SOC 2 Compliance Essential Training (2022)
49mBeginner2022-08-03
Authors

AJ Yawn
Cybersecurity Expert, Founder and CEO at ByteChek
Course details
Imagine you're running a successful, fast-growing software company. Your dream customer comes along with the contract that will set your company up for long-term success. But there's something holding up the deal: They want to ensure your application is secure and they want a third party to validate that. This is where SOC 2 comes in. SOC 2 is a compliance framework that helps companies build trust with customers, investors, and prospects, and unlock growth in new markets and verticals through third-party audits. In this course, instructor AJ Yawn helps individuals in any role understand the core concepts of the SOC 2 framework and how companies use this compliance report to build trust with their customers. AJ details the sometimes-confusing and overwhelming documentation, covers what to look for in each section of the report, and how to read SOC 2 reports. He also explains how auditors perform assessments during a SOC 2 examination and what to expect when being audited.
Skills covered
Governance, Risk, and ComplianceCybersecurityLearning
Concepts
Introduction
- SOC 2 compliance
SOC 2 Overview
- Key SOC 2 terms to know
- Why do companies pursue SOC 2
- How are SOC 2 reports distributed
SOC 2 Report Types
- SOC 3 101 and use cases
- SOC 2+ reports and use cases
- The basics of SOC 2 Type 1
- Understanding SOC 2 Type 2
Sections of a SOC 2 Report
- Section one - Independent service auditor's report
- Section two - Management's assertion
- Section three - System description
- Section four - Trust Services Criteria and related controls
- Section five - Information not covered in auditor's report
Trust Services Categories (TSCs)
- SOC 2 - Trust Services Categories scoping
- The security TSC
- The availability TSC
- The confidentiality TSC
- The processing integrity TSC
- The privacy TSC
Conclusion
- Next steps