Resources
Articles
Practical guides and industry updates to help your organization stay secure and compliant in a digital-first world.

Exploring the Five Trust Service Principles of SOC 2 Compliance
Exploring the Five Trust Service Principles of SOC 2 Compliance
How Using the 5 Trust Service Principles of SOC 2 Compliance Enhances Confidence in Your Industry
SOC 2 is an internationally recognized standard, and it provides a framework for service providers to demonstrate their commitment to the Five Trust Service Principles (TSP) of SOC 2:
- Security
- Availability
- Processing integrity
- Confidentiality
- Privacy
This blog post will explore the 5 TSP of SOC 2 compliance and how they apply to various industries.
READ MORE:
The 5 Trust Service Principles of SOC 2
1. Security

The security principle requires service providers to protect the system and its data against unauthorized access, use, disclosure, modification, and destruction. This principle also requires service providers to implement policies and procedures to identify, assess, and mitigate security risks. Service providers must have appropriate controls to safeguard the system, including access controls, encryption, firewalls, intrusion detection and prevention, and incident management.
2. Availability
The availability principle requires service providers to ensure the system is available for operation and use as agreed upon with their customers. Service providers must have appropriate controls to ensure the system is continuously available and minimize service disruptions; this includes redundant systems, backup and recovery procedures, and disaster recovery plans.
3. Processing Integrity
The processing integrity principle requires service providers to ensure that the system processes data accurately, entirely, and on time. Service providers must have appropriate controls to ensure data is processed accurately, including input validation, error handling, and reconciliation procedures. This principle also requires service providers to implement policies and procedures to prevent and detect unauthorized changes to data.
4. Confidentiality
The confidentiality principle requires service providers to protect the confidentiality of data throughout its lifecycle. Service providers must have appropriate controls to ensure that data is only accessible by authorized personnel and protects against unauthorized disclosure, including access controls, encryption, and policies and procedures to protect sensitive data.
5. Privacy
The privacy principle requires service providers to collect, use, retain, disclose, and dispose of personal information following their customers' privacy requirements. Service providers must have appropriate controls to protect confidential information against unauthorized access, use, disclosure, modification, destruction, data classification, consent management, and incident response.
System Components Covered by the 5 Trust Service Criteria in a SOC 2 Audit
During a SOC 2 audit, the 5 TSP criteria apply to different components of a system, including the following:

- Infrastructure: Physical structures, IT, and hardware, such as facilities, computers, equipment, mobile devices, and telecommunications networks.
- Software: Application programs and IT system software that supports application programs, such as operating systems, middleware, and utilities.
- People: The personnel involved in the governance, operation, and use of a system are also covered, including developers, operators, entity users, vendor personnel, and managers.
- Procedures: This covers both automated and manual processes involved in the system.
- Data: Transaction streams, files, databases, tables, and output used or processed by a system.
READ MORE: SOC 2 Compliance Requirements
Earn the Trust of Your Customers: Prioritize the 5 Trust Services Criteria (TSP) for SOC 2
Establishing trust with customers is a critical component of any successful business.
Let’s delve into the 5 Trust Service Principles of SOC 2 and explore how different industries prioritize these principles to earn the trust of their customers. By prioritizing the 5 TSP, companies can demonstrate their commitment to security and reliability, and earn the trust of their customers.
SaaS Organizations:
SaaS organizations are entrusted with sensitive financial, personal, and other confidential information.

That's why SOC 2 compliance is vital for SaaS organizations. By meeting SOC 2 compliance, they can demonstrate that they have adequate controls to protect their clients' data.
Regarding the Five TSP criteria, SaaS organizations would likely rely on the following:
Security:
Because SaaS providers store, transmit, and process sensitive data, the Security TSP is critical. SaaS organizations must implement access controls, encryption, and monitoring systems. This principle ensures that SaaS providers have the necessary controls to protect their clients' data from unauthorized access, theft, and misuse.
Availability:
The availability principle ensures clients can access their data when needed. SaaS providers must ensure that their systems are available and reliable and have appropriate backup and recovery mechanisms. Downtime or interruptions in service can lead to significant financial losses, reputational damage, and legal liabilities.
Privacy:
SaaS organizations that handle personal health information (PHI) must also consider the privacy principle. This principle governs PHI's collection, use, retention, disclosure, and disposal. SaaS providers must implement appropriate controls to ensure that only authorized personnel can access PHI and that it's used and disclosed only for authorized purposes.
“The Johanson Group provided individualized attention during the discovery phase answering all of my questions uniquely tied to FlowEQ. “
Financial Services Sector
Financial services and fintech companies should focus primarily on the following:

