SOC 2
OVERVIEW#
SOC 2 (System and Organization Controls 2) is an AICPA attestation report on a service organization's controls relevant to the Trust Services Criteria. It is common in vendor due diligence and often requested alongside ISO 27001. This sheet covers the report types, the five criteria, control mapping, and the audit process.
KEY FACTS#
# Owner: AICPA (US); performed by a licensed CPA firm # Standard: SSAE 18 / AT-C 105 & 205; Trust Services Criteria (TSC) # Audience: customers, partners (report is confidential, NDA-gated) # Not a certification - it is an attestation REPORT with an opinion # Contrast: ISO 27001 = certifiable ISMS standard (international)
REPORT TYPES#
# SOC 1 - controls relevant to financial reporting (ICFR) - not this # SOC 2 - controls relevant to the Trust Services Criteria # SOC 3 - public-facing summary of a SOC 2 (no detail, shareable)
SOC 2 TYPE I vs TYPE II#
# TYPE I - design of controls at a POINT IN TIME # (are the right controls defined?) # TYPE II - design + OPERATING EFFECTIVENESS over a PERIOD # (typically 3-12 months; usually 6-12) # (did the controls actually work over time?) # Type II is what most customers want in vendor due diligence
TRUST SERVICES CRITERIA (TSC)#
# SECURITY (Common Criteria, CC) - MANDATORY in every SOC 2 # protection against unauthorized access (physical + logical) # AVAILABILITY - system uptime / SLAs / DR # PROCESSING INTEGRITY- complete, valid, accurate, timely processing # CONFIDENTIALITY - protection of confidential information # PRIVACY - PII collected/used/retained/disposed per notice # You always include Security; add others based on service + customer # commitments
COMMON CRITERIA (CC SERIES)#
# CC1 Control environment (governance, ethics, org structure) # CC2 Communication & information # CC3 Risk assessment # CC4 Monitoring activities # CC5 Control activities # CC6 Logical & physical access controls # CC7 System operations (incident, monitoring, detection) # CC8 Change management # CC9 Risk mitigation (vendor / business disruption) # CC = the Security criterion, structured on the COSO framework
TYPICAL CONTROL AREAS (EVIDENCE)#
# - Access control: MFA, least privilege, joiner/mover/leaver, reviews # - Change management: PR review, approvals, CI/CD gates, ticketing # - Vulnerability mgmt: scanning cadence, patch SLAs, pen test # - Logging & monitoring: SIEM, alerting, retention # - Incident response: IR plan, tabletop, post-incident review # - Vendor management: third-party risk assessments, SOC 2 of subs # - BCP/DR: backups, restore tests, RTO/RPO # - HR security: background checks, security training, policy sign-off
AUDIT PROCESS#
# 1. Scoping - pick TSC, define system boundary + period # 2. Readiness assessment (gap analysis) - fix gaps before audit # 3. Remediation - implement/operate controls (Type II needs history) # 4. Audit fieldwork - CPA tests design + operating effectiveness # 5. Report issuance - opinion + control matrix + test results # 6. Annual cadence - Type II usually renewed each period
OPINION TYPES#
# Unqualified - controls suitably designed & operating (the goal) # Qualified - one or more exceptions noted # Adverse - controls not effective # Disclaimer - auditor cannot form an opinion
SOC 2 vs ISO 27001 (QUICK MAP)#
# SOC 2: US-oriented, attestation report, TSC, period-based (Type II) # ISO 27001: international, certifiable ISMS, Annex A / 2022 controls # Heavy overlap in controls - a strong ISMS covers most of CC6-CC8; # many orgs run both to satisfy different customers # Neither is DORA - but both provide design evidence toward DORA ICT # risk management (independent DORA-delta verification still required)
EXAMPLES#
# Decide TSC scope: Security (always) + Availability + Confidentiality # Choose Type II with a 6-month initial observation period # Map existing ISO 27001 Annex A controls to the CC series to reuse # Stand up access reviews + change tickets early (Type II needs a trail)
NOTES#
- SOC 2 is a REPORT, not a badge - "SOC 2 certified" is a misnomer; say "SOC 2 Type II report with an unqualified opinion" - Type II value comes from the observation period - controls must have an evidence trail across the whole window - The report is confidential; share under NDA, or share SOC 3 publicly - For LU FS clients, a vendor's SOC 2 Type II supports (but does not replace) DORA third-party due diligence and CSSF outsourcing review - Practitioner reference, not audit or legal advice
