back to services

SOC Audit Process

Service Image

Team – Security Auditor/Governance Analyst, System Administrator (optional), Technical Writer (optional). Timelines – 1-2 weeks of the on-site fieldwork 2-4 weeks of follow-up work, depending on the scope; ongoing support (optional). Standard – SSAE 16 (SOC, SAS 70). Fees and Rates – economy airfare, accommodation, 70 CAD per diem, rates according to MSA.

GeeksForLess provides pre-audit evaluation, covering the controls and processes in the scope of SSAE 16 (SOC). The evaluation is performed on-site by a security expert. The key stakeholders are identified ahead of time and interviewed during the visit. The artifacts supporting the collected information about the controls and processes are requested and reviewed.The compliance gaps are identified, documented, and communicated to management through a checklist. Mitigation recommendations concerning the organization’s needs and capacities are a part of the checklist. Technical guidance facilitates the implementation and addresses the auditors’ requirements.

soc 2 audit

SCOPE AREAS

Operational

  • Personnel Security
  • Physical and Environmental Protection
  • Production, Input/Output Controls
  • Contingency Planning, Business Continuity, Disaster Recovery
  • Hardware and System Software Maintenance
  • Data Integrity
  • Change Management
  • Documentation
  • Security Awareness, Training, and Education
  • Incident Response Capability
soc 1 audit

MANAGEMENT

  • Risk Management
  • Security Controls
  • Review Lifecycle
  • Authorize Processing (Certification and Accreditation)
  • System

 

TECHNICAL

  • Identification and Authentication
  • Logical Access Controls
  • System-based Audit
Service Image

PREREQUISITES

Business

  • Determine the audited services
  • Define your customers
  • Describe user stories

 

Information Technology

  • Develop service maps
  • Prepare existing documentation
  • DELIVERABLES
  • Documents
  • Readiness assessment report
  • Findings and recommended mitigation steps
  • Optional
  • Risk assessment report Policies documentation
  • Prepare the hardware and software, inventory
  • Assign systems and processes, owners
soc report audit

DELIVERABLES

Documents

  • Readiness assessment report
  • Findings and recommended mitigation steps
  • Mitigation tracking checklist

Optional

  • Risk assessment report
  • Policies documentation
  • Process documentation
250 +
Clients
500 +
Projects
1000 +
Engineers

Let’s work together to build something great