TechKnowSurge
CompTIA Security+ 5.5 ISC2 CISSP 6.5 ISC2 CISSP 6.1 CompTIA Security+ 5.4 ISC2 CISSP 6.3 ISC2 CISSP 6.4
VideoSecurityFree

Compliance Audits Example

SOC 2 Type II is a third-party security audit conducted by certified CPA firms to verify that an organization's policies, procedures, and controls meet established information security standards. The resulting compliance report gives other businesses a reliable benchmark for evaluating a vendor's or partner's security posture.

Complete this video to capture a CTF flag worth 1 point.

About this video

Security auditing takes several forms across industries, including PCI DSS assessments for organizations handling credit card data, customer-initiated reviews, and periodic financial audits. Among these, SOC 2 Type II stands out as the benchmark standard for evaluating an organization's information security controls, and it is one of the most widely referenced compliance frameworks in the industry. Understanding what the audit involves and who can perform it is essential for any organization operating in environments where trust and data protection are critical business requirements. Only CPA firms are authorized to conduct SOC 2 audits, and within those firms, specific qualified individuals handle the security-focused assessment. This distinguishes SOC 2 from less formal review processes and gives the resulting report significant credibility in the marketplace. SOC 2 Type I examines whether an organization's written policies are appropriate given its industry, size, and business activities. SOC 2 Type II goes further by also evaluating whether the documented procedures align with those policies and, critically, whether the organization can produce evidence demonstrating that controls are consistently followed over time. Auditors review attestations and supporting documentation, then compile their findings into a formal report that identifies the organization's stated security objectives and assesses the degree to which those objectives are being met. That report becomes a tangible, standardized record that prospective clients, partners, and other stakeholders can use to evaluate an organization's security posture with confidence.

What you'll learn

What's covered

SOC 2 Auditing Process

Aligned to

CompTIA Security+
5.5 Explain types and purposes of audits and assessments.
5.4 Summarize elements of effective security compliance.
ISC2 CISSP
6.5 Conduct or facilitate security audits.
6.1 Design and validate assessment, test, and audit strategies.
6.3 Collect security process data.
6.4 Analyze test output and generate report.

Key terms

SOC 2 Type 1
An attestation that evaluates whether an organization has the appropriate controls designed and in place at a specific point in time.
SOC 2 Type 2
An attestation that evaluates not only whether controls are in place but also whether an organization is consistently following through with those controls over a defined period.
Attestation
The process of providing evidence or formal certification that a set of standards is being followed, either through self-reported documentation or third-party verification.
Security Policy
A formal document that defines an organization's security goals, rules, and responsibilities.
Audit
A formal and systematic examination of an organization's systems, policies, and procedures to verify that security controls are in place, functioning as intended, and meeting applicable compliance requirements.
Compliance
The act of adhering to the laws, regulations, standards, and internal policies that govern how an organization handles data and security. Compliance programs use audits and controls to demonstrate that requirements are being met.

Topics

Soc 2 Compliance Audits Information Security Third Party Auditing Security Controls Cybersecurity

Transcript

It's always nice to see an example of what this auditing process might look like. We're going to take a look at SOC. It's one of the ones that I'm more familiar with, and it's something that's very prevalent out there, so it's a good one to analyze and look at.

Audits I have been through

I've gone through quite a few different audits of many different types. Some examples are PCI DSS — if you're processing credit card companies, then you're going to need to do at least a self audit, and maybe a third-party audit with that.

I've also had customers come in and do audits of our systems, although that's not as common, and there is some sensitivity where you don't want to expose certain things to the customer. I'm pretty upfront with the stuff I'm not willing to expose to the customer, and tell them no, you're not able to look into certain systems.

There are also financial audits, where every year or two a company will get audited to make sure that they're following proper financial processes.

SOC 2 Type 2

The one that we'll get most into today is a SOC 2 Type 2, which is auditing your security and your information systems to make sure that you're remaining secure, that you're carrying out the proper security with your systems.

A SOC 2 is done by a third-party auditor, somebody external to the company. In fact, it can't be just anybody — you have to be a CPA firm. CPA firms do SOC 1 audits, which is over financial systems, and then they'll have somebody within their company that can perform SOC 2. So not just anybody can perform these SOC 2 audits; only specific people can perform them.

With a SOC 2 audit there are two types, type one and type two. We'll mainly talk about type two, which is really just type one but then it goes an extra level.

What the auditor does

What they'll do is come in and, number one, take a look at your policies and make sure that your policies align to what is appropriate for the business. They're going to come in and analyze yours — in fact, this is what a type one is: they just look at your policies and make sure that, based off of what industry you're in and the size of the company, it is appropriate for whatever business that you're doing. That's the first step right there, and they're going to make sure that that's done.

Then they're going to take a look at your procedures and make sure that it lines up, and that you're actually doing these. They're going to then ask for proof that you are in fact doing everything that you're doing, so they'll ask for attestations of everything, proof that you're doing everything. Then they can say, well, yes, you have the appropriate objectives, the appropriate policies, you have the appropriate procedures within your company, and you have shown proof of it.

The report

All of this is going to go into a report — a report that says these are the objectives that this company has set out, and whether you are currently meeting those objectives or not, whether you're meeting those policies or not. They're going to make an overall assessment, and now you have a report that shows whether you are SOC 2 Type 2 compliant or not, which is something that other businesses are familiar with and know about, and they can evaluate your company based off of this report and your level of compliance.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →