This course provides a comprehensive overview of SOC 2 reports, focusing on their structure, purpose, and how to interpret and apply them in a compliance or risk management context. Participants will learn about the five Trust Services Criteria (Security, Availability, Processing Integrity, Confidentiality, and Privacy), the difference between Type I and Type II reports, and the key components of a SOC 2 report including the system description, management assertion, and testing results. The course also covers common pitfalls in relying on SOC 2 reports and best practices for evaluating scope, subservice providers, and complementary user controls. Designed for auditors, compliance professionals, and vendor risk reviewers, this session equips attendees to effectively analyze and apply SOC 2 reports in real-world scenarios. This event may be a rebroadcast of a live event and the instructor will be available to answer your questions during the event.
Learning Objectives
After attending this presentation, you will be able to...
- Identify the purpose of SOC 2 reports and the types of SOC 2 reports.
- Identify the Trust Services Criteria and recognize when each criterion is applicable.
- Identify the structure and contents of a SOC 2 report.
- Recognize common use cases for a SOC 2 report.
Major Topics
The major topics that will be covered in this course include:
- Comprehensive overview of SOC 2 reports, focusing on their structure, purpose, and how to interpret and apply them in a compliance or risk management context.
- The five Trust Services Criteria (Security, Availability, Processing Integrity, Confidentiality, and Privacy).
- The difference between Type I and Type II reports.
- The key components of a SOC 2 report including the system description, management assertion, and testing results.