soc_2_requirement

    Bridge Letter
    SOC 2 Overview of SOC 2 requirements Bridge Letter Bridge Letter Overview of SOC 2 requirements Scoping TSCs (common + additional) Controls under TSCs Observation period Bridge letter Sometimes, there is a gap between the end of your SOC 2 report and the current day. That is where a bridge letter comes in. A bridge…
    SOC 2 Observation Period
    SOC 2 Overview of SOC 2 requirements SOC 2 Observation Period SOC 2 Observation Period Overview of SOC 2 requirements Scoping TSCs (common + additional) Controls under TSCs Observation period Bridge letter For initial SOC 2 Type 2 audits, the observation period is typically 6 months, though some organizations opt for a shorter period (around…
    Controls under TSCs
    SOC 2 Overview of SOC 2 requirements Controls under TSCs Controls under TSCs Overview of SOC 2 requirements Scoping TSCs (common + additional) Controls under TSCs Observation period Bridge letter Controls show how your organization meets each of the Trust Services Criteria. SOC 2 doesn’t hand you a checklist; you build your own set of…
    Trust Services Criteria (TSCs)
    SOC 2 Overview of SOC 2 requirements Trust Services Criteria (TSCs) Trust Services Criteria (TSCs) Overview of SOC 2 requirements Scoping TSCs (common + additional) Controls under TSCs Observation period Bridge letter Everything in SOC 2 ties back to the Trust Services Criteria (or Trust Service Principles (TSPs) , five key principles defined by the…
    What falls within scope?
    SOC 2 Overview of SOC 2 requirements What falls within scope? What falls within scope? Overview of SOC 2 requirements Scoping TSCs (common + additional) Controls under TSCs Observation period Bridge letter SOC 2 doesn’t audit your entire company, it audits the part that delivers a specific service to customers. That’s your system boundary, commonly…
    Overview of SOC 2 requirements
    SOC 2 Overview of SOC 2 requirements Overview of SOC 2 requirements Overview of SOC 2 requirements Scoping TSCs (common + additional) Controls under TSCs Observation period Bridge letter SOC 2 compliance requires organizations to establish and follow strict information security policies and procedures. Unlike more prescriptive frameworks, SOC 2 doesn’t provide a specific checklist…