SOC for Cybersecurity

Why SOC for Cybersecurity

Cybersecurity is among the top issues on the minds of boards of directors, managers, investors, customers, and other stakeholders of organizations of all sizes — whether public or private. Managing cybersecurity concerns is especially challenging because even an organization with a highly mature risk management program is susceptible to breaches that may not be detected in a timely manner.

SOC for Cybersecurity is a market-driven, flexible, and voluntary reporting framework that helps organizations communicate about their cybersecurity risk management programs and the effectiveness of program controls, and for CPAs to examine and report on such information. It uses a common underlying language for cybersecurity risk management reporting — much like US GAAP or IFRS for financial reporting — enabling organizations in all industries to communicate relevant information about their cybersecurity risk management programs. This common language brings comparability to disclosures and complements other commonly used security frameworks such as NIST and ISO 27001. A CPA examination report enhances the trust and confidence users can place in that information.

What Is a SOC for Cybersecurity Examination?

SOC for Cybersecurity is an examination engagement performed by CPAs on an entity's cybersecurity risk management program. The examination covers two distinct but complementary subject matters: (a) the description of the entity's cybersecurity risk management program, and (b) the effectiveness of controls within that program to achieve the entity's cybersecurity objectives. The resulting examination report is for general use and includes three key components:

  • Management's description of the entity's cybersecurity risk management program — a management-prepared narrative describing how the entity identifies its information assets, manages the cybersecurity risks that threaten it, and the key security policies and processes implemented to protect its information assets. It provides the context users need to understand the conclusions expressed by management and the practitioner.
  • Management's assertion — provided as of a point in time or for a specified period, addressing whether the description is presented in accordance with the description criteria and whether the controls within the program were effective to achieve the entity's cybersecurity objectives based on the AICPA control criteria.
  • Practitioner's report — containing an opinion addressing both subject matters: whether the description is presented in accordance with the description criteria, and whether the program's controls were effective to achieve the entity's cybersecurity objectives.

Potential Users & Benefits

  • Senior management: Gains information about the effectiveness of the organization's cybersecurity risk management program, including the controls designed, implemented, and operated to mitigate threats against sensitive information and systems.
  • Boards of directors: Receive information about the cybersecurity risks the entity faces and the program management has implemented, supporting oversight responsibilities and the evaluation of management's effectiveness in managing cybersecurity risk.
  • Analysts and investors: Understand the cybersecurity risks that could threaten the achievement of the entity's operational, reporting, and compliance objectives — and consequently impact the entity's value and stock price.
  • Business partners: Use the report as part of their overall risk assessment — for example, to decide whether multiple suppliers are needed, how much credit to extend, or to understand specific logical access protections over interconnected IT systems.

Ascend performs SOC for Cybersecurity examinations that give your stakeholders independent, CPA-backed assurance over your cybersecurity risk management program. Contact us to learn more.