SOC 2 Type II is a third-party security audit conducted by certified CPA firms to verify that an organization's policies, procedures, and controls meet established information security standards. The resulting compliance report gives other businesses a reliable benchmark for evaluating a vendor's or partner's security posture.
SOC 2 Auditing Process
It's always nice to see an example of what this auditing process might look like. We're going to take a look at SOC. It's one of the ones that I'm more familiar with, and it's something that's very prevalent out there, so it's a good one to analyze and look at.
I've gone through quite a few different audits of many different types. Some examples are PCI DSS — if you're processing credit card companies, then you're going to need to do at least a self audit, and maybe a third-party audit with that.
I've also had customers come in and do audits of our systems, although that's not as common, and there is some sensitivity where you don't want to expose certain things to the customer. I'm pretty upfront with the stuff I'm not willing to expose to the customer, and tell them no, you're not able to look into certain systems.
There are also financial audits, where every year or two a company will get audited to make sure that they're following proper financial processes.
The one that we'll get most into today is a SOC 2 Type 2, which is auditing your security and your information systems to make sure that you're remaining secure, that you're carrying out the proper security with your systems.
A SOC 2 is done by a third-party auditor, somebody external to the company. In fact, it can't be just anybody — you have to be a CPA firm. CPA firms do SOC 1 audits, which is over financial systems, and then they'll have somebody within their company that can perform SOC 2. So not just anybody can perform these SOC 2 audits; only specific people can perform them.
With a SOC 2 audit there are two types, type one and type two. We'll mainly talk about type two, which is really just type one but then it goes an extra level.
What they'll do is come in and, number one, take a look at your policies and make sure that your policies align to what is appropriate for the business. They're going to come in and analyze yours — in fact, this is what a type one is: they just look at your policies and make sure that, based off of what industry you're in and the size of the company, it is appropriate for whatever business that you're doing. That's the first step right there, and they're going to make sure that that's done.
Then they're going to take a look at your procedures and make sure that it lines up, and that you're actually doing these. They're going to then ask for proof that you are in fact doing everything that you're doing, so they'll ask for attestations of everything, proof that you're doing everything. Then they can say, well, yes, you have the appropriate objectives, the appropriate policies, you have the appropriate procedures within your company, and you have shown proof of it.
All of this is going to go into a report — a report that says these are the objectives that this company has set out, and whether you are currently meeting those objectives or not, whether you're meeting those policies or not. They're going to make an overall assessment, and now you have a report that shows whether you are SOC 2 Type 2 compliant or not, which is something that other businesses are familiar with and know about, and they can evaluate your company based off of this report and your level of compliance.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →