Resources

Articles

Practical guides and industry updates to help your organization stay secure and compliant in a digital-first world.

Filters
Show all
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Sep 4, 2023

What is SOC 2 Penetration Testing and Why You Need One

Stay ahead of cyber threats with SOC 2 penetration testing. Learn how it helps ensure data security and meets compliance standards.

SOC 2
Pen Test

Is Penetration Testing (Pen Testing) required for SOC 2?

We get this question a lot. The short answer is, no, it is not required.  But let's talk about the nuances within this topic.

According to CC4.1:COSO Principle 16: The entity selects, develops, and performs ongoing and separate evaluations to ascertain whether the components of internal control are present and functioning. The points of focus specified in the COSO framework require management uses various types of ongoing and separate evaluations, including penetration testing, independent certifications made against established specifications (for example, ISO certifications), and internal audit assessments.

It may look like the requirements for penetration testing are integral to your SOC 2, but if you find them overwhelming, I encourage you to look at it more as a standard example of evaluations your company might consider. After performing your risk assessment and concluding that other ongoing evaluations are sufficient, you might look to exclude a pen test. However, you should undoubtedly include a penetration test if you have a high-risk level in that area.

When working towards a SOC 2 Type I report, the auditor looks at the appropriateness of the design of the controls, not at the operating effectiveness or the policies being followed. Due to this, a penetration test is not required for a SOC 2 Type I report.

For the SOC 2 Type II, if you have penetration testing as one of your controls, then you will absolutely need to have one performed.

Often clients choose to do a shortened period for their initial SOC 2 Type II and most opt to have pen testing annually. In this case, if you do have pen testing as a control, it might not occur during the audit period. That is completely fine. The SOC 2 report would say, "no events to test." That is not an exception or a "ding" on the report, it's merely informing you and your customers know the auditors could not test that control.

Why your company should do pen testing even if it’s not required

Pen testing is a good business practice and industry standard. Many of our client’s customers will ask for their most recent pen test, and their SOC 2 Type II report. So, even if you try to cut costs by not having penetration testing as a control, you will probably still have to have one performed annually.

Types of Penetration Testing

There are three main types of pen testing:

  • External Pen testing is also called “black hat” or “black box” testing. This type of test focuses on attacking points of entry.
  • Internal pen testing is also called “white hat” or “white box” testing. This test focuses on the movement of the hacker once inside your system.
  • “gray hat” or “gray box” testing, this type is a mix of internal and external pen testing. This test is a great way to get the best of both tests.

You can choose manual penetration testing or pen testing as a service, a.k.a automated pen testing. SOC 2 does not specify one over the other. Instead, it is up to management to decide what is most appropriate and what their customers would expect.

What is the difference between manual and automated penetration testing?

Manual pen testing uses human knowledge and expertise. It is an excellent way to detect design flaws, compound flaw risks, and missing business logic that pen testing as a service would miss.

Pen testing as a Service (automated penetration testing) is a great way to perform more frequent or continuous testing. It uses a modern SaaS platform to enable penetration testing to occur quickly and at a significantly reduced price. It focuses on easily automated tasks like missing security patches, common passwords, or unintended exposure to the internet. They will also be up to date on the current threats facing companies.

When considering what type of penetration test might be appropriate for your situation, it would be best to talk to an expert CPA knowledgeable in the nuances of SOC 2 and SOC I reporting and pen testing.

When should you perform a penetration test?

Generally, pen testing is performed annually. If you are already on a pen testing schedule, you should stay on that schedule.

If this is your first time, select the best time for you and your company. Your CPA can help you determine this.

If you go with the pen test as a service or automated pen testing model, you will want to identify when the tests are performed and write your policy around that.

Does my penetration test have to come back clean for SOC 2?

NO! SOC 2 is looking for you to follow your processes and policies. When issues are identified, auditors look for the ticket to be created and resolved within the SLA specified in the policy.

Don't look at flagged issues as negative. It is a good thing when problems are identified and resolved because you can be confident your company and customers' data are more secure than when you first started the process.

SOC 2 penetration testing is up to you!

While obtaining a "clean" SOC 2 report is not a must-have requirement, it is a good business practice. The more controls and testing performed, the more secure the data will be. It is also a great marketing tool. You can show your customers, stakeholders, and partners that you go above and beyond the minimum requirements to secure your customers' data.

