Don't fail your SOC 2 because of a just-do-it attitude
- Product
-
The Platform
Design a security program that builds trust, scales with your business, mitigates risk, and empowers your team to work efficiently.
-
-
- Solutions
- Pricing
- Company
- Resources
-
WHITE PAPER
The future of compliance AI is already here
-
SEARCH
Find answers to all your questions about security, compliance, and certification.
- Sign In
- Schedule a demo
Ready to see Strike Graph in action?
Find out why Strike Graph is the right choice for your organization. What can you expect?
- Brief conversation to discuss your compliance goals and how your team currently tracks security operations
- Live demo of our platform, tailored to the way you work
- All your questions answered to make sure you have all the information you need
- No commitment whatsoever
We look forward to helping you with your compliance needs!
Find out why Strike Graph is the right choice for your organization. What can you expect?
- Brief conversation to discuss your compliance goals and how your team currently tracks security operations
- Live demo of our platform, tailored to the way you work
- All your questions answered to make sure you have all the information you need
- No commitment whatsoever
We look forward to helping you with your compliance needs!
- Home >
- Resources >
- Don't fail your SOC 2 because of a just-do-it attitude
Don't fail your SOC 2 because of a just-do-it attitude
written by Kenneth Webb
, CISSP, GWAPT, CSSLP, CISA, CIS LA Strike Graph
We’ve all heard, “Just Do It”. Since 1988 it’s been a mantra for a certain shoe company and five years ago became a meme for motivation, thanks Shia LaBeouf! We all desire to take quick and decisive action if possible in order to achieve an outcome. Personally, the “Just Do It” slogan has always been a great motivator.
However over the years I’ve learned that the *real* hard work is in the planning. Having a game plan that focuses on only what is necessary is critical so you are not wasting precious time. Identifying the correct activities that are not going to help you achieve your goal is always faster. For a company with a goal of achieving a SOC 2 certification, before “Just Doing It” first plan and prepare to ensure success.
The two phases of the SOC 2 certification process
The SOC 2 certification process has two distinct phases: planning for the audit then preparing for the audit. We have interviewed many companies that jumped into passing the audit and without properly planning. This tends to make the process quite painful! Companies will create a lot of policies and procedures preparing for their audit. It's easy to find a list of "typical policies" and make them your own. However the result is creating cybersecurity requirements that the SOC 2 auditor will test. Fail those imaginary requirements and you fail your audit! What a waste of effort and time.
Right-size your scope
At Strike Graph right-sizing the scope of certification is the first thing we do. Customers use a risk-driven assessment to narrow the scope of a compliance practice. This can dramatically reduce the requirements of your cyber security practice. It will also focus time and energy on the things that contribute to passing your audit. If you’re a SaaS company, make sure you’re only identifying specific risks to your service and then you can determine the appropriate controls to put in place. Without this approach, we’ve seen companies try to “boil the ocean” during an audit and greatly expand the time, effort and cost of the certification. Make sure you have a clear scope with your risks assessed and controls identified before collecting the evidence needed.
With the right scope preparation moves right into evidence collection to support the SOC 2 auditor. Now you can surgically go after the artifacts — screenshots, config files, policies - that will help you demonstrate your security posture and validate the controls you have put in place. This preparation saves you a tremendous amount of back-and-forth with the auditor during the actual audit and sets you up a much lower "total cost of ownership". Most importantly it can dramatically reduce the likelihood that you'll fail your audit.
The takeaway
It should be no surprise that hard work upfront in scoping pays dividends in helping make the audit a success. Take the time to use a risk-driven approach to your SOC 2 certification process and you will see the benefits. While “Just Do It” is a great mantra and motivator, just make sure you are scoping the work in preparation prior to jumping into the auditors office.
Get a product demo to talk with our experts and see Strike Graph in action
Related Stories
Keep up to date with Strike Graph.
The security landscape is ever changing. Sign up for our newsletter to make sure you stay abreast of the latest regulations and requirements.
Ready to see Strike Graph in action?
Fill out a simple form and our team will be in touch.
Experience a live customized demo, get answers to your specific questions , and find out why Strike Graph is the right choice for your organization.
What to expect:
- Lorem Ipsum is simply dummy text of the printing and typesetting industry.
- Lorem Ipsum is simply dummy text of the printing.
- It is a long established fact that a reader will be distracted by the readable content of a page when looking at its layout.
- The standard chunk of Lorem Ipsum used since the 1500s
We look forward to helping you with your compliance needs!
Fill out a simple form and our team will be in touch.
Experience a live customized demo, get answers to your specific questions , and find out why Strike Graph is the right choice for your organization.
What to expect:
- Lorem Ipsum is simply dummy text of the printing and typesetting industry.
- Lorem Ipsum is simply dummy text of the printing.
- It is a long established fact that a reader will be distracted by the readable content of a page when looking at its layout.
- The standard chunk of Lorem Ipsum used since the 1500s
We look forward to helping you with your compliance needs!