Confidentiality: To meet SOC 2 compliance for the confidentiality TSP, financial services companies must identify and classify sensitive information and implement proper protection controls— access to confidential data and ensure that it is encrypted and protected in storage and transit
Security: Security is a top priority when handling other people's money. Financial services and Fintech companies must implement measures to prevent unauthorized access to data and systems, including firewalls, intrusion detection, and anti-malware software.
There must also be a process to detect and respond to security incidents and conduct regular vulnerability assessments to identify and address potential security risks.
Availability: Availability ensures that systems and data are accessible when needed.
Processing integrity: This principle is critical to ensuring financial transactions are processed accurately and efficiently. Processing integrity ensures that data is accurate, complete, and timely.
— David Patrick, Neural Payments
“Thank you very much for your team's diligence and hard work during our audit! It was a pleasure working with you all and we hope to again in the future.”
Healthcare Organizations
To comply with the Health Insurance Portability and Accountability Act of 1996 (HIPAA), healthcare organizations must follow specific guidelines when handling patient information.

However, in addition to HIPAA compliance, healthcare organizations should also focus on the five TSP for SOC 2 compliance to ensure they properly manage and secure patient data.
The SOC 2 TSP that healthcare organizations should focus on the most are:
Privacy:
This principle requires organizations to establish and maintain policies and procedures to protect personal information, including healthcare data, from unauthorized access, use, or disclosure.
Security:
Healthcare organizations must implement technical and physical safeguards to prevent unauthorized access to patient data, such as encrypting data at rest and in transit, implementing firewalls, and restricting access to sensitive information.
Availability:
Serious consequences could ensue if patient data is unavailable when needed. These organizations must ensure that their systems and data are available to authorized users when needed and have contingency plans to mitigate the impact of system failures or natural disasters.
“Amazing! Thank you so much for the final report and the marketing materials.
This has been a seamless process - thank you all for your efforts and my team very much enjoyed working with you. I'm sure we'll be in touch for the Type II after the monitoring phase.”
The sectors mentioned above are just a handful that necessitates adherence to SOC 2 compliance according to the 5 TSP criteria.
Here's a compilation of other industries that must prioritize the Five TSP for SOC 2 compliance:
- Cloud service providers
- Customer or sales support
- Human resources departments
- IT security management
- Customer relationship management (CRM)
- Medical claims processing
- Data analysis companies
- Accounting and auditing firms
- Workflow management
- Document and records management
- Insurance claims processors
- Technology consulting
- Pharmaceutical
- Financial processors
- Legal Firms
FAQs: SOC 2 Compliance and Meeting the 5 TSP
As with any compliance framework, questions often arise when understanding and implementing the requirements. Below are some frequently asked questions we get about the Five Trust Service Principles of SOC 2:
- What is the difference between SOC 2 Type 1 and Type 2 reports?
- A SOC 2 Type 1 report provides an opinion on the design of a service provider's controls, while a SOC 2 Type 2 report provides a statement on the design and operating effectiveness of those controls over a specific period (usually six months to a year). Type 2 reports are more comprehensive and provide greater assurance to customers.
- What is the scope of a SOC 2 report?
- The scope of a SOC 2 report is determined by the service provider and its customers. It should include all relevant systems and processes within the service provider's control and relevant to the five Trust Service Principles.
- Are there any specific controls that must be in place to comply with SOC 2?
- No, SOC 2 is a principles-based framework, meaning that service providers are free to choose the most appropriate controls for their systems and processes. However, the AICPA guides the types of controls that may be relevant to each of the Trust Service Principles.
- Can a service provider maintain SOC 2 compliance with only some Trust Service Principles?
- Service providers can comply with one or more of the 5 Trust Service Principles for SOC 2 compliance, depending on their customers' requirements. However, it is important to note that the principles are interrelated, and compliance with one may impact compliance with others.
- What is the role of auditors in SOC 2 compliance?
- Auditors play a critical role in SOC 2 compliance. They are responsible for conducting the assessments and providing opinions on the design and operating effectiveness of a service provider's controls. Auditors must be independent and qualified to perform SOC 2 assessments.
- How often should a service provider undergo a SOC 2 assessment?
- It is common for assessments to renew, or more frequently if there are significant changes to the service provider's systems or processes.
- By understanding the answers to these frequently asked questions, service providers can better understand and implement the requirements of the five Trust Service Principles of SOC 2.
- Consulting qualified professionals to ensure compliance with SOC 2 and other frameworks is worth the investment and time.
Conclusion
In today's digital landscape, safeguarding sensitive data is crucial for businesses.
SOC 2 compliance is a non-negotiable requirement for service providers who handle confidential information such as health records, credit card numbers, or trade secrets.
By implementing SOC 2 controls under the guidance and criteria of the 5 Trust Principals, service providers can establish customer trust and showcase their unwavering commitment to data security.
Achieving SOC 2 compliance can be challenging, but it's crucial to work with experienced professionals who understand the requirements and can help guide you through the process.
Don't take risks with your customers' trust or your business's reputation — Partner with Johanson Group and let our experts help you achieve SOC 2 compliance, giving you and your customers peace of mind knowing that you take data security seriously.
Johanson Group provides risk advisory services, including SOC 2 audits, HIPAA compliance, and ISO 27001 certification, to help companies safeguard their most valuable asset: customer and employee data.

