For a smooth SOC 2 process, companies should ensure controls are accurate, efforts are effective, and responsibilities are communicated. Without these, the rest of your program will likely run into exceptions and struggle to meet the criteria. While performing these seems easy, it can be difficult to understand what should be done to achieve them. Some tips include documenting processes and requirements in-depth, templatizing all communication efforts, and reviewing changes against the control set and legal requirements.
- Documenting
- The procedures for documenting and treating findings from vulnerability scans, penetration tests, risk assessments, audits, and any other assessments, who perform these, and when.
- A policy to include a listing of services used to support the network and system infrastructure and how each must be configured to meet requirements and commitments.
- Documentation to include a listing of system performance and security monitoring tools, what they do, how they are configured, who gets alerts from the tools, and how those alerts should be treated.
- Examples include Cloudflare, Datadog, SolarWinds, CloudWatch, GuardDuty, etc.
- The procedures for every communication channel for users, both internal (e.g., personnel) and external (e.g., customers), to contact the company, how the channel is meant to be used, who is supposed to receive communications, and how they should document and respond.
- Channels for communication can be separated by many different types of concerns, such as privacy and security concerns or a need for technical support.
- Document, typically found on the public website, of commitments and requirements related to security and other included trust services criteria that are made to users.
- Templatizing
- Commitments made to users, regarding security and other included trust services criteria,
- Changes to the above commitments to users,
- User’s responsibilities to the company, including reporting issues and how to do so,
- How users can contact the company and what for,
- How users can use the system, including system boundaries, what information they will be expected to provide, and what results they can expect,
- Notification of incidents affecting users.
- Reviewing Changes
- The procedures in use,
- The business environment,
- Technology in use, and
- The regulatory requirements (e.g., new laws and regulations).
- Desired changes to the processes,
- Required changes to the processes, or
- Changes that have already taken place.
Madison Loewe
Like our content? Subscribe and stay informed.
Related posts
Tags
- Access Control (3)
- Amazon (1)
- Artificial Intelligence (3)
- Assessment (1)
- Attack Surface (2)
- Attack Surface Management (3)
- Attestation (1)
- Audit (1)
- Awareness Week (3)
- AWS (2)
- Backup And Recovery (1)
- BCAW (4)
- BCMS (1)
- Blackbasta (1)
- Business (16)
- Business Continuity (6)
- Business Continuity Planning (2)
- Caas (1)
- Certification (1)
- Christian Hyatt (19)
- CI (1)
- CISO (8)
- CISO Discussions (24)
- Cloud (1)
- CMMC (1)
- Competitive (1)
- Compliance (17)
- Compliance As A Service (5)
- COVID (1)
- Cyber Risk (6)
- Cyber Risk Management (59)
- Cyber Security Law (2)
- Cybersecurity (26)
- Cybersecurity Controls (4)
- Disaster Recovery (5)
- Engineers (1)
- Ethical Hacking (1)
- EU AI Act (3)
- Exercises (1)
- GDPR (4)
- GRC Tool (6)
- Grit (1)
- Hacking (3)
- Hashcat (1)
- HITRUST (16)
- IaaS (1)
- Information Security (11)
- Internal Audit (2)
- ISO (3)
- ISO 22301 (1)
- ISO 27001 (18)
- ISO 27001 Compliance (19)
- ISO 27018 (1)
- ISO 27701 (2)
- ISO 42001 (6)
- ISO 42005 (1)
- IT Audit (9)
- IT Audit And Compliance (33)
- Kahoot (1)
- Leadership (6)
- Management (1)
- Network Security (4)
- News (5)
- News And Events (20)
- NIST 800 Series (2)
- NIST 800-171 (1)
- OSINT (1)
- Outsourced Pci (1)
- P2pe (1)
- Passwords (3)
- PCI DSS (13)
- Penetration Test (7)
- Penetration Testing (31)
- Pentest Report (1)
- Phishing (1)
- PIA (1)
- Press Release (3)
- Privacy (8)
- Privacy Compliance (7)
- Privacy Impact Assessment (1)
- Privacy Shield (1)
- Ransomeware (1)
- Regulatory Compliance (12)
- Report (2)
- Risk Assessment (5)
- Risk Management (19)
- SDLC (2)
- Security (22)
- Security Advisory (1)
- SOC 2 (18)
- SOC Reporting (23)
- Soc2 (1)
- Strategy (1)
- System Backdoor (1)
- Tabletop (1)
- Training (5)
- VCISO (7)
- Vendor Management (2)
- Vulnerability Management (2)
- Vulnerability Scan (1)
- Wannacry (1)
- Webinars (9)