workflow
SOC 2 Trust Services Readiness
Runs on the existing Audit engagement with its system description, service commitments, review period, control and risk registers, and available evidence; assesses CC1–CC9 design readiness and consumes reviewed companion assessments for selected optional Trust Services categories. Delivers the criterion-to-control mapping, criterion-level evidence and design conclusions, owned gap register, and approved SOC 2 readiness disposition to management for remediation and examination planning; Type II testing, management-owned PBC preparation and management assertion remain separate workflows.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- audit
- department
- internal-audit
- lineOfDefense
- assure
Details
- teams
- internal-audit
- domains
- audit
- standards
- soc2
- sourceTemplateId
- workflow-library:audit-soc2-readiness-disposition
- releaseId
- sha256:14f2f6568cafdb682d7dafdf0ff401fe56649c1307c627ad67aa0c432bf095ed
- canonicalUrl
- https://workflow-library.com/all/?w=audit-soc2-readiness-disposition
- capabilities
- soc2-readiness
- mappingStatus
- mapped
- lineOfDefense
- assure
- controls
- UC-ACCESS-01
- UC-ACCESS-03
- UC-ASSET-01
- UC-ASSET-04
- UC-AUDIT-13
- UC-AUDIT-25
- UC-CONFIG-01
- UC-CONFIG-02
- UC-CONFIG-05
- UC-CRYPTO-01
- UC-GOV-04
- UC-GOV-05
- UC-GOV-06
- UC-GOV-07
- UC-GOV-14
- UC-GOV-16
- UC-GOV-21
- UC-GOV-34
- UC-HR-06
- UC-IR-06
- UC-IR-09
- UC-LOG-04
- UC-LOG-06
- UC-NET-01
- UC-PHYS-01
- UC-RISK-04
- UC-RISK-06
- UC-RISK-11
- UC-RISK-12
- UC-RISK-13
- UC-RISK-14
- UC-TPRM-02
- roleIntegrity
- activityCount
- 1
- ermPhases
- report
- lineRoles
- third
- serviceModes
- assurance
- warnings
Source
No record-specific source URL is provided.
Download workflow template · Release: sha256:14f2f6568cafdb682d7dafdf0ff401fe56649c1307c627ad67aa0c432bf095ed
Connections
- SOC 2 Trust Services Readiness tests UC-CONFIG-01 — Harden systems to approved secure configuration baselines
- SOC 2 Trust Services Readiness tests UC-RISK-04 — Define objectives and business context for risk assessment
- SOC 2 Trust Services Readiness tests UC-AUDIT-13 — Gather and analyze evidence to develop engagement findings
- SOC 2 Trust Services Readiness tests UC-CONFIG-05 — Permit only authorized software installation and use
- SOC 2 Trust Services Readiness tests UC-ASSET-01 — Maintain a complete inventory of systems, hardware, and software
- SOC 2 Trust Services Readiness tests UC-ASSET-04 — Control storage media through use, storage, and destruction
- SOC 2 Trust Services Readiness tests UC-NET-01 — Segment networks and defend the external boundary
- SOC 2 Trust Services Readiness tests UC-GOV-21 — Communicate and report risk and control information
- SOC 2 Trust Services Readiness tests UC-HR-06 — Embed security and competence in HR practices
- SOC 2 Trust Services Readiness tests UC-GOV-16 — Select and tailor a risk-based control baseline
- SOC 2 Trust Services Readiness tests UC-GOV-04 — Set tone at the top: integrity, ethics, and risk-aware culture
- SOC 2 Trust Services Readiness tests UC-CRYPTO-01 — Encrypt data at rest and in transit
- SOC 2 Trust Services Readiness tests UC-RISK-13 — Monitor and review risk management performance
- SOC 2 Trust Services Readiness tests UC-RISK-11 — Assess changes that could significantly affect risk and control
- SOC 2 Trust Services Readiness tests UC-RISK-06 — Perform periodic enterprise risk assessments
- SOC 2 Trust Services Readiness tests UC-ACCESS-03 — Enforce least privilege, need-to-know, and segregation of duties
- SOC 2 Trust Services Readiness tests UC-LOG-04 — Continuously monitor systems for anomalous activity
- SOC 2 Trust Services Readiness tests UC-GOV-05 — Ensure board-level oversight of risk and internal control
- SOC 2 Trust Services Readiness tests UC-GOV-07 — Hold individuals accountable for control responsibilities
- SOC 2 Trust Services Readiness tests UC-IR-09 — Recover from incidents using defined initiation criteria
- SOC 2 Trust Services Readiness tests UC-RISK-12 — Assess and mitigate fraud risk including management override
- SOC 2 Trust Services Readiness tests UC-ACCESS-01 — Provision and deprovision accounts through a managed lifecycle
- SOC 2 Trust Services Readiness tests UC-LOG-06 — Evaluate events and declare incidents against defined criteria
- SOC 2 Trust Services Readiness tests UC-RISK-14 — Track deficiencies to closure with remediation action plans
- SOC 2 Trust Services Readiness tests UC-AUDIT-25 — Maintain quality records and information for internal control
- SOC 2 Trust Services Readiness tests UC-IR-06 — Respond to, contain, and eradicate declared incidents
- SOC 2 Trust Services Readiness tests UC-GOV-34 — Maintain business continuity and contingency planning policy
- SOC 2 Trust Services Readiness tests UC-CONFIG-02 — Authorize, test, and approve changes before production
- SOC 2 Trust Services Readiness tests UC-GOV-14 — Establish and maintain approved security policies and procedures
- SOC 2 Trust Services Readiness tests UC-PHYS-01 — Restrict physical access to facilities and secure areas
- SOC 2 Trust Services Readiness tests UC-TPRM-02 — Perform risk-based due diligence before engaging vendors
- SOC 2 Trust Services Readiness tests UC-GOV-06 — Define security roles, responsibilities, and authorities