Jason Edwards

Framework - SOC 2 Compliance Course

Education EN ↓ 65 episodes

The **SOC 2 Compliance Audio Course** is your comprehensive, audio-first guide to understanding and implementing the Service Organization Control (SOC) 2 framework from the ground up. Designed for cybersecurity professionals, auditors, and business leaders, this course breaks down the American Institute of Certified Public Accountants (AICPA) Trust Services Criteria into clear, practical lessons that connect compliance theory with daily operational reality. Each episode explores essential concepts such as governance, risk assessment, security controls, and audit preparation—helping you underst...

Author

Jason Edwards

Category

Education

Podcast website

baremetalcyber.com

Latest episode

Oct 14, 2025

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Episode 40 — Fieldwork Do’s & Don’ts; Request Lists & Walkthroughs 14.10.2025

Fieldwork is the active phase of the SOC 2 audit when auditors test controls, review evidence, and conduct walkthroughs. The exam expects familiarity with the rhythm: request list issuance, evidence submission, clarifications, and interviews. “Do’s” include organizing artifacts before requests arrive, validating timeframes, and rehearsing walkthroughs with control owners. “Don’ts” include submitti...

Episode 39 — Readiness Assessments & Gap Closure 14.10.2025

A readiness assessment bridges the gap between current state and audit expectations. It is a dry run designed to identify deficiencies in design, documentation, or operation before formal examination begins. The exam expects you to outline its purpose: reduce audit risk, clarify scope, and build a prioritized remediation plan. The assessment reviews policies, control narratives, evidence repositor...

Episode 38 — Selecting the CPA Firm & Independence 14.10.2025

Choosing the right Certified Public Accountant (CPA) firm is critical because SOC 2 is an attestation engagement requiring auditor independence. The exam expects you to know that the firm must be licensed, subject to peer review, and experienced in SOC examinations under AICPA standards. Independence means the auditor cannot design or operate your controls, provide management services, or have fin...

Episode 37 — Policy-to-Practice Traceability (Text → Proof → Tests) 14.10.2025

Policy-to-practice traceability connects written commitments to measurable evidence. The exam will expect you to map a control statement from the policy, through its implementation procedure, to the proof and corresponding test result. This linkage ensures that every “shall” or “must” in documentation is supported by a verifiable control, and that every test can trace back to a stated requirement....

Episode 36 — CI/CD & Cloud Proofs: Pipelines, Baselines, Diffs 14.10.2025

Continuous Integration and Continuous Deployment (CI/CD) pipelines are now central to SOC 2 evidence collection because they record how code and infrastructure move from development to production. The exam expects you to explain how build pipelines, infrastructure baselines, and configuration diffs demonstrate both control operation and change discipline. Each commit, pull request, and merge appro...

Episode 35 — Audit-Ready Logs & Screenshots: Accept vs Reject 14.10.2025

Audit-ready evidence depends on provenance, completeness, and repeatability. Logs should originate from systems of record, be time-synchronized, and retained immutably for the audit period. For the exam, differentiate acceptable artifacts—exported reports with filters documented, log extracts showing unique IDs and timestamps, configuration states pulled via API—from weak artifacts like unlabeled...

Episode 34 — Ticketing as Evidence (Approvals, Change, Incidents) 14.10.2025

Ticketing systems provide the audit backbone for approvals, changes, incidents, and exceptions, turning ephemeral conversations into durable records. The exam will expect you to tie SOC 2 controls to specific ticket fields: requester, approver, timestamps, risk classification, test results, and closure notes. Strong implementations standardize templates so a reviewer can verify that required steps...

Episode 33 — Continuous Control Monitoring & Automation 14.10.2025

Continuous control monitoring (CCM) converts periodic, manual checks into automated, near-real-time assurance. For the exam, be prepared to explain how CCM maps control objectives to measurable signals—metrics, events, and thresholds—captured from systems of record such as IAM, cloud configuration, CI/CD, and endpoint management. Automation enforces policy-as-code and reduces human error, while da...

Episode 32 — Evidence Strategy & Sampling for Type II 14.10.2025

Type II reports evaluate operating effectiveness over time, so your evidence strategy must prove consistency, not isolated success. The exam expects fluency with defining populations (for example, all change tickets between specific dates), selecting statistically or judgmentally appropriate samples, and preserving chain-of-custody for artifacts. Good strategy starts with a calendar that aligns co...

Episode 31 — Strong Control Narratives: Before/After Examples 14.10.2025

A strong control narrative translates policy intent into the specific, routine actions a team performs, expressed in clear, testable language. For exam readiness, understand that narratives must answer who performs the control, what system or dataset it affects, when and how often it runs, and how results are evidenced and escalated. Weak narratives rely on vague phrases like “as needed” or “perio...

Episode 30 — Cloud & Multitenant Edge Cases (Scope, Tenancy, Regions) 14.10.2025

Cloud-native and multitenant architectures introduce scoping complexities that the exam will expect you to navigate precisely. Define the “system” to include services, infrastructure-as-code, managed platforms, and shared components that affect commitments. Tenancy models—single-tenant, pooled multi-tenant, or hybrid—change risk profiles for data isolation, noisy-neighbor effects, and blast radius...

Episode 29 — Evidence for A/C/PI/P: What “Good” Looks Like 14.10.2025

Auditors evaluate whether controls for Availability, Confidentiality, Processing Integrity, and Privacy are designed and operating effectively, so your evidence must be relevant, complete, and reliable. “Good” evidence ties a stated control to a dated sample that demonstrates performance over the period. For Availability, think DR test plans, results, and remediation tickets with timestamps; for C...

