SOC Audit | Quick Guide: SOC Compliance & Certification

Page 1

Most Important Things You Need to Know about

SOC COMPLIANCE & CERTIFICATION IARM, Top Cybersecurity Company in India. Trustworthy Partner Forever


What is SSAE 18? SSAE 18 Stands for Statement for Standard for Attestation Engagements created by the Auditing Standards Board of American Institute of Certified Public Account for redefining and updating how service companies report on compliance controls.


In order to check the level of assurance and adequacy of controls that the companies have implemented it is recommended to undergo the Service Organisation Control Audit by qualified and competent Information and Cyber Security organisation and the report attested by qualified and good standing CPA (Chartered Public Account).

Most companies often are on cross-roads on how to choose the right SOC type of Audit for their organisation. Organisation can choose either SOC 1 or SOC 2 types of audit based on the requirements and controls that they have implemented. The control objectives related to both business process and information security which may impact the client’s financial reporting, shall choose SOC 1. Under the SOC 1, the organisation can just opt for Type 1 which is just the Description of Controls of what they have implemented. If they choose SOC 1 and Type II, the organisation should demonstrate the description of controls and also provide the results of testing as part of evidence exercise.

Similarly if the organisation would like to opt for SOC 2 Audit, which is much more than the SOC1 but also addresses the Trust Principle (i.e) Availability, Security, Process Integrity, Confidentiality and Privacy. Like SOC 1, SOC 2 also has Type I and Type II which states the Description of Controls and also Description of Controls and Testing with results.


How to Choose the Right Service Provider? The real challenge in choosing the right service provider to help you with the attestation of the Audit report be it SOC 1 or SOC2.


The following are the suggestions that organisation intend to go in for SSAE18 Attestation Process. Even though this is attested by the CPA (Financial Auditors), it is equally important that the CPA is backed up by a capable Information/Cyber Security Organisation. SOC reports are in-depth and require multiple validation and verification both technically and Process wise as well.Â

Most attestation fail to qualify due to lack of technical controls assessed or improper validation of technical controls implemented. It is important that the technical of various flavours are involved in the assessment such as Physical Security, Operating System Security, Application Security, Database Security, Network Security and operation Security. The technical validation list is endless but is determined by the level of controls that is required for the identified organisation.

Attestation of the report is for the historical information irrespective of the type of SOC chosen. So it is important that the organisation understand that scope and the criteria of the report that is required to be attested.


SOC attestation helps organisations limit the number of security queries being bombarded by their Clients and Customers on periodic basis. Once when the SOC reports are attested, they can share the report with their client and customer who almost ask the same set of questions on their security compliance.

Organisations are required to perform the SOC audit every 12 months, else the attestation of the period 12 months can not be held valid for the next subsequent 12 month. It is purely time bound.

Organisation may have ISO 27001: 2013 certification in place, but SOC audit and attestation gives an edge over and complement the ISO 27001:2013 Certificate.

Organisation would have to look at the extensive validation of both the technical and process involved with Security Operation Control Framework provided by the audit team and the credibility of the attestation individual.Â

More than the Brand of which the audit firm performs the audit or attestation of the report, it is rather prudent to look for the audit firm which performs a complete technical and process validation.


How would IARM Information Security help with the SOC Reports?


IARM Cyber & Information Security Services will do SOC certification, for all service industries. Now a days Enterprises are struggling with regulatory compliance issues largely because of audit costs, financial obligations, and recognizing the complexities of the laws and regulations themselves.

We are here to help. Our audit team has performed SOC testing for a number of industries, including property management companies, application service providers, financial institutions and payroll service bureaus.

IARM Information Security has empanelled the credible & reputed CPA’s to attest the report for SOC Compliance. To learn more, Check out our available SOC Services


Contact Us

Toll free - 18001021532 (India)

info@iarminfo.com

https://www.iarminfo.com/


Turn static files into dynamic content formats.

Create a flipbook
Issuu converts static files into: digital portfolios, online yearbooks, online catalogs, digital photo albums and more. Sign up and create your flipbook.