SOC 2 CHEATSHEET ================ Source: https://cheatsheet.johlem.net OVERVIEW -------- SOC 2 (System and Organization Controls 2) is an AICPA attestation report on a service organization's controls relevant to the Trust Services Criteria. It is common in vendor due diligence and often requested alongside ISO 27001. This sheet covers the report types, the five criteria, control mapping, and the audit process. KEY FACTS --------- # Owner: AICPA (US); performed by a licensed CPA firm # Standard: SSAE 18 / AT-C 105 & 205; Trust Services Criteria (TSC) # Audience: customers, partners (report is confidential, NDA-gated) # Not a certification - it is an attestation REPORT with an opinion # Contrast: ISO 27001 = certifiable ISMS standard (international) REPORT TYPES ------------ # SOC 1 - controls relevant to financial reporting (ICFR) - not this # SOC 2 - controls relevant to the Trust Services Criteria # SOC 3 - public-facing summary of a SOC 2 (no detail, shareable) SOC 2 TYPE I vs TYPE II ----------------------- # TYPE I - design of controls at a POINT IN TIME # (are the right controls defined?) # TYPE II - design + OPERATING EFFECTIVENESS over a PERIOD # (typically 3-12 months; usually 6-12) # (did the controls actually work over time?) # Type II is what most customers want in vendor due diligence TRUST SERVICES CRITERIA (TSC) ----------------------------- # SECURITY (Common Criteria, CC) - MANDATORY in every SOC 2 # protection against unauthorized access (physical + logical) # AVAILABILITY - system uptime / SLAs / DR # PROCESSING INTEGRITY- complete, valid, accurate, timely processing # CONFIDENTIALITY - protection of confidential information # PRIVACY - PII collected/used/retained/disposed per notice # You always include Security; add others based on service + customer # commitments COMMON CRITERIA (CC SERIES) --------------------------- # CC1 Control environment (governance, ethics, org structure) # CC2 Communication & information # CC3 Risk assessment # CC4 Monitoring activities # CC5 Control activities # CC6 Logical & physical access controls # CC7 System operations (incident, monitoring, detection) # CC8 Change management # CC9 Risk mitigation (vendor / business disruption) # CC = the Security criterion, structured on the COSO framework TYPICAL CONTROL AREAS (EVIDENCE) -------------------------------- # - Access control: MFA, least privilege, joiner/mover/leaver, reviews # - Change management: PR review, approvals, CI/CD gates, ticketing # - Vulnerability mgmt: scanning cadence, patch SLAs, pen test # - Logging & monitoring: SIEM, alerting, retention # - Incident response: IR plan, tabletop, post-incident review # - Vendor management: third-party risk assessments, SOC 2 of subs # - BCP/DR: backups, restore tests, RTO/RPO # - HR security: background checks, security training, policy sign-off AUDIT PROCESS ------------- # 1. Scoping - pick TSC, define system boundary + period # 2. Readiness assessment (gap analysis) - fix gaps before audit # 3. Remediation - implement/operate controls (Type II needs history) # 4. Audit fieldwork - CPA tests design + operating effectiveness # 5. Report issuance - opinion + control matrix + test results # 6. Annual cadence - Type II usually renewed each period OPINION TYPES ------------- # Unqualified - controls suitably designed & operating (the goal) # Qualified - one or more exceptions noted # Adverse - controls not effective # Disclaimer - auditor cannot form an opinion SOC 2 vs ISO 27001 (QUICK MAP) ------------------------------ # SOC 2: US-oriented, attestation report, TSC, period-based (Type II) # ISO 27001: international, certifiable ISMS, Annex A / 2022 controls # Heavy overlap in controls - a strong ISMS covers most of CC6-CC8; # many orgs run both to satisfy different customers # Neither is DORA - but both provide design evidence toward DORA ICT # risk management (independent DORA-delta verification still required) EXAMPLES -------- # Decide TSC scope: Security (always) + Availability + Confidentiality # Choose Type II with a 6-month initial observation period # Map existing ISO 27001 Annex A controls to the CC series to reuse # Stand up access reviews + change tickets early (Type II needs a trail) NOTES ----- - SOC 2 is a REPORT, not a badge - "SOC 2 certified" is a misnomer; say "SOC 2 Type II report with an unqualified opinion" - Type II value comes from the observation period - controls must have an evidence trail across the whole window - The report is confidential; share under NDA, or share SOC 3 publicly - For LU FS clients, a vendor's SOC 2 Type II supports (but does not replace) DORA third-party due diligence and CSSF outsourcing review - Practitioner reference, not audit or legal advice
Defensive reference on CyberRamen. Offensive / red-team sheets live on OffensiveRamen.com.