Understanding SOC Compliance Before Committing: What You Need to Know
“Trust but verify” is a quote often associated with the 40th President of the United States, Ronald Reagan. If he coined the term himself or was fond of using it, it is up for debate, but the simple message that the quote portrays still cuts to the core of understanding how we ought to treat one another in business dealings and beyond. Even among those you otherwise put a lot of trust in with essential matters, a certain skepticism level is healthy. Companies seeking a provider of technological services should certainly apply this principle to the work that they do. That is why SOC Compliance exists in the technology services space, and it is critical to understand its meaning in your particular set of circumstances.
What Is SOC Compliance?
SOC stands for System and Organization Controls. AICPA describes SOC as a suite of assurance services that CPAs may provide. SOC 2 reports concern controls relevant to security, availability, processing integrity, confidentiality, or privacy. SOC 2 is a report category, not a higher compliance level that replaces every other SOC report.
Before relying on a provider’s report, review the system and period covered, the auditor’s opinion, and the controls relevant to your use of the service. A report does not guarantee that a security incident cannot occur.
What Factors Do SOC Compliance Standards Take Into Account?
The following are practical topics to discuss with a provider. They are examples for due diligence, not a complete statement of the applicable SOC criteria.
- The ability to monitor known and unknown threats to technological systems
- Audit trails
- Top-level confidentiality agreements with clients
- Integrity in getting the proper data to the appropriate place in the proper time
- A level of forensic detail that can be acted upon
Use the report scope and applicable criteria to decide which controls need closer review.
Monitoring Threats
New threats are dreamed up in the minds of cyber-criminals every day. There is a gold mine of information and data that those criminals would love to have access to, and they are more than happy to invent the viruses and other malicious tools they need to get to it. This is why any SOC 2 compliant vendor or company must have the ability to monitor any potential threats on a software system. Not only should they be able to monitor threats that are already known and previously detected, but they need to have the ability to keep tabs on emerging threats that have not yet shown their face.
Audit Trails
Details matter, and audit trails are the only way to keep all of those details and pieces of information together in one place. Just like a court of law requires a detailed record of everything said and done in the courtroom, so too should companies seeking to protect themselves and their data from attack.
Confidential Agreements With Clients
It is crucial that all matters between a service provider and the company purchasing those services be kept confidential. Sensitive data is passed between the two regularly as a matter of doing business. Thus, any SOC 2 compliant service provider must demonstrate that they have the utmost integrity and values regarding confidentiality.
Integrity Of Data
All data must seamlessly pass through the service provider and get to where it needs to go without hiccups or mistakes. Protecting that data at every stage of the process is the service provider’s work, and there is no reason for there to be any issues when it comes to this. Routine checks on the data’s ability to get from Point A to Point B without problem are recommended and are factors in achieving SOC 2 compliance.
Forensic Details
AICPA explains that SOC assurance reports help users assess risks associated with outsourced services. When evaluating a provider, ask how security events are investigated, how evidence is retained, and how corrective actions are documented. Review the actual report scope and findings.
Final Thoughts
Do not treat a SOC claim as a substitute for reviewing the actual assurance report. Match its scope to your service requirements, ask about exceptions, and clarify which responsibilities remain with your organization.
For the latest on SOC compliance and its role in the world of business, please contact us.
