soc2-readiness

v2026.09.25

Prepare an organization for a SOC 2 Type I or II audit — trust services criteria mapping, evidence collection, control implementation, and remediation planning. Use when starting a SOC 2 journey or preparing for an audit window.

GitHub
安装命令
npx skhub add securityskills/soc2-readiness
Markdown
SKILL.md

SOC 2 Readiness

Drive an organization from "no controls documented" to audit-ready.

1. Scoping

  • Determine report type: Type I (point-in-time) vs Type II (period of time — start the observation window early)
  • Define the system description: services in scope, infrastructure, boundaries (subprocessors, cloud providers)
  • Select Trust Services Criteria: Security (required) + Availability, Confidentiality, Processing Integrity, Privacy as applicable

2. Gap Assessment

Map current practices to the criteria:

AreaTypical CriteriaCommon Gaps
Access controlCC6.1–CC6.3No MFA, no role-based access, shared accounts
Change managementCC8.1No peer review on deploys, no environment separation
Risk assessmentCC3.1–CC3.4No annual risk assessment or vendor reviews
MonitoringCC7.1–CC7.3No log review, no alerting on anomalies
Incident responseCC7.4–CC7.5No IR plan or tabletop evidence
BC/DRA1.2–A1.3Untested backups, no documented RTO/RPO
Vendor managementCC9.2No subprocessor due diligence
Onboarding/offboardingCC6.1Access removal not timely or evidenced

3. Remediation

  • Prioritize by audit-blocker status first, then risk
  • Implement policy + practice + evidence together: a policy without execution evidence fails
  • Typical timeline: 2–4 months for a Type I; Type II needs 2–12 months of operating evidence

4. Evidence Package

Per control: policy documents, implementation artifacts (screenshots, configs), and dated operating evidence over the review period (access reviews, change tickets, training logs, IR exercises)

5. Audit Logistics

  • Choose auditor; confirm scope wording matches your system description
  • Readiness assessment (optional but useful) → fieldwork → draft report review
  • Track findings/exceptions honestly; management responses documented

Output

Gap register with owners and dates, control matrix mapped to criteria, evidence repository structure, and auditor-ready system description.

发现
标签

此技能尚未发布标签。

版本
最新版本元数据

版本

v2026.09.25

发布时间

2026年9月25日

分类

未分类

许可证

未指定

源路径

compliance/soc2/soc2-readiness

默认分支

main

最新提交

b2b6b52

Tree SHA

8db485b