Choosing the Right Compliance Framework for Your Business: NIST vs ISO
Choosing the Right Compliance Framework for Your Business: NIST vs ISO
When it comes to data security and compliance, businesses need to follow guidelines and standards to ensure they are protecting their sensitive information and customer data. However, choosing the right compliance framework can be overwhelming, with many options available. NIST and ISO are two of the most popular and respected frameworks.
This blog will look closely at NIST vs ISO 27001 (the most recent addition to the ISO series) and help you determine which compliance framework best suits your business needs.
Whether you're a small business owner or an enterprise-level corporation, understanding the differences between these frameworks can help you decide to safeguard your organization against potential cyber threats and data breaches.
NIST Cybersecurity Framework: An Overview
The Cybersecurity Framework (CSF) was developed by the National Institute of Standards and Technology (NIST) in 2013.
It's been used for everything from nanotechnology to cybersecurity ever since, and it's a key resource for companies seeking to develop or improve their cybersecurity frameworks.
The NIST CSF is focused on 5 key areas:

- Identify
- Protect
- Detect
- Respond
- Recover
The NIST Cybersecurity Framework is organized in a hierarchical fashion that allows organizations to begin with the lowest level of protection possible and then move up as needs change over time.
In addition to providing a path for organizations to improve their security posture, the NIST Cybersecurity Framework also offers resources that can be used by individual employees to help them understand how they can take steps toward greater security on their own time.
Read more about the history of the NIST Cybersecurity Framework (CSF)
- Obama’s Cybersecurity Executive Order: What You Need to Know
- Trump’s Cybersecurity Executive Order: 4 Things You Need to Know
How NIST CSF Is Used
There are three major components to the system:

1) Framework Core:
This is the baseline of the NIST CSF and what everything else is built on. The five functions that make up this core mentioned previously ( Identify, Protect, Detect, Respond, and Recover) are used to identify and manage any risk management issues. The five core functions of cybersecurity contain 23 categories that provide the basic elements needed to establish a solid defensive strategy.
2) Implementation Tiers:
NIST CSF Tier levels provide benchmarks for organizations' cybersecurity efforts, with the highest tier (4) representing a strong adherence to the framework's rules and recommendations.
The four implementation tiers are:
- Tier 1: Partial
- Tier 2: Risk Informed
- Tier 3: Repeatable
- Tier 4: Adaptive
3) Profiles:
A profile at each tier allows you to gauge your current level of risk and see how improving your security measures can increase protection for everyone on the network.
When you have analyzed these three components, you can better understand the risk level of your system and identify any underlying problems. As such, you will be able to prioritize any issues and take action sooner rather than later.
Do you know how your cybersecurity defense efforts stack up against your competitors? Contact Johanson Group today to find out.
Now, before we get into NIST Cybersecurity Framework vs ISO 27001, here's a brief introduction to ISO 27001, so that you can better understand why it’s important for businesses looking to protect their data.
ISO 27001: An Overview
The ISO is an independent international body based in Geneva, Switzerland. It provides standards on a wide range of topics—including information security—to governments and businesses around the world.
First released in 2005, the 27000 standards are a family of corporate guidelines for information technology and security risk management.
ISO 27001 (aka ISO/IEC 27001:2013) is an information security risk management standard that specifies requirements for a comprehensive ISMS.
The basic goal of ISO 27001 protect your company and customer information with:
- Confidentiality: Only authorized persons may access data.
- Integrity: Only authorized individuals can modify the data.
- Availability: The information must be retrievable by authorized persons whenever they need it.
ISO 27001 is a process standard that outlines the steps needed to develop and maintain an ISMS. However, it doesn't include specific language on performing these tasks; you need other resources like the NIST SP 800-30 for guidance on how exactly do them (but not included in ISO 27001).
Learn more about the history of security audits here.
How ISO 27001 Is Used
So how does ISO 27001 work?
The standards here are meant to help businesses systemize their cybersecurity, growing a system that was put into place to cover certain issues into a full IT management system. You can get certification for compliance with ISO 27001, whether that's through the ISO themselves or a third-party auditor.
With ISO 27001, the scope can be limited to just one aspect of the company, rather than the company as a whole. For example, you could get certified just for your data center, or just for your cloud-based data storage—or any other aspect of your information technology (IT) systems.
When getting certified, you'll have to go through two stages:
Stage 1: Documentation review: Where your documents on processes, policies, and procedures will be audited. They will be looked at to ensure that they meet ISO standards.
Stage 2: Certification Audit: This will involve an auditor doing a full and thorough on-site assessment to ensure that your systems comply with ISO 27001 fully.
Wondering What the Difference is Between SOC 2 and ISO 27001? Find out!
ISO 27001 vs. NIST CSF: Key Differences
Now that you know the basics of NIST CSF and ISO 27001, if you want to improve and certify your cybersecurity systems, which one should you follow? Both of them are highly useful, and it just depends on what you need from them as a company.
Here are some of the key differences between them:
Risk maturity
The age and sophistication of your business's security system will help you decide here.
If you're just getting started with a comprehensive security program, then the NIST Cybersecurity Framework is likely to be a better fit for your organization.
For those that have a more mature system in place and need certification, ISO 27001 is going to be the way to go. This is because it's better at helping businesses mitigate issues such as data breaches.
Certification
For a cybersecurity system to be certified, it must conform with the ISO 27001 framework.
It's a valuable investment to hire an experienced risk management CPA for ISO 27001 audit, obtain your compliance certification and show stakeholders that you're taking cybersecurity seriously. NIST CSF is not a certification—it sets standards but doesn’t certify organizations against them.
Cost
ISO 27001 is a more advanced standard, so it charges for its documentation and other materials. NIST can provide you with good starting points for implementing an information security system and will be free of charge.
ISO 27001 vs NIST CSF: Similarities
Both ISO 27001 and NIST CSF are security frameworks that help organizations identify and mitigate risks. They are similar in that they both have the following elements:
• Risk assessment
• Risk treatment plan
• Corrective actions for non-conformities discovered during risk assessments
• Continuous improvement processes
Both frameworks also require organizations to have a documented security policy, which is one of the first steps in implementing both standards. Additionally, both frameworks require that organizations develop a Security Awareness Training Program (SATP) to educate employees on their roles in information security.
Can NIST CSF and ISO 27001 be Used Together?
Although you may want to choose one or the other when it comes to frameworks, sometimes combining them can be a good idea. The trick is figuring out why you'd want do that in your particular case.
A lot of new companies begin with NIST, as it allows them to get up and running without incurring any costs. However, they should consider ISO 27001—it's an international standard that's widely recognized by businesses across the world.
If they decide to move on to ISO 27001 compliance, certification will be much easier as they'll have done most of the work during NIST CSF implementation.
While there are advantages to implementing either of these two solutions, you can also benefit by using them in combination. You'll need to evaluate your options carefully so that you get the best possible security for your business needs.
Protect Your Business: Get a Risk Advisory CPA for Compliance and Data Breach Prevention—Here’s Why
As the world increasingly relies on technology, data security has become a top concern for businesses of all sizes. This is particularly true for SaaS startups and organizations that rely on Information Security Management Systems (ISMS) to protect sensitive information.
One way to ensure the security of your organization's data is to hire an experienced risk advisory Certified Public Accountant (CPA) who can conduct an ISO 27001 audit or NIST framework assessment.
Here are some reasons why this investment is worth it for your business.
1. Expertise in ISMS implementation
Implementing an ISMS can be a complex process, and having an experienced CPA on your team can be a great asset.
These professionals have the knowledge and expertise to guide your organization through the implementation process, ensuring that your systems are set up correctly and are aligned with industry best practices.
An experienced CPA can help you identify potential risks and vulnerabilities and develop mitigation strategies.
2. Compliance with international standards
Since ISO 27001 is an international standard for information security management, and the NIST is a framework developed by the US government to help organizations manage and reduce cybersecurity risks, compliance with these standards is crucial for businesses that handle sensitive information.
A risk advisory CPA can help ensure compliance with the new standards, lowering your organization's risk of a data breach or cyber attack.
3. Protection against financial loss
A data breach or cyber attack can be costly for any business, particularly for startups just getting off the ground.
According to a study by IBM, the average cost of a data breach is $4.24 million. This cost includes legal fees, regulatory fines, and lost business.
By investing in an experienced risk advisory CPA, you can reduce the risk of a breach or attack, potentially saving your business millions of dollars in the long run.
4. Improved reputation
A data breach can damage your organization's reputation, causing customers to lose trust in your business. This can result in lost business, decreased revenue, and difficulty attracting new customers.
By investing in an experienced risk advisory CPA, you can demonstrate to your customers that you take data security seriously, improving your reputation and increasing customer trust.
Are you forgetting SOC 2? Don’t! As a SaaS organization SOC 2 Compliance is crucial— Read more
Conclusion
Choosing the right compliance framework for your business is a critical decision that can significantly impact your organization's data security and overall success.
Both NIST and ISO 27001 offer comprehensive guidelines and standards for information security and data privacy, and choosing one over the other depends on your unique business needs, industry regulations, and the level of security you require.
By assessing your business's specific risks and compliance requirements, you can select the most appropriate framework that aligns with your objectives, budget, and resources.
Whichever framework you choose, remember that compliance is an ongoing process, and you must regularly review and update your security measures to maintain your organization's data integrity and protect your customers' sensitive information.
Ready to Get Started?
Ready to take the first step in protecting your business against cyber threats and ensuring compliance with industry regulations?
Contact Johanson Group today to schedule a consultation with our expert risk advisory specialists. Our team has extensive experience in navigating the ISO 27001 audit and compliance process, making it seamless and understandable for businesses of all sizes.

