About this program
Quick check on whether you are reviewing vendor SOC 2 reports properly — not just collecting them.
Risks addressed
- High SOC 2 collected but never read u2014 qualifications missed
- High Carve-out / sub-service organisations not chased down
- High Complementary user-entity controls (CUECs) ignored
Controls (6)
-
SOC 2 / ISAE 3402 collected for Tier-1 vendors
HighThis control requires the organization to obtain and maintain current SOC 2 Type II or ISAE 3402 assurance reports from all Tier-1 (critical or high-impact) third-party vendors who process, store, or transmit organizational data. Tier-1 vendors are typically those handling…
How to test + evidence
Testing procedure: Vendor register flags Tier-1; reports on file dated within 12 months.
Evidence to collect: Vendor register + report files.
-
Reports actually reviewed by SecOps
HighThis control ensures that security monitoring reports generated by SIEM, IDS/IPS, vulnerability scanners, and other detection tools are actively reviewed by qualified Security Operations personnel within defined timeframes. It addresses the gap between automated alert generation and human analysis, requiring…
How to test + evidence
Testing procedure: Documented review with date + reviewer + findings.
Evidence to collect: Review log.
-
CUECs mapped to your own controls
HighCustomer User Entitlement Controls (CUECs) are controls defined and operated by a service provider's customers within a shared responsibility model, particularly in SaaS and PaaS environments. The service provider maps these customer-managed controls to their own baseline security requirements, establishing…
How to test + evidence
Testing procedure: Complementary user-entity controls captured in your control library.
Evidence to collect: CUEC mapping.
-
Qualifications / exceptions tracked
HighThis control ensures that all approved deviations, exceptions, and qualifications to security policies, standards, or baseline configurations are formally documented, tracked, and reviewed. Organizations maintain a centralized register or database that records the justification, scope, duration, compensating controls, and approval…
How to test + evidence
Testing procedure: Each qualification raised as a risk + mitigated or accepted.
Evidence to collect: Risk register entries.
-
Sub-service organisations evidenced
MediumThis control requires that organizations maintain and validate evidence of security controls and assurance activities for all sub-service organizations (subprocessors, cloud providers, managed service providers, and other third parties) that process, store, or transmit organizational data. The organization must obtain…
How to test + evidence
Testing procedure: Carve-out method? Chase the sub-service report.
Evidence to collect: Sub-service inventory.
-
Annual recheck workflow
MediumAnnual recheck workflows are automated or semi-automated processes that re-verify security controls, user access rights, system configurations, or compliance posture at defined yearly intervals. These workflows typically trigger review tasks, collect fresh evidence, compare current state against baseline or policy…
How to test + evidence
Testing procedure: Reports expire; workflow chases renewal within 60 days of expiry.
Evidence to collect: Renewal calendar.