A SOC Gap Assessment is how you get a benchmark for “where you are” against “where you need to get to” for a successful SOC examination. A gap assessment is the first step on your SOC journey, setting you up for better results when it is time for your SOC 2 Type 2 audit. Our gap assessment work will:
Provide an overview of SOC, determine the categories that should be in scope based on your service, identify showstoppers, and any control issues that will delay your SOC progress.
- Provide an overview of AICPA SOC examinations and requirements
- Determine the control objectives or trust service categories that should be in scope for your SOC report based on the service(s) you provide
- Boundary review and validation
- Quick-hit process to identify roadblocks that could prevent a successful SOC Type 2 report
- Initial review of the implementation status for each control in place to meet criteria
- Overall cost-effective way to obtain a SOC roadmap
SOC is a detail oriented and nuanced process towards preparing your environment for assessment that your team will undergo. For the security category of SOC 2, your organization will need to demonstrate how it meets “common criteria”. The common criteria and some examples of what would be included are:
- Control Environment
- Communication and information
- Risk assessment
- Monitoring activities
- Control Activities
- Logical and physical access controls
- System operations
- Change management
- Risk mitigation
Under the availability and confidentiality categories, you would also include criteria for:
- Processing capacity
- Backup and recovery
- Testing of recovery plans & procedures
- Data retention
- Data destruction