SlideShare a Scribd company logo
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
SOC 2:
Build Trust & Confidence
Overview & Considerations
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
01. Background / Overview of SOC 2
02. The AICPA Framework
03. Purpose and Scope
04. The Anatomy
05. Considerations
06. Mapping – Other Standards
06. Q/A
Contents
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
Background
& Overview
01
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
Growth &
Popularity
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
Service
Auditors
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
Service
Providers
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
User Entities
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
Why Do You Need a SOC Report?
Regulatory requirements
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
Why Do You Need a SOC Report?
Regulatory requirements
User entity mandates
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
Why Do You Need a SOC Report?
Regulatory requirements
User entity mandates
Vendor management programs
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
Why Do You Need a SOC Report?
Regulatory requirements
User entity mandates
Vendor management programs
Due diligence
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
Why Do You Need a SOC Report?
Regulatory requirements
User entity mandates
Vendor management programs
Due diligence
Independent 3rd party opinion
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
Why Do You Need a SOC Report?
Regulatory requirements
User entity mandates
Vendor management programs
Due diligence
Independent 3rd party opinion
Competition and market
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
Overview
• What is a SOC 2 report?
• How does a SOC 2 differ from a SOC 1 report
• SOC 2 versus SOC 3
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
Overview of the
AICPA Framework
02
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
AICPA SOC Framework
Applicable SOC-1 SOC-2 SOC-3
Standard/Guidance
SSAE 16:
AICPA Guide (2013)
AT 101:
AICPA Guide (2013)
AT 101:
Technical Practice Aid
(2014)
Scope ICFR Security/Systems, Privacy Security/Systems, Privacy
Criteria Control Objectives
Trust Services
Principles/GAPP
Trust Services
Principles/GAPP
Usage of report
User auditor, user entity,
management of SO
Knowledgeable parties Anyone
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
Purpose
& Scope
03
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
Purpose
• What SOC 2 does cover?
• What SOC 2 does cover?
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
• System
• Boundaries
• Commitments
• System Requirements
Scope
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
Principles
• Security
• Availability
• Processing Integrity
• Confidentiality
• Privacy
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
Common Criteria (Security):
1: Organization & Mgmt
2: Communications
3: Risk Mgmt & Controls
4: Monitoring of Controls
5: Logical and Physical Access
6: System Operations
7: Change Management
Principles
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
Principles
Availability Common Criteria: +3
Processing Integrity Common Criteria: +6
Confidentiality Common Criteria: +6
Privacy Common Criteria: +74
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
• Type 1
• Type 2
Report Type
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
The
Anatomy
04
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
Service Auditor’s Report – “The Opinion”
Management’s Assertion
Description of the System
Tests of Controls and Corresponding Results
Additional Information – Provided by Service Organization
Report Structure
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
Unqualified vs. Qualified
Service Auditor’s Report
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
• Commitment - suitability and accuracy
• Subservice organizations
Management’s Assertion
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
• Management’s objective description of the
services provided to user entities
• Components of a System Description
System Description
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
• Test procedures
• Results
• Deviations / Exceptions
Test of Controls / Results
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
Intended Use
• Management of service organization
• User entities of the services
• Other knowledgeable parties
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
Considerations
05
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
Relevance To The User
• RFP requirements
• Customer mandates
• Regulatory needs
• Vendor management process
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
Understanding Reporting
• SOC 1 vs. SOC 2
• AT 101
• AT 601
• Agreed Upon Procedures
• Readiness Assessment
• PCI
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
Education & Preparedness
• Contracts, RFP, SLA
• AICPA website
• Training and awareness
• Executive communication
• Discussion with service auditor
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
Control Environment
• Start-up
• Developing systems
• No customers yet
• Lack of documentation /evidence
• No monitoring of controls
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
Carve-out Vs Inclusive
• Subservice organization
• Carve-out method emphasis
• Inclusive method requirements
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
Perform a risk assessment
Risk Assessment & Scope
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
• Internally
• Service auditors
Readiness Assessment
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
• Policies / Procedures
• Segregation of duties
• Monitoring
Remediation
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
• Licensed CPA firm
• Independent
• Single vendor approach
• Audit team
Audit Firm Selection
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
Mapping to Other
Standards
06
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
• SOC 1
• ISO 27001
• HIPAA
• HITRUST
• PCI
Other Standards
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
View the WebinarView the Webinar

More Related Content

What's hot

All you wanted to know about iso 27000
All you wanted to know about iso 27000All you wanted to know about iso 27000
All you wanted to know about iso 27000
Ramana K V
 
Privacy Trends: Key practical steps on ISO/IEC 27701:2019 implementation
Privacy Trends: Key practical steps on ISO/IEC 27701:2019 implementationPrivacy Trends: Key practical steps on ISO/IEC 27701:2019 implementation
Privacy Trends: Key practical steps on ISO/IEC 27701:2019 implementation
PECB
 
What is iso 27001 isms
What is iso 27001 ismsWhat is iso 27001 isms
What is iso 27001 isms
Craig Willetts ISO Expert
 
CISA Domain 1 - IS Auditing (day 1)
CISA Domain 1 - IS Auditing (day 1)CISA Domain 1 - IS Auditing (day 1)
CISA Domain 1 - IS Auditing (day 1)Cyril Soeri
 
Project plan for ISO 27001
Project plan for ISO 27001Project plan for ISO 27001
Project plan for ISO 27001
technakama
 
