{"description":"Design-readiness review of the SOC 2 availability series: capacity management, environmental protections with backup and recovery infrastructure, and recovery plan testing (A1.1–A1.3). Design-readiness assessment limited to the listed SOC 2 criteria. Evidence may include operating examples to assess the design; this module does not provide a SOC 2 Type II opinion. Attach this workflow to the existing audit engagement item; retain evidence and conclusions on its workflow steps.","edges":[],"isPublic":true,"itemTypeSlug":"audit","metadata":{"capabilities":[],"configuration":["engagement_scope","applicable_criteria","review_period","responsible_roles","resource_reference_index"],"controlMappingQualification":"Links reflect the procedures and scoped criteria in this module; other requirements sharing a unified control remain outside its conclusion.","controlVerbs":{},"controls":["UC-BCDR-03","UC-BCDR-05","UC-BCDR-10"],"department":"internal-audit","domains":["audit"],"library":{"aliases":[],"canonicalUrl":"https://workflow-library.com/all/?w=audit-soc2-availability-assessment","contentDigest":"sha256:7983431d7321b998260992c652b92d70e13509f7bf8e704d755e882efb2c9f77","prerequisites":{"status":"undeclared"},"provenance":[],"releaseId":"sha256:7983431d7321b998260992c652b92d70e13509f7bf8e704d755e882efb2c9f77","schemaVersion":1,"sourceTemplateId":"workflow-library:audit-soc2-availability-assessment"},"lineOfDefense":"assure","mappingStatus":"mapped","risks":[],"scope":"Design-readiness assessment limited to the listed SOC 2 criteria. Evidence may include operating examples to assess the design; this module does not provide a SOC 2 Type II opinion.","slug":"audit-soc2-availability-assessment","source":"coworkcanvas-gallery","standards":["soc2"],"teams":["internal-audit"]},"name":"SOC 2 Availability Assessment","nodes":[{"data":{"controls":["UC-BCDR-10","UC-BCDR-03","UC-BCDR-05"],"description":"Evaluate A1.1–A1.3 capacity, backup and recovery-test design and approve the evidence-supported module conclusion with the original reviewer and sign-off requirements.","instructions":"**Objective**\nEvaluate A1.1–A1.3 capacity, backup and recovery-test design and approve the evidence-supported module conclusion with the original reviewer and sign-off requirements.\n\n**Inputs**\nBefore starting, attach the approved scope and applicable criteria, review-period dates, responsible-role assignments, and a resource-reference index identifying the existing subject item, policy versions, systems of record, linked controls and processes, and any upstream evidence packages. Resolve each generic resource reference against that index; record unavailable resources as gaps.\n\nThe assigned assessor evaluates evidence and drafts each conclusion; an independent engagement reviewer challenges sufficiency and conclusions. Management sign-off acknowledges findings and action ownership. The service auditor retains responsibility for any SOC opinion.\n\n- The linked consolidated controls for capacity management and backup\n- Capacity signals: the application hosting service scaling limits, quota headroom, and database capacity per customer environment\n- Backup configuration and restore-verification evidence for the window\n- The inherited-environmental position for the hosting provider facilities\n\nThe linked consolidated control for recovery testing and contingency training\n- Recovery test plan with cadence, scenarios, and success criteria\n- Results of the most recent restore or customer-environment rebuild exercise, with timings\n- Recovery objectives committed to customers\n\n**Procedure**\n*Agent retrieval, preparation and filing absorb “Assess Capacity Management & Recovery Infrastructure”; the responsible roles retain their judgments and all independent sign-offs within this checkpoint.*\n\n1. Assessment scope for Assess Capacity Management & Recovery Infrastructure: Assess A1.1 and A1.2: current processing capacity is maintained, monitored, and evaluated to manage demand, and environmental protections, software, data back-up processes, and recovery infrastructure are authorized, operated, and monitored. Evaluate capacity and backup responsibilities at the resource and customer boundaries defined in the service architecture.\n\n2. Verify capacity is monitored per customer environment with alerting before limits bite, and that quota or scaling changes follow the change process.\n3. Confirm demand planning exists for onboarding growth: provisioning a new tenant must not degrade existing ones.\n4. Inspect backup configuration for coverage, frequency, encryption, and retention, and verify restore verification actually ran in the window.\n5. Identify the environmental protections operated directly and those inherited from providers; verify attestation coverage for inherited controls and assign the residual monitoring duty.\n6. Record a design conclusion per criterion and log gaps as candidate findings.\n\n7. Assessment scope for Evaluate Recovery Plan Testing: Evaluate A1.3: the entity tests recovery plan procedures supporting system recovery. Availability commitments are only as good as the last successful exercise, so the design question is whether restore and rebuild procedures for customer environments are tested on a defined cadence with results measured against the committed recovery objectives.\n\n8. Verify a test cadence is defined and met, covering database restore and full customer-environment rebuild from infrastructure definitions.\n9. Inspect the latest exercise: scope, executed procedure, measured recovery time, and comparison against the committed objectives.\n10. Confirm failures or misses in the exercise produced corrective actions with owners and dates.\n11. Check the people dimension: more than one person can execute the recovery procedures, and the runbooks stand alone.\n12. Record a design conclusion for A1.3 and log gaps as candidate findings.\n\n**Record in AssureSwarm**\nAttach capacity dashboards, backup configuration, and restore-verification evidence to this step. Raise gaps as issues linked to the readiness audit and record both conclusions in the step record.\n\nAttach the test plan and exercise results to this step. Raise gaps as issues linked to the readiness audit and record the conclusion; single sign-off closes the series.\n\n**Exit criteria**\nA1.1 and A1.2 each carry a documented design conclusion supported by attached evidence, and every gap has a named owner and a target date. A1.3 carries a documented design conclusion supported by exercise evidence, and every recovery-testing gap has a named owner and a target date.","kind":"task","label":"Evaluate Recovery Plan Testing","performedBy":{"note":"Agent retrieves authorized evidence and prepares workpaper attachments. The assigned human assessor evaluates sufficiency and signs the conclusion.","primitives":["coach-query-data","coach-document-upload"]}},"id":"step-2"}],"sourceTemplateId":"workflow-library:audit-soc2-availability-assessment"}
