Our Approach and Methodology
In today’s marketplace, with the number of breaches on the rise, it’s
important that organizations ensure that their 3rd party service providers
are maintaining a level of security and privacy with regards to their
customer information. One way to do this is to only use service providers
that have had an unbiased 3rd party audit performed which examines,
documents, and tests internal controls within the service provider
organization.
SecureState’s approach to an SSAE 16/AT 101 SOC 1, SOC 2, and SOC 3 Gap
Assessment/Pre-Audit maps out critical information processes and determines
if regulatory controls have an impact on the business. SecureState can
provide assistance as well as perform a Gap Assessment on the 3 new auditing
standards. The goals are to ensure that there are no surprises during the
formal audit; as well as:
- Efficiently execute your SSAE 16/AT 101 program
- Determine what Reporting requirements are appropriate for your
organization i.e SOC1, SOC2 and/or SOC3.
- Either help build or determine the appropriate controls for your
SOC1 engagement or help Interpret the Trust Services Criteria control
requirements for SOC2 /SOC3 and get answers for you quickly
- Remediation cost-justification
The stages of our SSAE 16/AT 101 Gap Assessment/Pre-Audit, with
limited descriptions, are as follows:
Pre-Onsite Visit:
- Introduce engagement participants and define roles
- Review engagement activities
- Review any applicable documentation
Process Mapping:
- Document the high level business process and supporting technologies
- Perform data flow analysis and map processes to technical
infrastructure
Requirements Analysis:
- Document the existing controls
- Identify gaps against the appropriate reporting requirements
Reporting:
- On-site interview and information gathering to assess SOC 1, SOC2,
and/or SOC3 status
- Outline strategic recommendations to mitigate identified control
gaps
- Upload remediation activities to “MyState Portal”