Navigate SOC 2 Compliance in the Cloud
34mIntermediate2024-08-22
Authors

AJ Yawn
Cybersecurity Expert, Founder and CEO at ByteChek

Jerich Beason
Chief Information Security Officer, Podcast Host, Speaker
Course details
This strategic course designed specifically for security professionals working with and for cloud-hosted companies takes a deep dive into SOC 2 compliance, a crucial standard for security and trust in cloud services. This course with instructors Jerich Beason and AJ Yawn is structured into chapters that focus on different aspects of SOC 2 compliance. Learn about SOC 2 concepts from both auditor and CISO perspectives, understand the unique impact of SOC 2 in cloud environments, hear key strategies for effective compliance, and more.
Learning objectives
Grasp the fundamental concepts of SOC 2 compliance, especially as they apply to cloud-hosted environments.
Develop strategies for effective SOC 2 compliance and communicate these requirements efficiently within their organization.
Recognize specific risks associated with cloud environments and learn how to mitigate them in line with SOC 2 standards.
Apply the learned concepts to enhance the security and trustworthiness of their cloud systems and services.
Learning objectives
Grasp the fundamental concepts of SOC 2 compliance, especially as they apply to cloud-hosted environments.
Develop strategies for effective SOC 2 compliance and communicate these requirements efficiently within their organization.
Recognize specific risks associated with cloud environments and learn how to mitigate them in line with SOC 2 standards.
Apply the learned concepts to enhance the security and trustworthiness of their cloud systems and services.
Skills covered
Governance, Risk, and ComplianceCybersecurityOne-Off
Concepts
Introduction
- SOC 2 - Insights from an auditor and a CISO
- Why SOC 2 matters - Unpack its impact on your business
Unraveling Logical Access in the Cloud for SOC 2
- IAM - Balancing access and security in SOC2
- Securing the cloud network - Checkpoints vs. strategy
- The art of data encryption - Data protection
- Bridge audit requirements and technical reality
Navigating Change Management in the Cloud
- Change management - Auditor queries and CISO responses
- Adapting SDLC for the cloud - A compliance perspective
- Proving change management to auditors - Inside tips
- Change management - Expectations vs. execution
Addressing Vulnerability and Incident Response
- Auditor's viewpoint vs. CISO's challenges
- Pen testing - From audit compliance to real-world scenarios
Ensuring High Availability in Cloud Environments
- Fundamentals of cloud availability
- Fundamentals of cloud availability
- Leveraging Multi-AZ for optimal availability
Conclusion
- Cloud SOC 2 resources