ISO/IEC 27001:2022 (Information Security Management Systems) Awareness Training
ISO/IEC 27001:2022 (Information Security Management Systems) Awareness TrainingISO/IEC 27001:2022 (Information Security Management Systems) Awareness Training
ISO/IEC 27001:2022 (Information Security Management Systems) Awareness Training
Operational Excellence Consulting
 
IT General Controls Presentation at IIA Vadodara Audit Club
IT General Controls Presentation at IIA Vadodara Audit ClubIT General Controls Presentation at IIA Vadodara Audit Club
IT General Controls Presentation at IIA Vadodara Audit Club
Kaushal Trivedi
 
Iso27001- Nashwan Mustafa
Iso27001- Nashwan MustafaIso27001- Nashwan Mustafa
Iso27001- Nashwan Mustafa
Fahmi Albaheth
 
ISO 27001
ISO 27001ISO 27001
Best Practices in Auditing ISO/IEC 27001
Best Practices in Auditing ISO/IEC 27001Best Practices in Auditing ISO/IEC 27001
Best Practices in Auditing ISO/IEC 27001
PECB
 
Control Standards for Information Security
Control Standards for Information SecurityControl Standards for Information Security
Control Standards for Information Security
JohnHPazEMCPMPITIL5G
 
ISO/IEC 27001:2022 – What are the changes?
ISO/IEC 27001:2022 – What are the changes?ISO/IEC 27001:2022 – What are the changes?
ISO/IEC 27001:2022 – What are the changes?
PECB
 
IT System & Security Audit
IT System & Security AuditIT System & Security Audit
IT System & Security Audit
Mufaddal Nullwala
 
ITIL Continual Service Improvement
ITIL Continual Service ImprovementITIL Continual Service Improvement
ITIL Continual Service Improvement
Marvin Sirait
 
Iso 27001 awareness
Iso 27001 awarenessIso 27001 awareness
Iso 27001 awareness
Ãsħâr Ãâlâm
 
Cisa domain 1
Cisa domain 1 Cisa domain 1
Cisa domain 1
Ismail aboulezz
 
SOC-2 Framework - Plan, Budget, Design, Integrate & Audit Security Controls
SOC-2 Framework - Plan, Budget, Design, Integrate & Audit Security ControlsSOC-2 Framework - Plan, Budget, Design, Integrate & Audit Security Controls
SOC-2 Framework - Plan, Budget, Design, Integrate & Audit Security Controls
Mark S. Mahre
 
ISO 27001 2013 isms final overview
ISO 27001 2013 isms final overviewISO 27001 2013 isms final overview
ISO 27001 2013 isms final overview
Naresh Rao
 
What is ISO 27001 ISMS
What is ISO 27001 ISMSWhat is ISO 27001 ISMS
What is ISO 27001 ISMS
Business Beam
 
ISO 27001:2022 What has changed.pdf
ISO 27001:2022 What has changed.pdfISO 27001:2022 What has changed.pdf
ISO 27001:2022 What has changed.pdf
Andrey Prozorov, CISM, CIPP/E, CDPSE. LA 27001
 

What's hot (20)

All you wanted to know about iso 27000
All you wanted to know about iso 27000All you wanted to know about iso 27000
All you wanted to know about iso 27000
 
Privacy Trends: Key practical steps on ISO/IEC 27701:2019 implementation
Privacy Trends: Key practical steps on ISO/IEC 27701:2019 implementationPrivacy Trends: Key practical steps on ISO/IEC 27701:2019 implementation
Privacy Trends: Key practical steps on ISO/IEC 27701:2019 implementation
 
What is iso 27001 isms
What is iso 27001 ismsWhat is iso 27001 isms
What is iso 27001 isms
 
CISA Domain 1 - IS Auditing (day 1)
CISA Domain 1 - IS Auditing (day 1)CISA Domain 1 - IS Auditing (day 1)
CISA Domain 1 - IS Auditing (day 1)
 
Project plan for ISO 27001
Project plan for ISO 27001Project plan for ISO 27001
Project plan for ISO 27001
 
ISO/IEC 27001:2022 (Information Security Management Systems) Awareness Training
ISO/IEC 27001:2022 (Information Security Management Systems) Awareness TrainingISO/IEC 27001:2022 (Information Security Management Systems) Awareness Training
ISO/IEC 27001:2022 (Information Security Management Systems) Awareness Training
 
IT General Controls Presentation at IIA Vadodara Audit Club
IT General Controls Presentation at IIA Vadodara Audit ClubIT General Controls Presentation at IIA Vadodara Audit Club
IT General Controls Presentation at IIA Vadodara Audit Club
 
Iso27001- Nashwan Mustafa
Iso27001- Nashwan MustafaIso27001- Nashwan Mustafa
Iso27001- Nashwan Mustafa
 
ISO 27001
ISO 27001ISO 27001
ISO 27001
 
Best Practices in Auditing ISO/IEC 27001
Best Practices in Auditing ISO/IEC 27001Best Practices in Auditing ISO/IEC 27001
Best Practices in Auditing ISO/IEC 27001
 
Control Standards for Information Security
Control Standards for Information SecurityControl Standards for Information Security
Control Standards for Information Security
 
ISO/IEC 27001:2022 – What are the changes?
ISO/IEC 27001:2022 – What are the changes?ISO/IEC 27001:2022 – What are the changes?
ISO/IEC 27001:2022 – What are the changes?
 
IT System & Security Audit
IT System & Security AuditIT System & Security Audit
IT System & Security Audit
 
ITIL Continual Service Improvement
ITIL Continual Service ImprovementITIL Continual Service Improvement
ITIL Continual Service Improvement
 
Iso 27001 awareness
Iso 27001 awarenessIso 27001 awareness
Iso 27001 awareness
 
Cisa domain 1
Cisa domain 1 Cisa domain 1
Cisa domain 1
 
SOC-2 Framework - Plan, Budget, Design, Integrate & Audit Security Controls
SOC-2 Framework - Plan, Budget, Design, Integrate & Audit Security ControlsSOC-2 Framework - Plan, Budget, Design, Integrate & Audit Security Controls
SOC-2 Framework - Plan, Budget, Design, Integrate & Audit Security Controls
 
ISO 27001 2013 isms final overview
ISO 27001 2013 isms final overviewISO 27001 2013 isms final overview
ISO 27001 2013 isms final overview
 
What is ISO 27001 ISMS
What is ISO 27001 ISMSWhat is ISO 27001 ISMS
What is ISO 27001 ISMS
 
ISO 27001:2022 What has changed.pdf
ISO 27001:2022 What has changed.pdfISO 27001:2022 What has changed.pdf
ISO 27001:2022 What has changed.pdf
 

Similar to SOC 2: Build Trust and Confidence

Hitrust: Navigating to 2017, Your Map to HITRUST Certification
Hitrust: Navigating to 2017, Your Map to HITRUST CertificationHitrust: Navigating to 2017, Your Map to HITRUST Certification
Hitrust: Navigating to 2017, Your Map to HITRUST Certification
Schellman & Company
 
Salesforce.com Relaunch Featuring Customer Success Story From Aon
Salesforce.com Relaunch Featuring Customer Success Story From AonSalesforce.com Relaunch Featuring Customer Success Story From Aon
Salesforce.com Relaunch Featuring Customer Success Story From AonRightpoint
 
Issues Management In The Digital Age
Issues Management In The Digital AgeIssues Management In The Digital Age
Issues Management In The Digital Age
Charlie Pownall
 
Achieving SSAE 16 Certification
Achieving SSAE 16 Certification Achieving SSAE 16 Certification
Achieving SSAE 16 Certification
Gary Pennington
 
Facilities Management - Extending Service Automation to Outside Contractors
Facilities Management - Extending Service Automation to Outside ContractorsFacilities Management - Extending Service Automation to Outside Contractors
Facilities Management - Extending Service Automation to Outside Contractors
ServiceChannel
 
EPCS Overview
EPCS OverviewEPCS Overview
EPCS Overview
Schellman & Company
 
Service Organizational Control (SOC 2) Compliance - Kloudlearn
Service Organizational Control  (SOC 2) Compliance - KloudlearnService Organizational Control  (SOC 2) Compliance - Kloudlearn
Service Organizational Control (SOC 2) Compliance - Kloudlearn
KloudLearn
 
Innovation TVA Presentation Deck
Innovation TVA Presentation DeckInnovation TVA Presentation Deck
Innovation TVA Presentation DeckJoe Scherrer
 
CQS_ISO 2015_ASQR (4-16-15)
CQS_ISO 2015_ASQR (4-16-15)CQS_ISO 2015_ASQR (4-16-15)
CQS_ISO 2015_ASQR (4-16-15)Lori Cohen
 
2016 AICPA Bank - CECL Governance
2016 AICPA Bank - CECL Governance2016 AICPA Bank - CECL Governance
2016 AICPA Bank - CECL GovernanceDorsey Baskin
 
Cigniti joint webinar with Soasta - Agile DevOps: Test-driven IT Environment ...
Cigniti joint webinar with Soasta - Agile DevOps: Test-driven IT Environment ...Cigniti joint webinar with Soasta - Agile DevOps: Test-driven IT Environment ...
Cigniti joint webinar with Soasta - Agile DevOps: Test-driven IT Environment ...
Cigniti Technologies Ltd
 
It12015
It12015It12015
Customer Success in the Healthcare Industry
Customer Success in the Healthcare IndustryCustomer Success in the Healthcare Industry
Customer Success in the Healthcare Industry
Gainsight
 
So CaTec 2015 metrics
So CaTec 2015   metricsSo CaTec 2015   metrics
So CaTec 2015 metrics
Kathryn Kuhn
 
BSW Value of Muni Audits
BSW Value of Muni AuditsBSW Value of Muni Audits
BSW Value of Muni AuditsRon Steinkamp
 
The Future of Auditing and Fraud Detection
The Future of Auditing and Fraud Detection The Future of Auditing and Fraud Detection
The Future of Auditing and Fraud Detection
Jim Kaplan CIA CFE
 
AgileCamp Silicon Valley 2015: Unlock Excellence with Agile Metrics
AgileCamp Silicon Valley 2015: Unlock Excellence with Agile MetricsAgileCamp Silicon Valley 2015: Unlock Excellence with Agile Metrics
AgileCamp Silicon Valley 2015: Unlock Excellence with Agile Metrics
Hyperdrive Agile Leadership (powered by Bratton & Company)
 
Manage Supplier Risk - Drive Superior Supplier Quality Outcomes (CEB Webinar)
Manage Supplier Risk - Drive Superior Supplier Quality Outcomes (CEB Webinar)Manage Supplier Risk - Drive Superior Supplier Quality Outcomes (CEB Webinar)
Manage Supplier Risk - Drive Superior Supplier Quality Outcomes (CEB Webinar)
Simone Silva, MS, MBA
 
Manage Supplier Risk - Drive Superior Supplier Quality Outcomes (CEB Webinar)
Manage Supplier Risk - Drive Superior Supplier Quality Outcomes (CEB Webinar)Manage Supplier Risk - Drive Superior Supplier Quality Outcomes (CEB Webinar)
Manage Supplier Risk - Drive Superior Supplier Quality Outcomes (CEB Webinar)
Simone Silva, MS, MBA
 
Update on BPAS as Your Retirement Plan Partner and Evolution of the DC Servic...
Update on BPAS as Your Retirement Plan Partner and Evolution of the DC Servic...Update on BPAS as Your Retirement Plan Partner and Evolution of the DC Servic...
Update on BPAS as Your Retirement Plan Partner and Evolution of the DC Servic...
BPAS
 

Similar to SOC 2: Build Trust and Confidence (20)

Hitrust: Navigating to 2017, Your Map to HITRUST Certification
Hitrust: Navigating to 2017, Your Map to HITRUST CertificationHitrust: Navigating to 2017, Your Map to HITRUST Certification
Hitrust: Navigating to 2017, Your Map to HITRUST Certification
 
Salesforce.com Relaunch Featuring Customer Success Story From Aon
Salesforce.com Relaunch Featuring Customer Success Story From AonSalesforce.com Relaunch Featuring Customer Success Story From Aon
Salesforce.com Relaunch Featuring Customer Success Story From Aon
 
Issues Management In The Digital Age
Issues Management In The Digital AgeIssues Management In The Digital Age
Issues Management In The Digital Age
 
Achieving SSAE 16 Certification
Achieving SSAE 16 Certification Achieving SSAE 16 Certification
Achieving SSAE 16 Certification
 
Facilities Management - Extending Service Automation to Outside Contractors
Facilities Management - Extending Service Automation to Outside ContractorsFacilities Management - Extending Service Automation to Outside Contractors
Facilities Management - Extending Service Automation to Outside Contractors
 
EPCS Overview
EPCS OverviewEPCS Overview
EPCS Overview
 
Service Organizational Control (SOC 2) Compliance - Kloudlearn
Service Organizational Control  (SOC 2) Compliance - KloudlearnService Organizational Control  (SOC 2) Compliance - Kloudlearn
Service Organizational Control (SOC 2) Compliance - Kloudlearn
 
Innovation TVA Presentation Deck
Innovation TVA Presentation DeckInnovation TVA Presentation Deck
Innovation TVA Presentation Deck
 
CQS_ISO 2015_ASQR (4-16-15)
CQS_ISO 2015_ASQR (4-16-15)CQS_ISO 2015_ASQR (4-16-15)
CQS_ISO 2015_ASQR (4-16-15)
 
2016 AICPA Bank - CECL Governance
2016 AICPA Bank - CECL Governance2016 AICPA Bank - CECL Governance
2016 AICPA Bank - CECL Governance
 
Cigniti joint webinar with Soasta - Agile DevOps: Test-driven IT Environment ...
Cigniti joint webinar with Soasta - Agile DevOps: Test-driven IT Environment ...Cigniti joint webinar with Soasta - Agile DevOps: Test-driven IT Environment ...
Cigniti joint webinar with Soasta - Agile DevOps: Test-driven IT Environment ...
 
It12015
It12015It12015
It12015
 
Customer Success in the Healthcare Industry
Customer Success in the Healthcare IndustryCustomer Success in the Healthcare Industry
Customer Success in the Healthcare Industry
 
So CaTec 2015 metrics
So CaTec 2015   metricsSo CaTec 2015   metrics
So CaTec 2015 metrics
 
BSW Value of Muni Audits
BSW Value of Muni AuditsBSW Value of Muni Audits
BSW Value of Muni Audits
 
The Future of Auditing and Fraud Detection
The Future of Auditing and Fraud Detection The Future of Auditing and Fraud Detection
The Future of Auditing and Fraud Detection
 
AgileCamp Silicon Valley 2015: Unlock Excellence with Agile Metrics
AgileCamp Silicon Valley 2015: Unlock Excellence with Agile MetricsAgileCamp Silicon Valley 2015: Unlock Excellence with Agile Metrics
AgileCamp Silicon Valley 2015: Unlock Excellence with Agile Metrics
 
Manage Supplier Risk - Drive Superior Supplier Quality Outcomes (CEB Webinar)
Manage Supplier Risk - Drive Superior Supplier Quality Outcomes (CEB Webinar)Manage Supplier Risk - Drive Superior Supplier Quality Outcomes (CEB Webinar)
Manage Supplier Risk - Drive Superior Supplier Quality Outcomes (CEB Webinar)
 
Manage Supplier Risk - Drive Superior Supplier Quality Outcomes (CEB Webinar)
Manage Supplier Risk - Drive Superior Supplier Quality Outcomes (CEB Webinar)Manage Supplier Risk - Drive Superior Supplier Quality Outcomes (CEB Webinar)
Manage Supplier Risk - Drive Superior Supplier Quality Outcomes (CEB Webinar)
 
Update on BPAS as Your Retirement Plan Partner and Evolution of the DC Servic...
Update on BPAS as Your Retirement Plan Partner and Evolution of the DC Servic...Update on BPAS as Your Retirement Plan Partner and Evolution of the DC Servic...
Update on BPAS as Your Retirement Plan Partner and Evolution of the DC Servic...
 

