Establishing a SOC 2 Security Program

Organizations should establish a SOC 2 security program that addresses Trust Services Criteria. Teams should develop administrative policies, implement cloud security controls, and gather all security evidence and documentation to prepare for an audit.

Engaging with a Third-Party Audit Firm

Organizations must engage with a third-party audit firm to perform a SOC 2 audit. Teams should consider selecting a reputable firm that has worked with similar clients and security expertise.

Maintaining SOC 2 Internal Controls

After receiving a SOC 2 report, organizations must continue to maintain SOC 2 internal controls across their AWS cloud environment. Teams must complete a SOC 2 audit every year in order to stay current with their SOC 2 report.

Trust Services Criteria Principles

Security Principle

The Security principle refers to how system resources are protected against unauthorized access. This principle includes implementing necessary access control, network firewall, intrusion detection systems (IDS).

Confidentiality Principle

The Confidentiality principle refers to the access and disclosure of data to authorized parties. This includes implementing standards around access control, user roles, network firewalls, and transmission encryption.

Availability Principle

The Availability principle refers to the accessibility and availability of systems and core services within the organization, as well as contract and service level agreement (SLA) standards. This principle includes standards around building highly available systems, addressing service failover, resource monitoring, and contingency plans.

Privacy Principle

The Privacy principle refers to system collection, use, and retention of personal information in relation to the organization’s privacy policies. Security controls must be implemented to protect Personally Identifiable Information (PII).

Processing Integrity Principle

The Processing Integrity principle refers to the ability of systems to deliver accurate data. Data processing must be accurate, timely, and authenticated. For organizations, this includes managing data integrity and setting quality assurance processes for managing data.

Using Dash in AWS Cloud

Dash is deployed into your AWS Cloud account and allows teams to manage cloud services. Dash can be used alongside the hundreds of AWS cloud services to rapidly build, manage, and get to market.