SOC 2
SOC 2 is a framework for the information security of service providers, especially those storing customer data in the cloud. In 2017, the audit body American Institute of Certified Public Accountants (AICPA) defined SOC as System and Organization Controls, previously known as Service Organization Controls. SOC 1 focuses on the accuracy of financial reporting, Internal Control over Financial Reporting (ICFR). SOC 1 corresponds to International Standard on Assurance Engagements 3402 (ISAE 3402), published by the International Federation of Accountants (IFAC) and developed by the International Auditing and Assurance Standards Board (IAASB). SOC 1 is a way of meeting the requirements of the US Sarbanes-Oxley Act (SOX) of 2002 on internal control and transparency in publicly listed companies. SOC 2 instead focuses on the reliability of digital services and information security for SaaS providers, cloud services, IT operations and data centres, and digital platforms that handle customer data. There are two different types of SOC reports.
- Type I assesses controls at a specific point in time.
- Type II assesses controls over a period of time, usually at least six months.
For a CISO, SOC 2 Type II is particularly relevant because it provides deeper insight into how well security controls perform over time, which is essential for continuously identifying and managing potential risks. With SOC 2 controls in place, a SaaS provider can demonstrate how it protects customer data. SOC 2 can also strengthen the security culture, offering an opportunity to be transparent and show that security is taken seriously. This builds trust with customers and stakeholders. The framework includes a wide range of information and IT security controls, such as multi-factor authentication, encryption and logging for a service provider, or redundancy and recovery plans for a data centre. The controls are organised into five Trust Service Criteria (TSC):
- Security Protection against unauthorised access to systems and resources. Access control Restrict access to systems and data to authorised users through solutions such as multi-factor authentication (MFA) and role-based access control (RBAC). Intrusion detection Identify and respond to security threats, for example with Security Information and Event Management (SIEM). Encryption At rest and in transit, to protect data. Patch management Identify and install security updates.
- Availability Uptime for operations and use in accordance with a service level agreement (SLA). Disaster Recovery Plan (DRP) Create and test a recovery plan to ensure operations in the event of a disaster. Monitoring Tools to detect operational disruptions in real time. Redundancy Alternative resources for critical infrastructure such as servers, networks and data storage.
- Processing integrity Process data completely, accurately and in a timely manner. Automated controls For example, input validation. Review and logging Ensure that data is processed without manipulation. Timestamps Ability to trace transactions.
- Confidentiality Protection of information intended to be restricted to a specific group. Classification Classify data (for example public, internal, sensitive) and restrict access according to the classification. Disposal Delete data that is no longer needed. Data Loss Prevention (DLP) Tools to prevent sensitive information from leaving the organisation.
- Privacy Protection of personal data in accordance with legal requirements and internal policies. Privacy policy Describe how customer data is collected, processed, stored and protected. Access controls Give customers the ability to manage their data. Incident management Manage and report personal data incidents.
A coding system shows which control belongs to which TSC. Security is the only category that is mandatory in every SOC 2 report.
| Trust Service Criteria (TSC) | Prefix | |
| Security | Common Criteria | CC |
| Availability | Availability | A |
| Processing integrity | Processing Integrity | PI |
| Confidentiality | Confidentiality | C |
| Privacy | Privacy | P |
Seclight offers and has experience with effective transitions toward sustainable information and IT security in line with SOC 2.
Alternatives to SOC 2
One alternative for meeting SOX and ICFR requirements is IT General Controls (ITGC), used by the AICPA, covering four areas: Access Management, Change Management, IT Operations, and IT Governance and Third-party Management, with audit reports under SOC 1, SOC 2 and ISAE 3402 for control ITGC.33. ITGC can be regarded as the IT component of the COSO Internal Control Framework from the Committee of Sponsoring Organizations of the Treadway Commission (COSO). A governance framework is Control Objectives for Information and Related Technologies (COBIT), developed by the US-based Information Systems Audit and Control Association (ISACA).
The frameworks overlap
| ITGC → ICFR | ITGC ensures that IT systems support financial reporting. |
| SOC1 / ISAE 3402 → ICFR | Audit reports on providers' controls. |
| SOC2 ↔ ISO 27001 | Similar security controls. |
| CIS Controls ↔ NIST CSF | CIS is more operational and technical. |
| NIS2 → ISO 27001 / NIST | Legal requirements often implemented using these frameworks. |
| The Cybersecurity Act → NIS2 | National implementation. |
| CER ↔ NIS2 | Complements cybersecurity with physical resilience. |
| SoGP → NIS2 / CER | SoGP can be used to structure governance and management responsibility for these regulations. |
| SoGP ↔ ISO 27001 | SoGP focuses on leadership and governance, while ISO 27001 focuses on operational security work. |
Different starting points give rise to different frameworks
| Governance | COBIT |
| Frameworks, processes | ISO 27001, NIST CSF |
| Operational controls | CIS Controls |
| Audit controls | ITGC |
| Audit reports, assurance | SOC1, SOC2, ISAE 3402 |
| Legal requirements, IT | NIS2, CER |
| Legal requirements, accounting / financial compliance | ICFR, Sarbanes-Oxley Act |