More from Schellman & Company

Privacy in the Cloud- Introduction to ISO 27018
Privacy in the Cloud- Introduction to ISO 27018Privacy in the Cloud- Introduction to ISO 27018
Privacy in the Cloud- Introduction to ISO 27018
Schellman & Company
 
Demystifying the Cyber NISTs
Demystifying the Cyber NISTsDemystifying the Cyber NISTs
Demystifying the Cyber NISTs
Schellman & Company
 
Determining Scope for PCI DSS Compliance
Determining Scope for PCI DSS ComplianceDetermining Scope for PCI DSS Compliance
Determining Scope for PCI DSS Compliance
Schellman & Company
 
Privacy shield: What You Need To Know About Storing EU Data
Privacy shield: What You Need To Know About Storing EU DataPrivacy shield: What You Need To Know About Storing EU Data
Privacy shield: What You Need To Know About Storing EU Data
Schellman & Company
 
Everything You Need To Know About SOC 1
Everything You Need To Know About SOC 1Everything You Need To Know About SOC 1
Everything You Need To Know About SOC 1
Schellman & Company
 
Work With Federal Agencies? Here's What You Should Know About FedRAMP Assessm...
Work With Federal Agencies? Here's What You Should Know About FedRAMP Assessm...Work With Federal Agencies? Here's What You Should Know About FedRAMP Assessm...
Work With Federal Agencies? Here's What You Should Know About FedRAMP Assessm...
Schellman & Company
 
PA-DSS and Application Penetration Testing
PA-DSS and Application Penetration TestingPA-DSS and Application Penetration Testing
PA-DSS and Application Penetration Testing
Schellman & Company
 
The CSA STAR Program: Certification & Attestation
The CSA STAR Program: Certification & AttestationThe CSA STAR Program: Certification & Attestation
The CSA STAR Program: Certification & Attestation
Schellman & Company
 
Get Ready Now for HITRUST 2017
Get Ready Now for HITRUST 2017Get Ready Now for HITRUST 2017
Get Ready Now for HITRUST 2017
Schellman & Company
 
STAND OUT: Why You Should Become ISO 27001 Certified
STAND OUT: Why You Should Become ISO 27001 CertifiedSTAND OUT: Why You Should Become ISO 27001 Certified
STAND OUT: Why You Should Become ISO 27001 Certified
Schellman & Company
 
Locking Up Your Cloud Environment: An Introduction to ISO/IEC 27017 and 27018
Locking Up Your Cloud Environment: An Introduction to ISO/IEC 27017 and 27018Locking Up Your Cloud Environment: An Introduction to ISO/IEC 27017 and 27018
Locking Up Your Cloud Environment: An Introduction to ISO/IEC 27017 and 27018
Schellman & Company
 
12 Steps to Preparing for a QAR
12 Steps to Preparing for a QAR12 Steps to Preparing for a QAR
12 Steps to Preparing for a QAR
Schellman & Company
 
PCI DSS 3.0 Overview and Key Updates
PCI DSS 3.0 Overview and Key UpdatesPCI DSS 3.0 Overview and Key Updates
PCI DSS 3.0 Overview and Key Updates
Schellman & Company
 
10 Steps Toward FedRAMP Compliance
10 Steps Toward FedRAMP Compliance10 Steps Toward FedRAMP Compliance
10 Steps Toward FedRAMP Compliance
Schellman & Company
 
Your've Been Hacked in Florida! Now What?
Your've Been Hacked in Florida! Now What?Your've Been Hacked in Florida! Now What?
Your've Been Hacked in Florida! Now What?
Schellman & Company
 

More from Schellman & Company (15)

Privacy in the Cloud- Introduction to ISO 27018
Privacy in the Cloud- Introduction to ISO 27018Privacy in the Cloud- Introduction to ISO 27018
Privacy in the Cloud- Introduction to ISO 27018
 
Demystifying the Cyber NISTs
Demystifying the Cyber NISTsDemystifying the Cyber NISTs
Demystifying the Cyber NISTs
 
Determining Scope for PCI DSS Compliance
Determining Scope for PCI DSS ComplianceDetermining Scope for PCI DSS Compliance
Determining Scope for PCI DSS Compliance
 
Privacy shield: What You Need To Know About Storing EU Data
Privacy shield: What You Need To Know About Storing EU DataPrivacy shield: What You Need To Know About Storing EU Data
Privacy shield: What You Need To Know About Storing EU Data
 
Everything You Need To Know About SOC 1
Everything You Need To Know About SOC 1Everything You Need To Know About SOC 1
Everything You Need To Know About SOC 1
 
Work With Federal Agencies? Here's What You Should Know About FedRAMP Assessm...
Work With Federal Agencies? Here's What You Should Know About FedRAMP Assessm...Work With Federal Agencies? Here's What You Should Know About FedRAMP Assessm...
Work With Federal Agencies? Here's What You Should Know About FedRAMP Assessm...
 
PA-DSS and Application Penetration Testing
PA-DSS and Application Penetration TestingPA-DSS and Application Penetration Testing
PA-DSS and Application Penetration Testing
 
The CSA STAR Program: Certification & Attestation
The CSA STAR Program: Certification & AttestationThe CSA STAR Program: Certification & Attestation
The CSA STAR Program: Certification & Attestation
 
Get Ready Now for HITRUST 2017
Get Ready Now for HITRUST 2017Get Ready Now for HITRUST 2017
Get Ready Now for HITRUST 2017
 
STAND OUT: Why You Should Become ISO 27001 Certified
STAND OUT: Why You Should Become ISO 27001 CertifiedSTAND OUT: Why You Should Become ISO 27001 Certified
STAND OUT: Why You Should Become ISO 27001 Certified
 
