Compliance Automation Toolby Agent Trust Cloud

SOC 2 compliance automation

SOC 2 is an examination of a service organisation's controls relevant to security, availability, processing integrity, confidentiality or privacy, reported by an independent CPA against the AICPA's Trust Services Criteria (AICPA & CIMA). A Type 1 report addresses the design of controls at a point in time; a Type 2 report also covers how they operated over a period, which is where automated, dated evidence pays off.

SOC 2 controls in our map

21 controls carry a SOC 2 reference; 19 of them can be evidenced from systems you probably already run. The references are to the criteria (CC1 to CC9, the common criteria, and A1 for availability); control wording is our own.

ControlSOC 2 criteriaEvidence fromISO 27001HIPAA
SEC-POL Security policies approved and acknowledgedCC5.3HR systemA.5.1§164.316(a), §164.316(b)(1)
ROLES Security and AI roles assignedCC1.3HR systemA.5.2§164.308(a)(2)
RISK Risk assessment and treatmentCC3.1, CC3.2Ticketing and change tracking6.1.2, 6.1.3, 8.2§164.308(a)(1)(ii)(A), §164.308(a)(1)(ii)(B)
ASSETS Asset inventoryCC6.1Cloud platform, Device management and endpoint protectionA.5.9§164.310(d)(1)
ACCESS Least-privilege access, approved before it is grantedCC6.2, CC6.3Identity provider or SSO, Ticketing and change trackingA.5.15, A.5.18, A.8.2§164.308(a)(4), §164.312(a)(1)
MFA Unique accounts and multi-factor authenticationCC6.1Identity provider or SSOA.5.17, A.8.5§164.312(a)(2)(i), §164.312(d)
OFFBOARD Access removed when people leaveCC6.2HR system, Identity provider or SSOA.5.11, A.5.18§164.308(a)(3)(ii)(C)
ACCESS-REVIEW Periodic access reviewsCC6.3Identity provider or SSOA.5.18§164.308(a)(4)(ii)(C)
ENCRYPT Encryption at rest and in transitCC6.1, CC6.7Cloud platform, Device management and endpoint protectionA.8.24§164.312(a)(2)(iv), §164.312(e)(1)
ENDPOINT Endpoint protectionCC6.8Device management and endpoint protectionA.8.1, A.8.7§164.308(a)(5)(ii)(B)
VULN Vulnerability managementCC7.1Vulnerability scanner, Cloud platform, Code repository and CI/CDA.8.8§164.308(a)(1)(ii)(B)
LOGGING Logging and monitoringCC7.2Central logging or SIEM, Cloud platformA.8.15, A.8.16§164.312(b), §164.308(a)(1)(ii)(D)
INCIDENT Incident responseCC7.3, CC7.4Ticketing and change trackingA.5.24, A.5.25, A.5.26§164.308(a)(6)
CHANGE Change managementCC8.1Code repository and CI/CD, Ticketing and change trackingA.8.32–
SDLC Secure developmentCC8.1Code repository and CI/CDA.8.25, A.8.28, A.8.31–
BACKUP Backups and restore testsA1.2, A1.3Backup service, Cloud platformA.8.13§164.308(a)(7)(ii)(A)
BCDR Business continuity and disaster recoveryA1.3, CC9.1ManualA.5.29, A.5.30§164.308(a)(7)(ii)(B), §164.308(a)(7)(ii)(D)
VENDOR Vendor and AI supplier riskCC9.2Vendor inventoryA.5.19, A.5.20, A.5.22§164.308(b)(1)
TRAINING Security and AI awareness trainingCC2.2Security awareness training platform, HR systemA.6.3§164.308(a)(5)(i)
SCREENING Screening and confidentiality agreementsCC1.4HR systemA.6.1, A.6.2, A.6.6§164.308(a)(3)(ii)(B)
AUDIT Internal audit and management reviewCC4.1Manual9.2, 9.3§164.308(a)(8)

Where automation helps most in a Type 2 period

What stays manual for SOC 2

Risk assessment decisions, vendor reviews, continuity tests and internal evaluation produce evidence through people. Schedule them early: a missed quarterly review can't be recreated after the period ends.

Planning more than SOC 2? See compliance control mapping and what a platform automates.

Map your SOC 2 controls and evidence

Sources

Questions

What is SOC 2?

An examination by an independent CPA of a service organisation's controls relevant to security, availability, processing integrity, confidentiality or privacy, reported against the AICPA's Trust Services Criteria.

Which SOC 2 criteria are easiest to automate?

Logical access (CC6), system operations and monitoring (CC7) and change management (CC8), because the evidence lives in identity, cloud, logging and code systems.

Does SOC 2 evidence help with ISO 27001?

Yes. Most controls that answer SOC 2 also answer ISO/IEC 27001 Annex A; the table on this page shows the reference for each.