Service Organization Control (SOC) Reports Focus on SOC 2 Reporting Standard



Similar documents
Service Organization Control (SOC) Reports

SSAE 16 for Transportation & Logistics Companies. Chris Kradjan Kim Koch

Service Organization Control Reports

Effectively using SOC 1, SOC 2, and SOC 3 reports for increased assurance over outsourced operations. kpmg.com

Information for Management of a Service Organization

Goodbye, SAS 70! Hello, SSAE 16!

Service Organization Controls. Managing Risks by Obtaining a Service Auditor s Report

Orchestrating the New Paradigm Cloud Assurance

Third Party Risk Management 12 April 2012

SERVICE ORGANIZATION CONTROL REPORTS SM. Formerly SAS 70 Reports

The Changing SAS 70 Landscape Dan Hirstein Director Rebecca Goodpasture Senior Manager Deloitte & Touche LLP January 13, 2011

SSAE 16 Everything You Wanted To Know But Are Afraid To Ask. Kurt Hagerman CISA, CISSP, QSA Managing Director, Coalfire December 8, 2011

Service Organization Controls. Managing Risks by Obtaining a Service Auditor s Report

Cybersecurity and the AICPA Cybersecurity Attestation Project

SECURITY AND EXTERNAL SERVICE PROVIDERS

SAS No. 70, Service Organizations

Understanding SOC Reports for Effective Vendor Management. Jason T. Clinton January 26, 2016

Third Party Security: Are your vendors compromising the security of your Agency?

Vendor Management Best Practices

FAQs New Service Organization Standards and Implementation Guidance

Service Organization Control (SOC) reports What are they?

Cybersecurity The role of Internal Audit

U.S. CFO Program The Four Faces of the CFO Deloitte Touche Tohmatsu

ERP Administrative Challenges Brian Jensen

HITRUST CSF Assurance Program

Hot Topics in IT. CUAV Conference May 2012

SOC Readiness Assessments. SOC Report - Type 1. SOC Report - Type 2. Building Trust and Confidence in Third-Party Relationships

Asset Manager Guide to SAS 70. Issue Date: October 7, Asset

ISAE 3402 and SSAE 16 (replacing SAS 70) Reinforcing confidence through demonstration of effective controls

SOC on Amazon Web Services (AWS) What You Need To Know Understanding the regulatory roadmap for SOC on AWS

Impact of New Internal Control Frameworks

Ayla Networks, Inc. SOC 3 SysTrust 2015

Cloud Computing What Auditors need to know

Division of Insurance Internal Control Questionnaire For the period July 1, 2013 through June 30, 2014

COSO Internal Control Integrated Framework (2013)

Key Cyber Risks at the ERP Level

Understanding changes to the Trust Services Principles for SOC 2 reporting

Understanding ISO and Preparing for the Modern Era of Cloud Security

TO: Chief Executive Officers of National Banks, Federal Branches and Data-Processing Centers, Department and Division Heads, and Examining Personnel

3 rd Party Vendor Risk Management

Third party assurance services

Shared Service System Audits: What User Management and Auditors Need to Know

SECTION I INDEPENDENT SERVICE AUDITOR S REPORT

Dan T. Stathos, CPA* Associate Director

Virginia Commonwealth University School of Medicine Information Security Standard

Microsoft s Compliance Framework for Online Services

SSAE 16 & SAS 70 A Primer on Changes to Service Organization Audit Standards

VENDOR MANAGEMENT. General Overview

Risk Management of Outsourced Technology Services. November 28, 2000

How mature is the internal control framework at your service organisation? ISAE 3402 and SSAE 16: Reinforcing confidence through demonstration of

Consolidated Audit Program (CAP) A multi-compliance approach

Deloitte Analytics. Trusting big data: Perspective on data governance as a customer analytics investment

Weighing in on the Benefits of a SAS 70 Audit for Third Party Data Centers

Risk Considerations for Internal Audit

Developing Your Strategic Plan

Effective Monitoring of Outsourced Plan Recordkeeping and Reporting Functions

Managing risks in a Salesforce environment

Weighing in on the Benefits of a SAS 70 Audit for Payroll Service Providers

VISP Vendor Information Security Plan: A tool for IT and Institutions to evaluate third party vendor capacity and technology to protect research data