Locking Up Your Cloud Environment: An Introduction to ISO/IEC 27017 and 27018
Locking Up Your Cloud Environment: An Introduction to ISO/IEC 27017 and 27018Locking Up Your Cloud Environment: An Introduction to ISO/IEC 27017 and 27018
Locking Up Your Cloud Environment: An Introduction to ISO/IEC 27017 and 27018
 
12 Steps to Preparing for a QAR
12 Steps to Preparing for a QAR12 Steps to Preparing for a QAR
12 Steps to Preparing for a QAR
 
PCI DSS 3.0 Overview and Key Updates
PCI DSS 3.0 Overview and Key UpdatesPCI DSS 3.0 Overview and Key Updates
PCI DSS 3.0 Overview and Key Updates
 
10 Steps Toward FedRAMP Compliance
10 Steps Toward FedRAMP Compliance10 Steps Toward FedRAMP Compliance
10 Steps Toward FedRAMP Compliance
 
Your've Been Hacked in Florida! Now What?
Your've Been Hacked in Florida! Now What?Your've Been Hacked in Florida! Now What?
Your've Been Hacked in Florida! Now What?
 

Recently uploaded

Key Trends Shaping the Future of Infrastructure.pdf
Key Trends Shaping the Future of Infrastructure.pdfKey Trends Shaping the Future of Infrastructure.pdf
Key Trends Shaping the Future of Infrastructure.pdf
Cheryl Hung
 
The Art of the Pitch: WordPress Relationships and Sales
The Art of the Pitch: WordPress Relationships and SalesThe Art of the Pitch: WordPress Relationships and Sales
The Art of the Pitch: WordPress Relationships and Sales
Laura Byrne
 
FIDO Alliance Osaka Seminar: FIDO Security Aspects.pdf
FIDO Alliance Osaka Seminar: FIDO Security Aspects.pdfFIDO Alliance Osaka Seminar: FIDO Security Aspects.pdf
FIDO Alliance Osaka Seminar: FIDO Security Aspects.pdf
FIDO Alliance
 
Designing Great Products: The Power of Design and Leadership by Chief Designe...
Designing Great Products: The Power of Design and Leadership by Chief Designe...Designing Great Products: The Power of Design and Leadership by Chief Designe...
Designing Great Products: The Power of Design and Leadership by Chief Designe...
Product School
 
De-mystifying Zero to One: Design Informed Techniques for Greenfield Innovati...
De-mystifying Zero to One: Design Informed Techniques for Greenfield Innovati...De-mystifying Zero to One: Design Informed Techniques for Greenfield Innovati...
De-mystifying Zero to One: Design Informed Techniques for Greenfield Innovati...
Product School
 
GraphRAG is All You need? LLM & Knowledge Graph
GraphRAG is All You need? LLM & Knowledge GraphGraphRAG is All You need? LLM & Knowledge Graph
GraphRAG is All You need? LLM & Knowledge Graph
Guy Korland
 
Slack (or Teams) Automation for Bonterra Impact Management (fka Social Soluti...
Slack (or Teams) Automation for Bonterra Impact Management (fka Social Soluti...Slack (or Teams) Automation for Bonterra Impact Management (fka Social Soluti...
Slack (or Teams) Automation for Bonterra Impact Management (fka Social Soluti...
Jeffrey Haguewood
 
LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...
LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...
LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...
DanBrown980551
 
To Graph or Not to Graph Knowledge Graph Architectures and LLMs
To Graph or Not to Graph Knowledge Graph Architectures and LLMsTo Graph or Not to Graph Knowledge Graph Architectures and LLMs
To Graph or Not to Graph Knowledge Graph Architectures and LLMs
Paul Groth
 
GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...
GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...
GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...
Sri Ambati
 
Essentials of Automations: Optimizing FME Workflows with Parameters
Essentials of Automations: Optimizing FME Workflows with ParametersEssentials of Automations: Optimizing FME Workflows with Parameters
Essentials of Automations: Optimizing FME Workflows with Parameters
Safe Software
 
UiPath Test Automation using UiPath Test Suite series, part 3
UiPath Test Automation using UiPath Test Suite series, part 3UiPath Test Automation using UiPath Test Suite series, part 3
UiPath Test Automation using UiPath Test Suite series, part 3
DianaGray10
 
Leading Change strategies and insights for effective change management pdf 1.pdf
Leading Change strategies and insights for effective change management pdf 1.pdfLeading Change strategies and insights for effective change management pdf 1.pdf
Leading Change strategies and insights for effective change management pdf 1.pdf
OnBoard
 
Transcript: Selling digital books in 2024: Insights from industry leaders - T...
Transcript: Selling digital books in 2024: Insights from industry leaders - T...Transcript: Selling digital books in 2024: Insights from industry leaders - T...
Transcript: Selling digital books in 2024: Insights from industry leaders - T...
BookNet Canada
 
Bits & Pixels using AI for Good.........
Bits & Pixels using AI for Good.........Bits & Pixels using AI for Good.........
Bits & Pixels using AI for Good.........
Alison B. Lowndes
 
Encryption in Microsoft 365 - ExpertsLive Netherlands 2024
Encryption in Microsoft 365 - ExpertsLive Netherlands 2024Encryption in Microsoft 365 - ExpertsLive Netherlands 2024
Encryption in Microsoft 365 - ExpertsLive Netherlands 2024
Albert Hoitingh
 
State of ICS and IoT Cyber Threat Landscape Report 2024 preview
State of ICS and IoT Cyber Threat Landscape Report 2024 previewState of ICS and IoT Cyber Threat Landscape Report 2024 preview
State of ICS and IoT Cyber Threat Landscape Report 2024 preview
Prayukth K V
 