Aug 28, 2023

Your Guide to SOC 2 Attestation Reports

All the things surrounding SOC 2 reports and attestation can seem a little overwhelming and complicated. We get it; that's why we've created this quick guide to SOC 2 attestation reports with simplified terms and definitions to help you understand the basics.

Reporting
SOC 2

During a SOC 2 attestation, companies need to use specific criteria to evaluate their services.

All the things surrounding SOC 2 reports and attestation can seem a little overwhelming and complicated. We get it; that's why we've created this quick guide to SOC 2 attestation reports with simplified terms and definitions to help you understand the basics.

A Quick SOC 2 Refresh

You've landed on this article for SOC 2 attestation, so odds are you already know what a SOC 2 report is, but just in case, here's a quick refresh:

What does the S-O-C in 'SOC 2' mean?

  • The ‘S-O-C’ stands for System and Organization Controls Number Two.
  • SOC 2 is a set of standards developed by the American Institute of Certified Public Accountants (AICPA).
    • These standards help businesses evaluate their internal controls and ensure they meet industry best practices regarding information systems management and cyber security.
  • Now, onto the basics of SOC 2 attestation reports.

What is a SOC 2 attestation?

A SOC 2 attestation is a third-party assessment of a service organization’s controls relevant to

  • Security
  • Availability
  • Processing Integrity
  • Confidentiality
  • Privacy

Why do you need a SOC 2 Attestation?

The idea behind a SOC 2 attestation is that companies can demonstrate their commitment to data protection by having their systems reviewed independently. Customers can then make informed decisions about whether it's safe to store sensitive information in the cloud and avoid legal issues down the road.

“The reason for a SOC 2 attestation is that it helps companies and clients know that information held at the service organization is being kept private and secure.”

What does a SOC 2 attestation include?

To assure customers that you're keeping their data safe and secure, you need to show that your company has thought through all aspects of data protection.

Including:

  • Who has access to customer data?
  • What measures do you take to protect information against cyberattacks?

What is required During a SOC 2 attestation?

During a SOC 2 attestation, companies are required to use a specific set of criteria to evaluate their services.

These criteria are organized into five trust services categories:

  1. Security (required)
  2. Availability (optional)
  3. Confidentiality (optional)
  4. Processing Integrity (optional)
  5. Privacy (optional)

You will also want to ensure that these controls are in place within your systems prior to your SOC 2 attestation with a CPA:

  • Network Firewalls
  • Two-factor authentication
  • Intrusion detection
  • Performance monitoring
  • Disaster recovery and Incident response procedures
  • Security breach management
  • Quality assurance
  • Process monitoring
  • Data encryption
  • Access controls (physical and logical)
  • Change Management processes

How long does a SOC 2 attestation take?

A SOC 2 Type I (point-in-time) attestation is typically completed in about 4-6 weeks. This may seem like a long time, but remember that it takes more time for complex organizations than for simple ones.

While these variables are essential in determining the duration of your audit, there are also other factors at play:

  • If you're working with a new auditor and they don't have much experience on their side yet (for example, if you're their first client), then this will slow down the process somewhat as well. That's why we recommend choosing a CPA specializing in SOC 2 attestations like Johanson Group.
  • Some companies may need additional support before providing all the necessary documentation required by SOC 2 auditors; this may add days or weeks to your timeline!

Need to add in SOC 2 Type II (period of time) details. Those audits are a minimum of 3 months the first time and 12 months for subsequent type II audits. Type I tests the design of control, whereas Type II tests both design of controls and their operating effectiveness over a period of time.

How much does a SOC 2 attestation cost?

The cost of a SOC 2 attestation depends on many factors, including:

  • Size: Smaller organizations can often complete an audit at a lower cost than larger ones.
  • Complexity: Suppose your company uses more complex controls and procedures than other companies. In that case, it will cost more to audit you than if it did not have as much complexity in its controls.
  • Type of Service: What type of service is provided by the system being audited? For example, a mobile app for a SaaS start-up may be less expensive than an internal data protection solution for a SaaS healthcare provider due to its more straightforward design and architecture requirements.
  • Type of audit (i.e., standard or enhanced): A standard assessment costs less than one that includes additional testing for application-specific vulnerabilities and threats (enhanced.)

