Jason Edwards

Framework - SOC 2 Compliance Course

Education EN ↓ 65 episodes

The **SOC 2 Compliance Audio Course** is your comprehensive, audio-first guide to understanding and implementing the Service Organization Control (SOC) 2 framework from the ground up. Designed for cybersecurity professionals, auditors, and business leaders, this course breaks down the American Institute of Certified Public Accountants (AICPA) Trust Services Criteria into clear, practical lessons that connect compliance theory with daily operational reality. Each episode explores essential concepts such as governance, risk assessment, security controls, and audit preparation—helping you underst...

Author

Jason Edwards

Category

Education

Podcast website

baremetalcyber.com

Latest episode

Oct 14, 2025

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Episode 15 — CC4 Commitments, SLAs, Regulatory Requirements 13.10.2025

CC4 focuses on whether an organization defines and meets commitments made to customers and regulators. It evaluates transparency, accountability, and compliance with service-level agreements (SLAs) and contractual or statutory obligations. The exam highlights the importance of translating business promises—such as uptime, data retention, or privacy guarantees—into measurable control objectives. Th...

Episode 14 — CC3 HR Lifecycle: Hiring, Training, Offboarding 13.10.2025

CC3 governs the human element of the control environment, ensuring that personnel are competent, trustworthy, and aware of their security responsibilities. It covers the entire employee lifecycle—background checks during hiring, role-based security training throughout employment, and structured offboarding when access must be revoked. Exam candidates should understand how these steps mitigate insi...

Episode 13 — CC2 Risk Assessment (Method & Cadence) 13.10.2025

CC2 addresses how an organization identifies, assesses, and manages risks to achieving its objectives. Effective risk assessment provides the context for prioritizing controls and ensuring proportional safeguards. The exam emphasizes the need for a defined methodology, documented risk register, and recurring review cadence. Inputs such as threat intelligence, incident history, and regulatory updat...

Episode 12 — CC1 Governance & Tone at the Top 13.10.2025

The first Common Criterion (CC1) focuses on governance and organizational culture—often summarized as “tone at the top.” It establishes the foundation for all other controls by ensuring leadership commitment, accountability, and ethical behavior. The exam expects familiarity with governance structures, board oversight, and management responsibility in establishing security policies. CC1 evaluates...

Episode 11 — How to Read a SOC 2 Report 13.10.2025

Interpreting a SOC 2 report requires understanding its structure and purpose. Each report includes an auditor’s opinion, system description, control testing results, and management assertions. The opinion letter clarifies whether controls were suitably designed and operated effectively during the review period. A clean, or “unqualified,” opinion indicates that no material exceptions were found, wh...

Episode 10 — CUECs Done Right 13.10.2025

Complementary User Entity Controls (CUECs) define what responsibilities customers or users must perform for the service organization’s controls to remain effective. They clarify shared accountability in outsourced or multi-tenant environments. On the exam, candidates should be able to identify CUECs as essential boundary statements—not optional disclosures. When done properly, CUECs prevent misint...

Episode 9 — Subservice Orgs: Inclusive vs Carve-Out 13.10.2025

SOC 2 engagements often depend on third-party providers—cloud platforms, payment processors, or data centers—known as subservice organizations. The inclusive versus carve-out distinction determines whether these providers’ controls are explicitly included within the system boundary or excluded but referenced through complementary user entity controls (CUECs). Inclusive reporting increases transpar...

Episode 8 — Writing the System Description 13.10.2025

The system description is the narrative foundation of a SOC 2 report. It defines the boundaries, components, services, infrastructure, and control environment in clear, auditable language. Examiners expect candidates to know its purpose: providing readers with context on what was evaluated and how it operates. A strong system description avoids marketing language and focuses on facts—locations, te...

Episode 7 — Type I vs Type II (and Bridge Letters) 13.10.2025

A fundamental SOC 2 distinction lies between Type I and Type II reports. Type I assesses the design of controls at a single point in time, confirming that policies and procedures are in place and suitably designed. Type II extends further, evaluating control effectiveness over a sustained period—usually six to twelve months—to determine consistent operation. Exam candidates must understand the sco...

Episode 6 — Program Roadmap & Realistic Timelines 13.10.2025

Building a SOC 2 program requires sequencing activities in a way that balances business priorities, risk reduction, and audit readiness. A structured roadmap outlines milestones such as scoping, control design, evidence collection, readiness assessment, and final audit execution. Unrealistic timelines are a frequent cause of failure—especially when leadership underestimates the effort required to...

Episode 5 — Control Ownership & RACI Across the Org 13.10.2025

SOC 2 success depends on clear control ownership across teams. Every control requires a defined Responsible, Accountable, Consulted, and Informed (RACI) structure to ensure consistency and accountability. Without it, audit evidence becomes fragmented, and responsibility for exceptions is unclear. Exam candidates should understand how assigning RACI roles prevents gaps in monitoring and ensures sus...

Episode 4 — Trust Services Criteria at a Glance 13.10.2025

The Trust Services Criteria (TSC) form the backbone of every SOC 2 report, defining the control objectives used to evaluate a system’s reliability. The five criteria—Security, Availability, Processing Integrity, Confidentiality, and Privacy—can be selectively included depending on customer needs. Security, also called Common Criteria, is mandatory and underpins the others. Each criterion aligns wi...

Episode 3 — Scoping: System Boundary, Services, Regions, Tenants 13.10.2025

Defining the SOC 2 scope is one of the most critical early steps. The “system” includes the services, infrastructure, software, people, and processes that support customer commitments. Poorly defined boundaries can inflate audit effort or miss key control areas. The exam emphasizes clarity between in scope and out of scope components—what’s controlled directly versus inherited from providers. Regi...

Episode 2 — Do You Need SOC 2 Now? Buyer & Contract Signals 13.10.2025

Determining when to pursue SOC 2 depends on business drivers, not curiosity. For many organizations, the trigger comes from customer requirements or procurement questionnaires where buyers demand proof of security controls through independent audit evidence. Early-stage companies often delay SOC 2 until revenue-critical contracts make it mandatory. Understanding these buyer and contract signals he...

Episode 1 — What SOC 2 Is (and Isn’t) 13.10.2025

SOC 2 is a framework developed by the American Institute of Certified Public Accountants (AICPA) to evaluate how well an organization manages customer data according to the Trust Services Criteria—Security, Availability, Processing Integrity, Confidentiality, and Privacy. It is not a law, certification, or one-size-fits-all checklist but an attestation based on evidence and control operation over...

Listen to the Framework - SOC 2 Compliance Course podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.