{"description":"Design-readiness review of the SOC 2 confidentiality series: identification and maintenance of confidential information and its secure disposal at end of life (C1.1–C1.2). Design-readiness assessment limited to the listed SOC 2 criteria. Evidence may include operating examples to assess the design; this module does not provide a SOC 2 Type II opinion. Attach this workflow to the existing audit engagement item; retain evidence and conclusions on its workflow steps.","edges":[],"isPublic":true,"itemTypeSlug":"audit","metadata":{"capabilities":[],"configuration":["engagement_scope","applicable_criteria","review_period","responsible_roles","resource_reference_index"],"controlMappingQualification":"Links reflect the procedures and scoped criteria in this module; other requirements sharing a unified control remain outside its conclusion.","controlVerbs":{},"controls":["UC-ASSET-03","UC-DATA-09"],"department":"internal-audit","domains":["audit"],"library":{"aliases":[],"canonicalUrl":"https://workflow-library.com/all/?w=audit-soc2-confidentiality-assessment","contentDigest":"sha256:2b53c083aeda413a08ab84f0003e32b08689327edd594b9f442805aae092b899","prerequisites":{"status":"undeclared"},"provenance":[],"releaseId":"sha256:2b53c083aeda413a08ab84f0003e32b08689327edd594b9f442805aae092b899","schemaVersion":1,"sourceTemplateId":"workflow-library:audit-soc2-confidentiality-assessment"},"lineOfDefense":"assure","mappingStatus":"mapped","risks":[],"scope":"Design-readiness assessment limited to the listed SOC 2 criteria. Evidence may include operating examples to assess the design; this module does not provide a SOC 2 Type II opinion.","slug":"audit-soc2-confidentiality-assessment","source":"coworkcanvas-gallery","standards":["soc2"],"teams":["internal-audit"]},"name":"SOC 2 Confidentiality Assessment","nodes":[{"data":{"controls":["UC-DATA-09","UC-ASSET-03"],"description":"Evaluate C1.1–C1.2 confidential-information identification, maintenance and disposal and approve the evidence-supported module conclusion with the original reviewer and sign-off requirements.","instructions":"**Objective**\nEvaluate C1.1–C1.2 confidential-information identification, maintenance and disposal and approve the evidence-supported module conclusion with the original reviewer and sign-off requirements.\n\n**Inputs**\nBefore starting, attach the approved scope and applicable criteria, review-period dates, responsible-role assignments, and a resource-reference index identifying the existing subject item, policy versions, systems of record, linked controls and processes, and any upstream evidence packages. Resolve each generic resource reference against that index; record unavailable resources as gaps.\n\nThe assigned assessor evaluates evidence and drafts each conclusion; an independent engagement reviewer challenges sufficiency and conclusions. Management sign-off acknowledges findings and action ownership. The service auditor retains responsibility for any SOC opinion.\n\n- The linked consolidated control for classification and labeling\n- Classification scheme with handling requirements per level\n- Data inventory mapping confidential information to systems and owners\n- Confidentiality commitments in customer terms and workforce agreements\n\nThe linked consolidated control for retention and destruction\n- Retention schedule with disposal triggers per information class\n- Tenant teardown procedure and records for any decommissioned customer environments\n- Backup expiry configuration and destruction evidence for the window\n\n**Procedure**\n*Agent retrieval, preparation and filing absorb “Assess Identification & Maintenance of Confidential Information”; the responsible roles retain their judgments and all independent sign-offs within this checkpoint.*\n\n1. Assessment scope for Assess Identification & Maintenance of Confidential Information: Assess C1.1: the entity identifies and maintains confidential information to meet its confidentiality objectives. For the scoped service that spans customer workflow data inside each scoped customer environment, credentials and keys, and corporate records - each needing classification, labeling, and handling proportionate to its sensitivity.\n\n2. Verify the classification scheme defines levels, handling rules, and ownership, and that it was applied to the data inventory rather than existing in the abstract.\n3. Confirm customer data is identified as confidential by default and its locations are known: customer databases, backups, and any diagnostic copies.\n4. Check handling practice for the highest-sensitivity classes - credentials, keys, and customer content - matches the declared requirements.\n5. Verify confidentiality obligations bind the workforce and advisors through signed agreements.\n6. Record a design conclusion for C1.1 and log gaps as candidate findings.\n\n7. Assessment scope for Evaluate Confidential Information Disposal: Evaluate C1.2: the entity disposes of confidential information to meet its confidentiality objectives. The critical path is tenant offboarding - teardown of a decommissioned customer environment must remove live data, backups, and residual copies on schedule - alongside routine retention-driven deletion in corporate systems.\n\n8. Verify the retention schedule assigns each confidential information class a retention limit and a disposal method.\n9. Walk the customer-environment teardown procedure: project deletion, backup expiry, and confirmation that no residual copies survive outside the destroyed project.\n10. Confirm backup expiry actually enforces the schedule and produced destruction evidence during the window.\n11. Check disposal events are recorded with date, scope, and approver, providing the audit trail behind customer attestations.\n12. Record a design conclusion for C1.2 and log gaps as candidate findings.\n\n**Record in AssureSwarm**\nAttach the classification scheme and data inventory extract to this step. Raise gaps as issues linked to the readiness audit and record the conclusion in the step record.\n\nAttach the retention schedule, teardown records, and destruction evidence to this step. Raise gaps as issues linked to the readiness audit and record the conclusion; single sign-off closes the series.\n\n**Exit criteria**\nC1.1 carries a documented design conclusion supported by attached evidence, and every classification gap has a named owner and a target date. C1.2 carries a documented design conclusion supported by attached evidence, and every disposal gap has a named owner and a target date.","kind":"task","label":"Evaluate Confidential Information Disposal","performedBy":{"note":"Agent retrieves authorized evidence and prepares workpaper attachments. The assigned human assessor evaluates sufficiency and signs the conclusion.","primitives":["coach-query-data","coach-document-upload"]}},"id":"step-2"}],"sourceTemplateId":"workflow-library:audit-soc2-confidentiality-assessment"}