Why You Need a Cybersecurity Risk Management Policy, How to Write One—and Who Can Help
Why You Need a Cybersecurity Risk Management Policy, How to Write One—and Who Can Help
With new technologies emerging every day to make transactions and processes smoother and faster, comes with an increased risk of cyber attacks. Cybercriminals adapt quickly to changes in technology and exploit all new platforms.
There’s no way to stop cybercriminals in their tracks for good, but there is a way to protect your company and customer data and information:
Develop a cybersecurity risk management plan regardless of industry or size.
To ensure that your organization is prepared to deal with any cybersecurity threat, you need a flexible and responsive risk assessment program that adapts according to the changing nature of cyber threats.
Let’s look at how this can be done effectively.
What is a risk management policy?
A risk management policy is a set of instructions for an organization to follow when dealing with cyber security risks. It is a set of guidelines designed to ensure that the organization takes the right steps to protect its data and systems.
Cybersecurity risk management is an ongoing process of identifying, analyzing, evaluating, and addressing cybersecurity threats. It is not a one-time event; it must be an ongoing process because new threats are constantly emerging.
Which companies should have a risk management policy?
The answer to this question is, "Every company."
Risk management is a process used to identify possible risks and take steps to mitigate them. It helps organizations understand how they can reduce their exposure to risk or how they can increase the likelihood of achieving their goals despite being exposed to risk. This means every company needs a risk management policy—even if they don't think they need one.
The goal of risk management is not just to prevent catastrophe; it's also about identifying opportunities for growth and progress. If a company doesn't have a risk management policy, then they are missing out on opportunities for growth and progress by failing to plan for what could happen in the future.
Cybersecurity risk management is the responsibility of everyone in the organization, not just the security team. Everyone needs to have a holistic view of what's going on to ensure they're addressing all risks appropriately.
The risk landscape has changed dramatically over the past few years—to address these challenges, organizations need to have robust policies and tools for assessing vendor risk, as well as identify internal weaknesses so they can fix them quickly before they become major problems.
They must also mitigate IT risks by training employees or changing policies and internal controls, depending on what works best for them.
Finally, organizations need to test their security posture regularly to always know if there are any holes in their defenses.
SOC 2 Compliance can help to gain your customer, employee, and stakeholder’s trust. Learn how.
Benefits of a Cyber Risk Management Policy

1. Improve and safeguard your business reputation
A major data breach can destroy your organization’s reputation, making it difficult to regain customers' trust.
To build and maintain trust with customers, a strong cybersecurity risk management program can help you prioritize critical risks so that you're equipped to deal with any impending attacks.
2. Enable and support your IT team
Your IT team will be better positioned to keep projects on track by ensuring that there is always an appropriate number of personnel and resources available during a crisis.
A cybersecurity plan can help your business better support IT, ultimately increasing productivity and efficiency.
3. Prevent revenue loss
Data breaches can affect every part of your organization, from finance to legal and everything in between. But the most obvious impact is financial: data breach insurance costs have skyrocketed over the last few years because so many organizations are experiencing them.
The average data breach cost is $3.86 million, and can take years to recover from the initial attack; moreover, businesses responsible for someone else's data are subjected to privacy laws and face fines and penalties.
4. Reduce the risk of temporary (or permanent) shutdowns
The average cost of downtime for different industries varies greatly:
- $2600 per minute for financial services
- $8400 per minute for healthcare organizations
- Over $17K per minute for manufacturers
Any attack—a ransomware infection, DDoS assault, or phishing scam—can disrupt your business and cost you time and money.
However, a risk management plan can help you better prepare for any cyber incident and mitigate potential downtime risks.
Are you a healthcare organization needing HIPAA Compliance? Learn More.
5. Increase employee engagement, trust, and company transparency
Companies should create plans to protect shareholders, customers, and employees.
Employee information, including social security numbers, credit card data, and birth dates, among other details, is a prime target for malicious hackers.
A solid risk management strategy empowers employees to focus on what matters most: advancing the organization's goals.
6. Raise the bar for your competition
A risk management plan demonstrates to potential customers that you take their data security seriously and are prepared in case of a breach, giving you an edge over your competitors.
Now that you know the benefits of having a cybersecurity risk management policy in place, here are five steps you can take to write one.
Writing Your Cyber Risk Management Policy

