
In this lecture we will provide an overview of what you can expect in this course.
Questions we will answer:
We will walk through how important marketplace trends like the explosion of data creation, cybercrime, and reliance on third party service providers has led to the rise in popularity of SOC 2.
In this video we will answer the questions:
Why does SOC 2 exist?
Why is it becoming so common for companies to ask each other for SOC 2 reports?
In this lecture we cover how the SOC 2 standard is governed, who is authorized to issue a SOC 2 report, and why you this matters to you. We will talk about the relationship between five key players:
The AICPA who governs the SOC 2 standard
CPA Firms that perform the SOC 2 audits
The AICPA CPA Peer Review Program
Your company that wants a SOC 2 audit
Your customers and stakeholders that want to read your SOC 2 report
Questions We Will Answer:
In this lecture we will cover the two key components that drive the scope of your SOC 2 report:
Which of the 5 Trust Services Criteria you select, and
The "System" (Products, Technology, Locations, Processes, etc.) you define as your scope.
In this lecture we will cover the 4-step process to obtain a SOC 2 report:
SOC 2 Gap Assessment
Correcting identified Issues
SOC 2 Type I Report
SOC 2 Type II Report
In this lecture we will cover:
What people are typically involved in a SOC 2 audit,
The typical efforts (by role) to expect during the audit, and
The drivers of audit fees for a SOC 2 audit.
One of the biggest factors that will impact your SOC 2 audit experience is the firm you select as your partner in the SOC 2 process. In this course, we will cover some lessons learned in choosing a great partner to help you through the SOC 2 journey:
SOC 2 Auditor vs. SOC 2 Consultant,
How to choose a great audit firm, and
Questions to ask and setting ground rules with your audit firm partner.
Going through an audit can be scary. This lecture will give you the insight you need to go into an audit with confidence that you know exactly what to expect from the auditor.
What to expect from the auditor
How the auditor performs an audit
How you should interact with the auditor
A couple of examples of how the auditor will review your Company
You will need to provide the SOC 2 auditor hundreds of pieces of evidence during a SOC 2 audit. After this lecture you will have an insider's perspective on what to expect during your SOC 2 audit.
In this lecture we are going to:
Review some of the types of evidence you can expect to provide the auditor,
Review the workflow to provide evidence between your team and the auditor, and
Demo a real world example of an audit information request list.
It's time for the real audit. Are you ready? In this lecture we will talk through how you can go into your SOC 2 audit with confidence:
How to prepare your team
Spot checking controls and evidence
Setting clear ground rules with your auditor
In this lecture we cover 10 of the most frequently asked questions about SOC 2 reports like:
What if I am in the cloud?
What if my whole company is remote?
What is the difference between SOC 2 and ISO 27001?
Does the auditor have to come on site?
What if my scope changes during the year?
What if I need to map to other frameworks like ISO 27001, PCI DSS, or HIPAA?
What if I need to be compliance with privacy frameworks like GDPR?
What if I outsource development or other key functions?
What are the most common mistakes?
Do you have policy templates?
In this lecture we will point you to free resources and templates you can use to get started on your SOC 2 journey.
All of the material referenced in this course
SOC 2 recurring events
SOC 2 Control Spot-Check checklist
Free Videos
Free Downloads and Templates
Check the downloadable materials in the description of this lecture!
Are you helping your organization get a SOC 2 report? Do you want to get up to speed fast? Well this is the perfect course to get started!
Course Outline:
Background and Context on SOC 2
All the important background information on SOC 2 so you have all the context you need.
The 4-Step Process to Get a Report
The simple 4-step process all organizations follow to achieve SOC 2 compliance.
Timeline, effort, and costs
We will cover a typical timeline to achieve SOC 2, how much effort it will take your internal team, who needs to be involved, and how much an audit costs.
What to expect during a SOC 2 audit
We will tell you exactly what to expect from an auditor during a SOC 2 audit. You will walk away with more confidence with how to prepare and what the audit will feel like.
Top 10 commonly asked questions
We will cover common questions like which policies you need, what to do if you are in the cloud, what to do if you outsource key functions, if you also do other frameworks like ISO 27001, and a lot more.
Free Resources and Templates
We will point you to some great resources to get started today.
These Are Lessons Learned from Doing 100s of SOC 2 Reports!
We have helped hundreds of organizations achieve SOC 2 compliance. So everything covered in this course is pulled from real world lessons learned as an auditor and as someone who has built many SOC 2 programs. We will provide an insiders perspective on exactly what you need to know to get a SOC 2 report and make your company successful.