System and Organizational Controls (SOC) 2
SOC 2 is a great first step to building your information security program, whether you want to build a sound information security program or have to meet SOC 2 Type 2. SOC 2 was created by the American Institute of Certified Public Accountants (AICPA), which is the national association that governs the certifications of Certified Public Accounts (CPA). The AICPA was already overseeing the financial audits of companies, and with the advent of information technology and its importance in safeguarding data, the AICPA created SOC 2. As a result, your auditor has to be a certified CPA who is registered with the AICPA to do SOC2 audits. SOC 2 covers five areas of the Trust Services Criteria:
- Security: The security controls safeguard information and systems from unauthorized access and the disclosure of sensitive data. Effective security controls are critical in ensuring an entity can achieve its objectives without compromise. Controls that...