A cybersecurity risk management policy is a document that outlines an organization's commitment to protecting its data and intellectual property from theft, loss, or damage. It outlines the steps that the organization will take to mitigate these risks.
The policy should be clear and concise. But before writing, you need to identify and clarify the following:
- What types of data are stored within the company's systems?
- How will employees access this data?
- Are there any restrictions on what type of information can be accessed by employees?
- How will employees store this data?
- How will employees dispose of this data when they leave their jobs?
- Have you consulted risk advisory specialists to review your cybersecurity policy plan to ensure you aren’t missing anything?
Regarding cybersecurity, you must know the risks that could compromise your company's data.
While your cybersecurity risk management policy can be tailored to fit your specific company and industry, every policy must include the following:
Step 1: Risk Identification
Identifying risks is the first step in managing potential dangers. Identify all prospective hazards and classify their severity or likelihood of happening if no precautions are taken—then take precautionary measures against them.
When assessing risk, consider both current and future risks. As technology evolves and companies restructure the risk landscape changes.
Step 2: Formulate a Risk Analysis
After identifying risks, the next step is to assess their likelihood and possible effect. For example, how vulnerable is your company to a particular risk? What would be the cost of that risk if it were realized?
Based on the potential for disruption, an organization may categorize risks as “high-, medium-, or low-impact.”
Risk analysis is used to prioritize risks and determine the most urgent threats.
Step 3: Create an Incident Response Plan
An Incident Response Plan addresses the actions you will take if a cyberattack were to occur.
An Incident Response Plan should include identifying:
- Who will be responsible for each step in the process, who will have access to sensitive data within this group, and what type of training they will receive.
- How often you will update your policy and procedures (if applicable).
- A list of resources available for employees who need help with their personal computers or devices (for example, IT support).
Step 4: Risk Mitigation Plan
Risk mitigation is any precautionary action taken by a company to avoid or minimize the impact of potential disasters. It is extremely important to review and assess the controls in place.
Step 5: Ongoing Risk Monitoring Process
Your Cybersecurity Risk Management Policy is a living document that should be updated and revised regularly. As cyber risks evolve, so should your policy. What was once considered a minor risk might become severe enough to threaten the company, and vice-versa. Understanding your current risk profile through regular risk assessments—proactively monitoring these risks rather than just reacting to them when they occur—helps you prepare for the future.
Cybersecurity Risk Management is Made Easy With Risk Advisory Specialists
When it comes to cybersecurity risk management, there are so many different factors that you have to consider. There are a lot of resources available online that will help you learn about the basics of cyber security and how to protect yourself from hackers or other cyber threats. But when it comes time to actually implement your new knowledge, things can get complicated fast.
That's why it's critical for any organization that wants to succeed in today's digital world—whether they're a small business or a Fortune 500 company—to enlist the help of risk advisory specialists who can assist them with their risk management efforts. These specialists have years of experience working with companies large and small and know exactly what type of services they need in order to succeed in this environment.
Conclusion
It's important to have a strong cybersecurity policy in place. With so many threats out there, it can be difficult to know where to start with creating a cybersecurity policy that works for your business. For expert, professional guidance, reach out to Johanson Group risk advisory specialists who can help you identify your cybersecurity risks and come up with a proactive plan to mitigate attacks.
Are you ready to be proactive in your cybersecurity response?

Why SOC 2 Auditing Is Essential for SaaS Businesses
Why SOC 2 Auditing Is Essential for SaaS Businesses
SaaS companies are becoming more and more popular, but not all of them are able to stay compliant. The truth is that if you run a SaaS business, there's no way around it: you have to be SOC 2 certified.
What are the requirements for SaaS?
SaaS is a model of software distribution that provides access to applications over the internet. SaaS is an acronym for Software as a Service, but it's also used to refer to the business model itself.
The acronym has been around since at least 1999 when it was defined as "the delivery of software applications via the Internet." However, the idea behind it dates back much further: The first commercial use of SaaS was in 1979 with CompuServe's CBIS system (Computer Based Information Services), which allowed users access to databases and email through their computers' modems. In recent years, we've seen this model grow enormously thanks largely due to its low cost compared with traditional on-premises solutions like Oracle or SAP--and because customers don't need expensive hardware or software licenses from vendors like Microsoft or Adobe anymore!
Is SOC 2 mandatory for SaaS?
SOC 2 is not mandatory for SaaS. However, SOC 2 is a standard for service providers and has been adopted by many companies as a good practice. There are several benefits of SOC 2 compliance:
- It increases trust in your brand among customers and partners
- It gives you more credibility in the market (especially when dealing with other businesses)
- It allows you to demonstrate compliance with data protection laws
Why SOC 2 Auditing Is Essential for SaaS Businesses