Mission to Decommission: Importance of Decommissioning Products to Increase E...
Mission to Decommission: Importance of Decommissioning Products to Increase E...Mission to Decommission: Importance of Decommissioning Products to Increase E...
Mission to Decommission: Importance of Decommissioning Products to Increase E...
Product School
 
Unsubscribed: Combat Subscription Fatigue With a Membership Mentality by Head...
Unsubscribed: Combat Subscription Fatigue With a Membership Mentality by Head...Unsubscribed: Combat Subscription Fatigue With a Membership Mentality by Head...
Unsubscribed: Combat Subscription Fatigue With a Membership Mentality by Head...
Product School
 
Software Delivery At the Speed of AI: Inflectra Invests In AI-Powered Quality
Software Delivery At the Speed of AI: Inflectra Invests In AI-Powered QualitySoftware Delivery At the Speed of AI: Inflectra Invests In AI-Powered Quality
Software Delivery At the Speed of AI: Inflectra Invests In AI-Powered Quality
Inflectra
 

Recently uploaded (20)

Key Trends Shaping the Future of Infrastructure.pdf
Key Trends Shaping the Future of Infrastructure.pdfKey Trends Shaping the Future of Infrastructure.pdf
Key Trends Shaping the Future of Infrastructure.pdf
 
The Art of the Pitch: WordPress Relationships and Sales
The Art of the Pitch: WordPress Relationships and SalesThe Art of the Pitch: WordPress Relationships and Sales
The Art of the Pitch: WordPress Relationships and Sales
 
FIDO Alliance Osaka Seminar: FIDO Security Aspects.pdf
FIDO Alliance Osaka Seminar: FIDO Security Aspects.pdfFIDO Alliance Osaka Seminar: FIDO Security Aspects.pdf
FIDO Alliance Osaka Seminar: FIDO Security Aspects.pdf
 
Designing Great Products: The Power of Design and Leadership by Chief Designe...
Designing Great Products: The Power of Design and Leadership by Chief Designe...Designing Great Products: The Power of Design and Leadership by Chief Designe...
Designing Great Products: The Power of Design and Leadership by Chief Designe...
 
De-mystifying Zero to One: Design Informed Techniques for Greenfield Innovati...
De-mystifying Zero to One: Design Informed Techniques for Greenfield Innovati...De-mystifying Zero to One: Design Informed Techniques for Greenfield Innovati...
De-mystifying Zero to One: Design Informed Techniques for Greenfield Innovati...
 
GraphRAG is All You need? LLM & Knowledge Graph
GraphRAG is All You need? LLM & Knowledge GraphGraphRAG is All You need? LLM & Knowledge Graph
GraphRAG is All You need? LLM & Knowledge Graph
 
Slack (or Teams) Automation for Bonterra Impact Management (fka Social Soluti...
Slack (or Teams) Automation for Bonterra Impact Management (fka Social Soluti...Slack (or Teams) Automation for Bonterra Impact Management (fka Social Soluti...
Slack (or Teams) Automation for Bonterra Impact Management (fka Social Soluti...
 
LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...
LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...
LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...
 
To Graph or Not to Graph Knowledge Graph Architectures and LLMs
To Graph or Not to Graph Knowledge Graph Architectures and LLMsTo Graph or Not to Graph Knowledge Graph Architectures and LLMs
To Graph or Not to Graph Knowledge Graph Architectures and LLMs
 
GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...
GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...
GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...
 
Essentials of Automations: Optimizing FME Workflows with Parameters
Essentials of Automations: Optimizing FME Workflows with ParametersEssentials of Automations: Optimizing FME Workflows with Parameters
Essentials of Automations: Optimizing FME Workflows with Parameters
 
UiPath Test Automation using UiPath Test Suite series, part 3
UiPath Test Automation using UiPath Test Suite series, part 3UiPath Test Automation using UiPath Test Suite series, part 3
UiPath Test Automation using UiPath Test Suite series, part 3
 
Leading Change strategies and insights for effective change management pdf 1.pdf
Leading Change strategies and insights for effective change management pdf 1.pdfLeading Change strategies and insights for effective change management pdf 1.pdf
Leading Change strategies and insights for effective change management pdf 1.pdf
 
Transcript: Selling digital books in 2024: Insights from industry leaders - T...
Transcript: Selling digital books in 2024: Insights from industry leaders - T...Transcript: Selling digital books in 2024: Insights from industry leaders - T...
Transcript: Selling digital books in 2024: Insights from industry leaders - T...
 
Bits & Pixels using AI for Good.........
Bits & Pixels using AI for Good.........Bits & Pixels using AI for Good.........
Bits & Pixels using AI for Good.........
 
Encryption in Microsoft 365 - ExpertsLive Netherlands 2024
Encryption in Microsoft 365 - ExpertsLive Netherlands 2024Encryption in Microsoft 365 - ExpertsLive Netherlands 2024
Encryption in Microsoft 365 - ExpertsLive Netherlands 2024
 
State of ICS and IoT Cyber Threat Landscape Report 2024 preview
State of ICS and IoT Cyber Threat Landscape Report 2024 previewState of ICS and IoT Cyber Threat Landscape Report 2024 preview
State of ICS and IoT Cyber Threat Landscape Report 2024 preview
 
Mission to Decommission: Importance of Decommissioning Products to Increase E...
Mission to Decommission: Importance of Decommissioning Products to Increase E...Mission to Decommission: Importance of Decommissioning Products to Increase E...
Mission to Decommission: Importance of Decommissioning Products to Increase E...
 
