Question

In: Accounting

Write a proposal to pursue the SOC 2 Type II compliance. Please be sure that your...

Write a proposal to pursue the SOC 2 Type II compliance. Please be sure that your proposal meets all the following requirements:

Explains the differences between SANS and SOC compliance

Provides rational as to why SOC 2 was chosen for XYZ Technologies.

Gives a timeline for when the project will begin and end, also including the major milestones along the way.

Solutions

Expert Solution

SANS COMPLIANCES:-

SANS 20 security controls laid down the most crucial security controls that the organisation should implement in its working to prevent the overall risk of data breach.

as per the various organisations, if these controls were implemented in an organisation,94% of the risks pertaining to the security would be mitigated.

while all the sans controls are important from the point of view of an organiation there arte two security controls that are often misused, or not implemented correctly:-

1.continuous vulnerability assesment and remediation

2.penetration testing and red team exercises.

SOC COMPLIANCES:-

SERVICE ORGANIZATION CONTROL(SOC) COMPLIANCES is an audit of internal controls to ensure security of data, minimal wastage of resources and confidence of shareholders of confidence at large.

this compliance helps the auditors in sucha way that it reduces the audit time of auditor becauseSOC reports cover a strong report on internal audit of an organisation thereby reducing the costs of auditor at large.

users of SOC services are as follows:-

any organisation who cannot afford to lose their confidential data,banks and investment houses, data centers ,etc.

WHY SOC 2 WAS CHOSEN FOR XYZ TECHNOLOGIES?

because it covers the areas such as processing integrity, security,confidentiality of controls present at the organisation.

offer great assurance to customers and stakeholders associated with the organisation at large compared to theSANS reports


Related Solutions

Type I and Type II Errors . Please discuss Type I and Type II errors. What...
Type I and Type II Errors . Please discuss Type I and Type II errors. What are they? Discuss their relationship with hypothesis testing. Answer all parts of question!!! Do not plagiarize!! Write out the answer on here, don't post a picture of it! Answer must be long!
Be sure to write clear steps for your derivations Explain MM Proposition I and II for...
Be sure to write clear steps for your derivations Explain MM Proposition I and II for capital structure. Provide some examples of the costs and benefits associated with debt and equity under market imperfections, and explain the concept of optimal capital structure.
Please label and write clearly. Please make sure to circle the answers Problem 2. We now...
Please label and write clearly. Please make sure to circle the answers Problem 2. We now wish to decide if there “use of e-cigarettes” and “income category” are dependent. To assist with this process, the table from before has been augmented with most of the expected frequencies (listed in parentheses): <$35,000 $35,000-$99,999 $100,000+ Total Vape 47 (34) 57 (58) 19 (31) 123 Do Not Vape 381 (394) 659 (???) 362 (???) 1402 Total 428 716 381 1525 a. Find the...
Solve the below questions using your own words PLEASE!! Make sure to write by your own...
Solve the below questions using your own words PLEASE!! Make sure to write by your own words or paraphrase 1. What is the difference between Windows and Linux server 2. Give some advantages and disadvantages Windows and Linux Operating System
Please provide an example of both a Type I Error and Type II Error. Why is...
Please provide an example of both a Type I Error and Type II Error. Why is it that increasing the sample size reduces the probability of a Type II error to an acceptable level. Please discuss.
Please post a rough draft of your Research Proposal
Please post a rough draft of your Research Proposal
Please explain your view of the most difficult aspect of Customs Compliance?
Please explain your view of the most difficult aspect of Customs Compliance?
Explain Type I and Type II errors in detail ( with example of your choice). Define...
Explain Type I and Type II errors in detail ( with example of your choice). Define level of significance and p Values. Interpret P-value of 0.023 in Hypothesis testing in general.
3) How do your values factor into the type of job or career you pursue? 4)...
3) How do your values factor into the type of job or career you pursue? 4) Do you take into consideration the culture of an organization when deciding to work there?
Does Protein Really Curb Your Appetite? ( PLEASE TYPE OUT NOT HAND WRITE)
Does Protein Really Curb Your Appetite? ( PLEASE TYPE OUT NOT HAND WRITE)
ADVERTISEMENT
ADVERTISEMENT
ADVERTISEMENT