Episode 28 — Privacy in Context: SOC 2 vs ISO 27701 vs HIPAA 14.10.2025

This episode situates SOC 2 Privacy alongside ISO/IEC 27701 and HIPAA so you can compare scope, obligations, and evidence expectations. SOC 2 is an attestation over your system against Trust Services Criteria, including Privacy, and is adaptable across industries. ISO 27701 extends ISO 27001 with a privacy information management system, prescribing requirements and guidance for roles like controll...

Episode 27 — Privacy: Notice, Rights, DPIAs, Retention, DSRs 14.10.2025

Under the SOC 2 Privacy criterion, organizations must show that personal information is collected, used, retained, disclosed, and disposed of in accordance with commitments and applicable regulations. The exam expects you to connect privacy program elements to operational controls: clear, accessible privacy notices; mechanisms to capture and honor consent or lawful bases; and procedures to support...

Episode 26 — Processing Integrity: Accuracy/Completeness/Monitoring 13.10.2025

Processing Integrity in SOC 2 focuses on whether systems deliver the right results at the right time for the right reasons, emphasizing accuracy, completeness, validity, timeliness, and authorization. For exam purposes, you should be able to explain how business rules, input validation, transformation logic, and output controls work together to prevent and detect errors. Accuracy means calculation...

Episode 25 — Confidentiality: Classification, Encryption, DLP 13.10.2025

Confidentiality ensures that sensitive information is protected from unauthorized disclosure. The exam focuses on how organizations identify, classify, and safeguard data based on sensitivity. Classification frameworks define what data is public, internal, or confidential, guiding appropriate handling. Encryption protects data in transit and at rest, while Data Loss Prevention (DLP) technologies d...

Episode 24 — Availability: Capacity, DR, RTO/RPO, Game-Days 13.10.2025

Availability is one of the Trust Services Criteria most closely tied to operational resilience. It ensures that systems meet uptime commitments and can recover from disruptions within defined tolerances. The exam highlights concepts like capacity management, Disaster Recovery (DR) planning, and recovery objectives—RTO (Recovery Time Objective) and RPO (Recovery Point Objective). Capacity planning...

Episode 23 — CC12 Physical/Environmental & Remote-First Realities 13.10.2025

CC12 governs physical and environmental safeguards—controls that protect systems from unauthorized access, damage, or environmental hazards. Traditionally, this meant data centers, offices, and server rooms. However, the rise of remote and hybrid work models has transformed CC12’s application. The exam now emphasizes how organizations adapt controls for distributed workforces while maintaining evi...

Episode 22 — CC11 Vendor Risk & Subservice Oversight 13.10.2025

CC11 addresses how organizations manage risks associated with third-party vendors and subservice providers. It requires structured due diligence, contract management, and ongoing monitoring to ensure external parties meet the same security and compliance standards as internal operations. The exam expects familiarity with how SOC 2 integrates with vendor management programs, emphasizing inherited a...

Episode 21 — CC10 Data Integrity in Pipelines 13.10.2025

CC10 ensures that information processed within systems remains accurate, complete, and valid throughout its lifecycle. It focuses on maintaining data integrity from input to output, particularly in automated or multi-stage processing pipelines. The exam highlights that controls must detect, prevent, and correct errors before they propagate downstream. Examples include input validation, reconciliat...

Episode 20 — CC9 Incident Management & Communications 13.10.2025

CC9 covers how organizations prepare for, detect, respond to, and communicate security incidents. The exam emphasizes structured processes that define roles, escalation paths, and notification requirements. Effective incident management limits damage and maintains trust with customers and regulators. The plan should outline detection mechanisms, classification levels, and response timelines aligne...

Episode 19 — CC8 Change Management & SDLC (incl. IaC Basics) 13.10.2025

CC8 evaluates how organizations manage system changes to prevent unintended disruption or new vulnerabilities. It covers structured change management processes, Software Development Lifecycle (SDLC) controls, and increasingly, Infrastructure as Code (IaC). The exam focuses on documentation, approval workflows, segregation of duties, and testing requirements before deployment. Change control ensure...

Episode 18 — CC7 Ops: Config Management, Vulnerability Mgmt, Patching 13.10.2025

CC7 governs how organizations maintain secure, reliable operations through configuration management, vulnerability management, and patching. The exam tests understanding of how operational hygiene translates into risk reduction. Configuration management ensures systems remain consistent with approved baselines; vulnerability management identifies and prioritizes risks through scanning and threat i...

Episode 17 — CC6 Logical Access: IAM, SSO, MFA, JML 13.10.2025

CC6 focuses on logical access—ensuring that only authorized individuals can interact with systems and data. It encompasses Identity and Access Management (IAM), Single Sign-On (SSO), Multi-Factor Authentication (MFA), and Joiner–Mover–Leaver (JML) processes. The exam expects understanding of how these components enforce least privilege and separation of duties. IAM defines identity lifecycle gover...

Episode 16 — CC5 Control Design, Reviews, and Monitoring 13.10.2025

CC5 addresses how controls are designed, implemented, and monitored for continued effectiveness. The exam expects you to understand the full lifecycle—from establishing control objectives that align with risks to ensuring management reviews validate their operation. Well-designed controls must be precise, measurable, and repeatable. They are ineffective if overly broad or disconnected from busines...

Listen to the Framework - SOC 2 Compliance Course podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.