A SOC 2 audit is a requirement for all SaaS companies. The reason why? Because it's the only way to prove that you are using security controls that meet the standards set by the industry and your customers.
In order to be SOC 2 compliant, a third-party auditor must verify that you have implemented specific security controls in accordance with an accepted framework such as NIST or ISO/IEC 27002.
By completing an annual SOC 2 audit and issuing an attestation report, you can demonstrate that your organization has met these standards of protection for its customers' data (and their own).
How to stay compliant as a SaaS business
A SOC 2 audit is an ongoing process. It's not a one-time thing, and it's not just about security. SOC 2 compliance means you're staying compliant with all five of these criteria:
- Security: You have appropriate physical, technical, and administrative controls in place to ensure the confidentiality, integrity, and availability of your data;
- Privacy: You protect the privacy rights of individuals whose personal information is involved in processing;
- Integrity: You follow policies for preventing unauthorized modification or destruction of information; * Availability: Your system must be available 99% of the time with no more than 5 minutes of downtime per month; * Compliance Reporting (if applicable): Your organization must provide evidence that it has met required standards through regular self assessments conducted by qualified personnel
READ MORE: What is the difference between SOC 2 Type 1 and SOC 2 Type 2
Why SaaS Companies Choose SOC 2 Compliance
SaaS companies can choose to be audited for SOC 2 compliance, which is why it's important to understand what this means. The SSAE 16 report is a document that verifies the security of your company and its data. It's one of the main reasons why many businesses choose to undergo an audit: because it lets them show clients that they're doing everything they can to protect their information from hackers and other threats. This can help you attract new clients who want their data handled safely--and even keep current ones from jumping ship!
SOC 2 for SaaS
If you're a SaaS company, SOC 2 compliance is essential. You must be able to prove the security of your systems and data to customers who demand it--and if they don't get what they want, they might take their business elsewhere.
Additionally, being SOC 2 compliant gives your business a boost in terms of its reputation and reliability in the eyes of potential clients. If you want to keep growing as an organization and earning new clients every year (or month), then becoming SOC 2 audited should be at the top of your agenda for 2019!
If you run a SaaS company, you must consider SOC 2 compliance
If you run a SaaS business, then SOC 2 compliance is essential. There are two main reasons for this:
- SOC 2 compliance is not mandatory, but it's recommended by many in the industry. If you want to build trust with customers and partners, then SOC 2 compliance can help. It provides them with proof that your company takes security seriously.
- In addition to this, many banks require that their vendors have undergone an independent audit before they do business with them--and if your software handles sensitive customer data like credit card information or social security numbers (SSNs), then banks may require an audit as part of their due diligence process before signing contracts with these vendors.
SaaS is a growing industry, and it's important for companies in this space to be SOC 2 compliant. If you run a SaaS business, then you should consider getting your company audited by an independent third party that can verify that your data security practices are up-to-date and working properly. An audit will also help ensure that your company remains compliant with regulations such as GDPR or HIPAA.

SOC 2 Frequency: What You Should Know
SOC 2 Frequency: What You Should Know
SOC 2 Audit Frequency: Types 1 & 2
When you start the audit process with an auditor, you will need to decide on the first audit period. While your auditor might give you some guidance as to when to start your audit period, it is up to you when the audit period starts and when it ends. In this blog, we will discuss the how frequently a SOC 2 audit should be performed.
For a SOC 2 Type 1 you will choose the earliest date that all the controls are in place. You normally only do a SOC 2 Type 1 report once. You might do it again if you have significant changes and need a report to show customers those changes. From the Type 1 report, you will move to a SOC 2 Type 2 report.
For a SOC 2 Type 2, you will want to choose a start date when all the controls are in place and you are following them.

With the creation of compliance platforms like Vanta and Secureframe a minimum audit period for a SOC 2 Type 2 is usually 3 months. Clients usually do a shortened period of 3-6 months the first time and then move to a 12-month period after that.
That schedule will get you a SOC 2 Type 2 report sooner to show prospective clients and close deals. From there you usually move to a 12-month audit period to show them that you continue to stay compliant.
READ MORE: What is the difference between SOC 2 Type 1 and SOC 2 Type 2
A SOC 2 report or attestation doesn’t really expire but, your customers will be looking for a new report annually. Often you will be asked for a bridge letter to cover the period since the last audit report.
READ MORE: What is a SOC 2 Bridge Letter?
One of the most important things to know is that once you start the SOC 2 audit process, you should always be under an audit period or window.
Once your initial audit period is over and you have received your report, it is important to stay on top of your controls and begin preparing for your next audit period in accordance with SOC 2 frequency. Any gaps between reporting periods could result in having to explain to your clients what happened, which can be avoided by consistent and timely audits.