Unsubscribed: Combat Subscription Fatigue With a Membership Mentality by Head...
Unsubscribed: Combat Subscription Fatigue With a Membership Mentality by Head...Unsubscribed: Combat Subscription Fatigue With a Membership Mentality by Head...
Unsubscribed: Combat Subscription Fatigue With a Membership Mentality by Head...
 
Software Delivery At the Speed of AI: Inflectra Invests In AI-Powered Quality
Software Delivery At the Speed of AI: Inflectra Invests In AI-Powered QualitySoftware Delivery At the Speed of AI: Inflectra Invests In AI-Powered Quality
Software Delivery At the Speed of AI: Inflectra Invests In AI-Powered Quality
 

SOC 2: Build Trust and Confidence

  • 1. ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved SOC 2: Build Trust & Confidence Overview & Considerations
  • 2. ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved 01. Background / Overview of SOC 2 02. The AICPA Framework 03. Purpose and Scope 04. The Anatomy 05. Considerations 06. Mapping – Other Standards 06. Q/A Contents
  • 3. ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved Background & Overview 01 ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
  • 4. ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved Growth & Popularity ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
  • 5. ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved Service Auditors ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
  • 6. ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved Service Providers
  • 7. ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved User Entities
  • 8. ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved Why Do You Need a SOC Report? Regulatory requirements
  • 9. ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved Why Do You Need a SOC Report? Regulatory requirements User entity mandates
  • 10. ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved Why Do You Need a SOC Report? Regulatory requirements User entity mandates Vendor management programs
  • 11. ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved Why Do You Need a SOC Report? Regulatory requirements User entity mandates Vendor management programs Due diligence
  • 12. ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved Why Do You Need a SOC Report? Regulatory requirements User entity mandates Vendor management programs Due diligence Independent 3rd party opinion
  • 13. ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved Why Do You Need a SOC Report? Regulatory requirements User entity mandates Vendor management programs Due diligence Independent 3rd party opinion Competition and market
  • 14. ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved Overview • What is a SOC 2 report? • How does a SOC 2 differ from a SOC 1 report • SOC 2 versus SOC 3
  • 15. ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved Overview of the AICPA Framework 02 ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
  • 16. ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved AICPA SOC Framework Applicable SOC-1 SOC-2 SOC-3 Standard/Guidance SSAE 16: AICPA Guide (2013) AT 101: AICPA Guide (2013) AT 101: Technical Practice Aid (2014) Scope ICFR Security/Systems, Privacy Security/Systems, Privacy Criteria Control Objectives Trust Services Principles/GAPP Trust Services Principles/GAPP Usage of report User auditor, user entity, management of SO Knowledgeable parties Anyone
  • 17. ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved Purpose & Scope 03 ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
  • 18. ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved Purpose • What SOC 2 does cover? • What SOC 2 does cover?
  • 19. ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved • System • Boundaries • Commitments • System Requirements Scope
  • 20. ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved Principles • Security • Availability • Processing Integrity • Confidentiality • Privacy
  • 21. ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved Common Criteria (Security): 1: Organization & Mgmt 2: Communications 3: Risk Mgmt & Controls 4: Monitoring of Controls 5: Logical and Physical Access 6: System Operations 7: Change Management Principles
  • 22. ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved Principles Availability Common Criteria: +3 Processing Integrity Common Criteria: +6 Confidentiality Common Criteria: +6 Privacy Common Criteria: +74
  • 23. ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved • Type 1 • Type 2 Report Type
  • 24. ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved The Anatomy 04 ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
  • 25. ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved Service Auditor’s Report – “The Opinion” Management’s Assertion Description of the System Tests of Controls and Corresponding Results Additional Information – Provided by Service Organization Report Structure
  • 26. ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved Unqualified vs. Qualified Service Auditor’s Report
  • 27. ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved • Commitment - suitability and accuracy • Subservice organizations Management’s Assertion
  • 28. ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved • Management’s objective description of the services provided to user entities • Components of a System Description System Description
  • 29. ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved • Test procedures • Results • Deviations / Exceptions Test of Controls / Results
  • 30. ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved Intended Use • Management of service organization • User entities of the services • Other knowledgeable parties
  • 31. ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved Considerations 05 ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
  • 32. ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved Relevance To The User • RFP requirements • Customer mandates • Regulatory needs • Vendor management process
  • 33. ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved Understanding Reporting • SOC 1 vs. SOC 2 • AT 101 • AT 601 • Agreed Upon Procedures • Readiness Assessment • PCI
  • 34. ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved Education & Preparedness • Contracts, RFP, SLA • AICPA website • Training and awareness • Executive communication • Discussion with service auditor
  • 35. ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved Control Environment • Start-up • Developing systems • No customers yet • Lack of documentation /evidence • No monitoring of controls
  • 36. ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved Carve-out Vs Inclusive • Subservice organization • Carve-out method emphasis • Inclusive method requirements
  • 37. ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved Perform a risk assessment Risk Assessment & Scope
  • 38. ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved • Internally • Service auditors Readiness Assessment
  • 39. ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved • Policies / Procedures • Segregation of duties • Monitoring Remediation
  • 40. ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved • Licensed CPA firm • Independent • Single vendor approach • Audit team Audit Firm Selection
  • 41. ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved Mapping to Other Standards 06 ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
  • 42. ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved • SOC 1 • ISO 27001 • HIPAA • HITRUST • PCI Other Standards
  • 43. ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved View the WebinarView the Webinar