A SOC 2 report focuses on outsourced services that could impact the security, availability, processing integrity, confidentiality, and privacy of their client's data.
This course will examine how SOC 2 reports address internal controls of service organizations and their internal controls around the security, availability, processing integrity, confidentiality, and privacy of their clients' data. Attendees will examine the criteria utilized for SOC 2 reporting and how it enables users to have an apple-to-apple comparison of their vendors or prospective vendors.
This webinar reviews the use cases and scenarios where SOC 2 reports are commonly seen across various industries. The instructor will also uncover common pitfalls encountered during the preparation phase of an audit, as well as issues that may arise during the audit itself. Join this course to review the implications of audit findings, recognize what it means if a finding is identified during the audit, and understand how that may impact the reader's interpretation of the report.
This presentation is part three of a three-part series.
Part 1: Introduction to SOC Reporting
Part 2: SOC 1 Reporting
Learning Objectives:
WithumSmith+Brown, PC
Senior Manager
[email protected]
(732) 828-1614
The AICPA selected Scott to write and present the first-ever Education Program for "Reporting on an Entities Cybersecurity Risk Management Program and Controls" to cybersecurity professionals obtaining SOC for Cybersecurity certification. This program is the first of its kind, and as the author and presenter, Scott is one of the first in the U.S. to become certified. With 20+ years of experience, Scott is a Senior Manager within Withum’s SOC Services practice. His expertise lies within internal control assessments, risk assessments, SOC reporting (SOC 1, SOC 2, SOC 3, and SOC for Cybersecurity), SOX 404, and internal audit co-sourcing.
WithumSmith+Brown, PC
Manager, System and Assurance Advisory Services
[email protected]
Andrea has over seven years of professional experience and is a manager within the System and Assurance Advisory Services practice. She specializes in internal control assessments and consulting services relating to Sarbanes-Oxley Act (SOX) and service organization control (SOC) reporting. Andrea is involved in the issuance of over 100 SOC reports, including a combination of SOC 1, SOC 2, and SOC 3 reports.