@@ -85,3 +85,7 @@ Keep your partnerships secure by managing third-party risks.
|
|||||||
### Transparency
|
### Transparency
|
||||||
|
|
||||||
SOC 2 is about showing how you operate—document and share your processes.
|
SOC 2 is about showing how you operate—document and share your processes.
|
||||||
|
|
||||||
|
- [Have a security page](TRA.001_have_a_security_page.md)
|
||||||
|
- [Clearly explain your services](transparency/TRA.002_clearly_explain_your_services.md)
|
||||||
|
- [External support available](TRA.003_external_support_available.md)
|
||||||
|
|||||||
31
controls/transparency/TRA.001_have_a_security_page.md
Normal file
31
controls/transparency/TRA.001_have_a_security_page.md
Normal file
@@ -0,0 +1,31 @@
|
|||||||
|
---
|
||||||
|
id: "TRA.001"
|
||||||
|
category: "transparency"
|
||||||
|
revision-version: 1
|
||||||
|
revision-date: "2024-01-15"
|
||||||
|
estimate-time: "1h"
|
||||||
|
necessity: "mandatory"
|
||||||
|
frameworks:
|
||||||
|
- name: "soc2"
|
||||||
|
sections: ["CC2.3"]
|
||||||
|
---
|
||||||
|
|
||||||
|
# Have a security page
|
||||||
|
|
||||||
|
## Purpose
|
||||||
|
|
||||||
|
Having SOC-2 for yourself is useless, you want to leverage it as much as
|
||||||
|
possible.
|
||||||
|
|
||||||
|
## Implementation
|
||||||
|
|
||||||
|
Something simple!
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
People need to know how to contact you if there is an incident or want access to
|
||||||
|
your trust center.
|
||||||
|
|
||||||
|
## Evidence
|
||||||
|
|
||||||
|
- Link to your security page
|
||||||
@@ -0,0 +1,30 @@
|
|||||||
|
---
|
||||||
|
id: "TRA.002"
|
||||||
|
category: "transparency"
|
||||||
|
revision-version: 1
|
||||||
|
revision-date: "2024-01-15"
|
||||||
|
estimate-time: "1h"
|
||||||
|
necessity: "mandatory"
|
||||||
|
frameworks:
|
||||||
|
- name: "soc2"
|
||||||
|
sections: ["CC2.3"]
|
||||||
|
---
|
||||||
|
|
||||||
|
# Clearly explain your services
|
||||||
|
|
||||||
|
## Purpose
|
||||||
|
|
||||||
|
Here, we are not enhancing security, we are helping the auditor be more
|
||||||
|
efficient. As part of the audit, he/she will need to understand clear boundaries
|
||||||
|
for the audit, identify the relevant risk and then check how you mitigate them.
|
||||||
|
|
||||||
|
A proper service description is key for your customers, but it also help the
|
||||||
|
auditor understands what your customers are expecting from you.
|
||||||
|
|
||||||
|
## Implementation
|
||||||
|
|
||||||
|
Nothing, everything should already be on your website for customers to see.
|
||||||
|
|
||||||
|
## Evidence
|
||||||
|
|
||||||
|
- Website link
|
||||||
33
controls/transparency/TRA.003_external_support_available.md
Normal file
33
controls/transparency/TRA.003_external_support_available.md
Normal file
@@ -0,0 +1,33 @@
|
|||||||
|
---
|
||||||
|
id: "TRA.002"
|
||||||
|
category: "transparency"
|
||||||
|
revision-version: 1
|
||||||
|
revision-date: "2024-01-15"
|
||||||
|
estimate-time: "1h"
|
||||||
|
necessity: "mandatory"
|
||||||
|
frameworks:
|
||||||
|
- name: "soc2"
|
||||||
|
sections: ["CC2.3"]
|
||||||
|
---
|
||||||
|
|
||||||
|
# External support available
|
||||||
|
|
||||||
|
## Purpose
|
||||||
|
|
||||||
|
External support is not required for SOC 2, but it enhances transparency by
|
||||||
|
showcasing your security practices, policies, and compliance efforts, building
|
||||||
|
trust with customers and stakeholders. - Ultimately, this is what SOC 2 is
|
||||||
|
about: reassuring your prospect and customer on how you work.
|
||||||
|
|
||||||
|
## Implementation
|
||||||
|
|
||||||
|
Create and maintain a complete list of support resources (eg. user guides,
|
||||||
|
technical documentation) for all your services.
|
||||||
|
|
||||||
|
Ensure easy access to those resources and keep them up to date.
|
||||||
|
|
||||||
|
## Evidence
|
||||||
|
|
||||||
|
- If not publicly available, drop a screenshot from your knowledge base showing
|
||||||
|
everything you cover (especially security)
|
||||||
|
- Link to your public documentation
|
||||||
BIN
controls/transparency/templates/security-page.png
Normal file
BIN
controls/transparency/templates/security-page.png
Normal file
Binary file not shown.
|
After Width: | Height: | Size: 461 KiB |
Reference in New Issue
Block a user