SOC 2

SOC 2 Requirements

SOC 2 is an auditing procedure for ensuring service providers have proper data and privacy protections in place for sensitive data. Organizations working to achieve SOC 2 certification must implement a series of controls and go through an audit with an external auditor.

Auditors assess organization compliance with one or more of the AICPA Trust Services Criteria (TSC). Teams must have all applicable controls in place and be able to provide evidence of control effectiveness in order to achieve SOC 2 certification and receive a SOC 2 report.

SOC 2 Trust Services Criteria (TSC)

To meet the latest SOC 2 report framework standards, organizations must implement the 2018 Trust Services Criteria (TSC) with the revised points of focus introduced in 2022. The Trust Services Criteria (previously Trust Services Principles) are a set of criteria and related controls implemented across your organization and IT infrastructure. The five categories of control criteria are:

Security

A business's data and computing systems are fully protected against unauthorized access, unauthorized and inappropriate disclosure of information, and any possible damage to systems. Security criteria cover the protection of information during its collection or creation, use, processing, transmission, and storage — and the systems that process and store it. Security controls prevent or detect the breakdown and circumvention of segregation of duties, system failure, incorrect processing, theft, misuse of software, and improper access to or alteration, destruction, or disclosure of information.

Availability

All information and computing systems are ready and available for operation and use to meet the entity's objectives. Availability refers to the accessibility of information used by your organization's systems, as well as the products or services provided to its customers. It addresses whether systems include controls to support accessibility for operation, monitoring, and maintenance — not system functionality or usability.

Processing Integrity

All system processing is complete, accurate, valid, timely, and authorized. Processing integrity covers controls and procedures for verifying the completeness, validity, accuracy, timeliness, and authorization of system processing, and for determining whether systems perform their intended functions free from error, delay, omission, and unauthorized or inadvertent manipulation.

Confidentiality

Any information designated as confidential remains secure. Confidentiality covers your organization's ability to protect designated information from its collection or creation through its final disposition and removal. Confidentiality differs from privacy in that privacy applies only to personal information, whereas confidentiality applies to various types of sensitive information — whether required by laws, regulations, contracts, or commitments made to customers.

Privacy

All personal information collected, used, retained, stored, disclosed, or disposed of must meet the entity's objectives. Privacy criteria examine your organization's controls and procedures around:

  • Notification and communication of objectives: Notifying data subjects about privacy-related objectives.
  • Choice and consent: Communicating the choices available regarding collection, use, retention, disclosure, and disposal of personal information.
  • Collection: Collecting personal information consistent with privacy objectives.
  • Use, retention, and disposal: Limiting the use, retention, and disposal of personal information.
  • Access: Providing data subjects access to their personal information for review and correction.
  • Disclosure and notification: Disclosing personal information only with consent, and notifying affected data subjects and regulators of breaches and incidents.
  • Quality: Maintaining accurate, up-to-date, complete, and relevant personal information.
  • Monitoring and enforcement: Monitoring compliance and addressing privacy-related inquiries, complaints, and disputes.

Ascend performs SOC 2 Type 1 and Type 2 examinations against the applicable Trust Services Criteria for your organization. Contact us to scope your engagement.