SOC 2 Audit Insights – Patch Management

An effective patch management process is a critical component of cybersecurity strategy and is also essential to a successful SOC 2 audit.  Patching is relevant to several of the Trust Services Criteria (TSC) in a SOC 2 report, but is considered most applicable to the change management requirements under CC8.1.  When […]

What is a SOC 3 Examination?

A service organization may wish to provide prospective customers (user entities) with information regarding the effectiveness of controls over its system. However, the prospective customers may not have signed a nondisclosure agreement required by the service organization to access the system description in the SOC 2 report. In other situations, prospective […]

SOC 2 Reporting Updates

SOC 2 Updates

Two key resources for SOC 2 reporting were updated during 2022: Revised Implementation Guidance was added to DC 200, 2018 Description Criteria for a Description of a Service Organization’s System in a SOC 2 Report.  DC 200 includes the categories of information that must be addressed in an organization’s system description […]

DOL Cybersecurity Guidance

DOL Cybersecurity Guidance for 401(k) and Employee Benefit Plans The U.S. Department of Labor recently announced new guidance for plan sponsors, plan fiduciaries, record keepers, and plan participants on best practices for maintaining cybersecurity for 401(k) and employee benefit plans. The guidance is directed at plan sponsors and fiduciaries regulated by […]

The Impact of SSAE No. 21 on SOC 2 Audits

Background In September 2020, the AICPA Auditing Standards Board issued Statement on Standards for Attestation Engagements (SSAE) No. 21, Direct Examination Engagements. SSAE No. 21 is applicable to SOC 2 audits, however, the changes brought about by SSAE No. 21 consist primarily of new terminology and the clarification of certain concepts. […]

SOC for Supply Chain

Due to rapid technological advancement, the production, manufacture, or distribution of products often involves a high level of interdependence and connectivity between an entity and (a) organizations that supply raw materials or components for the manufacturing process (suppliers) and (b) the entity’s customers and business partners. These relationships are often considered part […]