The SOC 2 attestation process with Johanson Group

  • The first step is to determine whether or not you are eligible for SOC 2 attestation services. If so, we will conduct an initial assessment and provide an estimate based on our findings.
  • Once we have reviewed the scope of work and estimated costs, we can begin working with you to develop a detailed plan for implementing security controls into your existing environment. Our goal is always to achieve compliance as efficiently as possible while minimizing disruption to business operations.

In short, a SOC 2 report evaluates whether a service organization's systems and processes meet high standards for security and privacy.

It also assures on behalf of service providers so they can show customers how they use their information responsibly.

Aug 21, 2023

What is a SOC 2 Bridge Letter?

How do you provide assurance to your employees, stakeholders and potential customers and partners in between compliance audit review periods?

Reporting
SOC 2

What is a SOC 2 Bridge Letter?

How do you assure your employees, stakeholders, and customers of your SaaS company that their information is private and secure between compliance audit review periods?

Provide them a SOC 2 Bridge Letter.

A SOC 2 bridge letter is issued after your company or organization's SOC 2 report audit period has ended. It bridges the gap between the end of your last SOC 2 report audit and when you're ready to conduct your next audit, which is why it's also referred to as a 'gap letter.'

Usually, SOC 2 reports cover a user entity for 6 months to a year, but if your company follows a calendar year, then your report’s validity may leave you uncovered.

Does a SOC 2 bridge letter provide any coverage? In its most simple form, the answer would be:  No.

Bridge letters aren’t meant to take the place of another SOC 2 report, but to provide coverage of your company and trustworthiness to your customers and clients.

What Does a SOC 2 Bridge Letter Look Like & What is Included?

What a SOC 2 bridge letter should include:

  • Significant changes to any systems or controls since the audit

OR

  • A statement that the organization or company is unaware of any material changes from the latest SOC 2 report to its expiration.


What a SOC 2 bridge letter should NOT Include:

Remember, a bridge letter is sent to cover the gap between SOC 2 audit reports. It isn’t meant to take the place of the actual audit, therefore it shouldn’t include specific details like

  • Test procedures
  • Test results
  • System descriptions

Here's an example of a SOC 2 Bridge letter template Johanson Group provides to our clients:

Who Writes and Issues a SOC 2 Bridge Letter?

Management of the company that received the previous SOC 2 report completes and sends the SOC 2 Bridge Letter to its stakeholders (not the auditor).

The letter intends to assure all intended recipients that there have been no significant changes to your SaaS company's controls between audit renewal periods. If there have been material changes, the SOC 2 bridge letter is where you would explain changes to your controls — if any— and assure your customers or clients how they wouldn't affect the results of your SOC 2 report.

The CPA firm conducting the SOC 2 audit is not involved in the writing or disbursement of a SOC 2 bridge letter. Why?

The entire purpose of the SOC 2 bridge letter is to attest that client, stakeholder, and employee privacy and security are still in compliance. If something were to change with the company's security services after a SOC 2 is complete, the CPA firm that conducted the audit could not speak to the passing of any new changes after the audit expires.

Why are Bridge Letters Important?

As you can see, bridge letters are an essential part of your SOC 2 compliance program. The written assurance to your customers and stakeholders that you are still in compliance after your SOC 2 report helps bring confidence and peace of mind that their information is secure and private and trust service commitments and requirements are being met.

LEARN MORE: Why Saas Start-Ups Should Prioritize SOC 2 Compliance

As we have seen, SOC 2 bridge letters are critical to your SOC 2 compliance. They help you to demonstrate that your controls are appropriately designed and operating effectively and can be relied upon by all stakeholders.

We encourage all organizations who use IT services to consider applying for a SOC 2 report and getting the letter as soon as possible, if they haven’t already done so.Remember, a bridge letter is a temporary coverage for your trust services compliance. Schedule your subsequent SOC 2 audit examination today with Johanson Group, your trusted CPA for SaaS organizations.

No results found.
No results found for your search query
PCI Compliance Guide
Determining the Scope Statement
SOC 1 vs SOC 2 vs SOC 3 — Which Report Does Your Company Actually Need?
What is a SOC 2 Bridge Letter?
Your Guide to SOC 2 Attestation Reports
What is SOC 2 Penetration Testing and Why You Need One
Key Differences Between ISO 27001 and 27002
How Your Customer Success Manager fits into your journey to SOC 2 compliance
What is the difference between SOC 2 Type 1 and SOC 2 Type 2