7 Things To Look For In A SOC 2 Auditor
7 Things To Look For In A SOC 2 Auditor
A SOC 2 audit can prove to customers that their data is secure.
However, mistakes, misunderstandings, and hiring an incompetent auditor can make the SOC 2 audit process more complicated than it needs to be.
What is a SOC 2 audit?
A SOC 2 audit is a service organization control (SOC) auditing methodology regulated by the American Institute of Certified Public Accountants (AICPA) that helps companies ensure the security and confidentiality of the customer data they handle.
This audit is carried out by an independent third party, who will evaluate your company's controls and procedures for protecting sensitive customer information. This audit is designed to show that you have a system in place to protect customer data, and it's one of the most common types of audits carried out by external parties.
An official SOC 2 report is valid for one year after its issue date, and future annual audits must be completed by an external auditor from a licensed CPA firm.
Why hire a SOC 2 auditor?
While compliance software can provide an excellent starting point for SOC 2 compliance, solely relying on it to prove your organization's compliance is not enough.
Compliance software tools can help companies prepare for a SOC 2 audit, but these programs cannot replace the work of an actual CPA firm. When conducting such audits, businesses must turn to professional auditors who specialize in this area.
7 Things to Consider When Choosing a SOC 2 Auditor
When trying to determine whether they need a compliance audit, many service organizations face obstacles. However, choosing the right SOC 2 auditor for your organization—although difficult—is an important step in addressing these hurdles.
1. The CPA firm must be affiliated with the AICPA
Before even looking at any of the criteria below, the first thing you need to do is check to see whether the auditor is affiliated with AICPA or a certified CPA firm. Choosing an independent SOC2 assessor is essential to receive a valid attestation.
2. Experience and Reputation

One of the most important things you can do to ensure that your SOC 2 audit goes smoothly is to choose an experienced audit firm with a reputation for excellence.
Determine whether the audit firm has performed similar SOC audits in your niche and for organizations of similar size. It will be significantly easier to work with an audit firm that has previously audited similar companies to yours.
You should also look into how many years the audit firm has been in business, its total number of employees, clients served, and overall financial stability.
A company with a strong reputation is more likely to be able to meet all of your needs, both before and throughout the course of your assessment.
See what others say about risk advisory specialists, Johanson Group
3. Qualifications to complete the audit in your specific industry
Because auditing is such a specialized skill, it's important to choose an auditor with experience in your industry—particularly if your company is similar in size and complexity to other companies within the same sector.
4. Look for well-rounded risk advisory specialists
Before hiring an auditor, ask if the firm can provide assessments and attestations for any other certifications your industry might need—such as HIPAA compliance or ISO 27001. Swapping auditors each time you pursue a different certification will waste your time and money.
READ MORE: SOC 2 vs. ISO 2700: Which to choose
5. Communication: Do you and your auditing firm agree on how to conduct the audit, gather evidence, and share information?
You should always choose an auditing firm that understands how you communicate.
Mismanagement and miscommunication with your auditing firm will waste time, effort, and money.
6. Thorough understanding of your organization's specific tech stack
If the potential audit firm doesn't seem knowledgeable about the technologies you use and depend on, it may be a sign that they aren’t an ideal fit for the job.
Finding an audit firm that understands your company's unique business practices and can use its expertise to find any vulnerable spots in your controls is essential for a successful audit.
7. Budget Alignment

If you are on a tight budget, consider working with a CPA firm that is responsive to your needs. However, affordable services often include hidden costs—especially if the price seems too good to be true!
Instead of considering just the expense for the first year, plan for two or three years because SOC 2 compliance is an ongoing process. In cases like these, collaborating with the same audit firm will be much more efficient over time.
Best practices to follow while selecting a SOC 2 auditor
It's crucial to have the right kind of auditor on your team—one who will be thorough and give you an objective assessment. Here are some tips for how to go about finding one:
- Interview several auditors before choosing one.
- It is always a good idea to ask for references from customers your auditors have served and clients who are similar in size and industry.
- Speak directly with the person who will be conducting your audit.
The bottom line is that clients need to perform due diligence on their SOC 2 auditors before signing a contract with them. An hour with a vendor selling their services isn't going to tell you much about the actual quality of the work. So choose your auditor based on the right criteria and get your money's worth.



