation
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 5b195b2edf
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
|
||
| Apply these caps after the initial maturity score: | ||
|
|
||
| - Cap at 2 if evidence exists but lacks audit period coverage, population, sample size, or system boundary mapping. |
There was a problem hiding this comment.
Avoid capping non-sampled controls for missing sample fields
This cap is applied to all evidence, but many SOC 2 artifacts in the table below are policies, configs, full-population reports, or other non-sampled evidence where population/sample size are legitimately N/A. In those cases the skill would force an otherwise complete Type II control down to 2 solely because sampling metadata is absent, even though the new checklist itself marks population and sample size as required only for sampled controls. Please scope this cap to sampled operating evidence, or allow explicit N/A/full-population evidence to remain eligible for higher scores.
Useful? React with 👍 / 👎.
Created from review issue: #1403
Summary
Validation
git diff --check