Securing the Microsoft Cloud

COSO s 2013 Internal Control Framework in Depth: Implementing the Enhanced Guidance for Internal Control over External Financial Reporting

The Changing IT Risk Landscape Understanding and managing existing and emerging risks

February Sample audit committee charter

Security Controls What Works. Southside Virginia Community College: Security Awareness

Hedge fund launch considerations Reaching new boundaries. Investment Management

CSA Position Paper on AICPA Service Organization Control Reports

FINAL May Guideline on Security Systems for Safeguarding Customer Information

APES GN 30 Outsourced Services

A Flexible and Comprehensive Approach to a Cloud Compliance Program

The Emergence of the ISO in Community Banking Patrick H. Whelan CISA IT Security & Compliance Consultant

Security Information Lifecycle

Cloud Computing An Auditor s Perspective

PCI Compliance and the Cloud: What You Can and What You Can t Outsource Presented By:

Guide to the Sarbanes-Oxley Act: IT Risks and Controls. Frequently Asked Questions

Vendor Management Compliance Top 10 Things Regulators Expect

Frequently asked questions: SOC 2 and 3

DEVELOPING A CYBERSECURITY POLICY ARCHITECTURE

February Audit committee performance evaluation

IAASB Main Agenda (June 2010) Agenda Item. April 28, 2009

Asset Management in the Cloud How to identify and manage Cloud based assets and services. September 19, 2014

Understanding SAS 70 Reports on Internal Control

Preparing yourself for ISO/IEC

Does Providing Tax Services Impair Auditor Independence? Evidence from Assessing Tax Accrual Quality

Program Overview. CDP is a registered certification designed and administered by Identity Management Institute (IMI).

Top 10 Compliance Issues for Implementing Security Programs

Transcription:

Information Systems Audit and Controls Association Service Organization Control (SOC) Reports Focus on SOC 2 Reporting Standard February 4, 2014 Tom Haberman, Principal, Deloitte & Touche LLP Reema Singh, Senior Manager, Deloitte & Touche LLP

Agenda Overview of Service Organization Control (SOC) reports Overview of SOC 2 reports SOC 2 reports industry application 1 Information Systems Audit and Controls Association

Overview of a Service Organization Control (SOC) report

What is a Service Organization Control (SOC) report? What is a SOC report? So what does this mean? What is a SOC 2 report? What are a few examples of SOC 2 reports? Service Organization Controls reports are designed to help service organizations, organizations that operate information systems and provide information system services to other entities, build trust and confidence in their service delivery processes and controls through a report by an independent certified public accountant. 1 SOC reports cover situations where one company outsources some portion of their business or technology to another company. SOC 2 reports are an examination engagement to report on controls at a service organization intended to mitigate risks related to security, availability, processing integrity, confidentiality, or privacy (trust services principles). Examples of service providers where a SOC 2 report might be relevant include cloud computing, customer call centers, enterprise IT outsourced services. 1 Definition from AICPA http://www.aicpa.org/interestareas/frc/assuranceadvisoryservices/pages/serviceorganization'smanagement.aspx 3 Information Systems Audit and Controls Association

Types of service organization control reports New standards and options Service Org Control 1 (SOC 1) Service Org Control 2 (SOC 2) Service Org Control 3 (SOC 3) SSAE16 Service auditor guidance AT 101 AT 101 Restricted Use Report (Type I or II Report) Generally Restricted Use Report (Type I or II Report) General Use Report (w/ public seal) Purpose: Reports on controls for F/S audits Purpose: Reports on controls related to compliance or operations Purpose: Reports on controls related to compliance or operations Historically SAS 70 Reports Trust Services Principles and Criteria 4 Information Systems Audit and Controls Association

Key terms relative to SOC reports Service auditor Service organization Subservice organization User entity Applicable trust services criteria Boundaries of the system A practitioner who reports on controls at a service organization. An organization or segment of an organization that provides services to user entities, which are likely to be relevant to those user entities internal control over financial reporting. A service organization used by another service organization to perform some of the services provided to user entities that are likely to be relevant to those user entities internal control over financial reporting. An entity that uses a service organization. The criteria in Trust Services Principles (TSP) section 100, i.e., Trust Services Principles, Criteria, and Illustrations for Security, Availability, Processing Integrity, Confidentiality, and Privacy (AICPA, Technical Practice Aids), that are applicable to the principle(s) being reported on. These are issued by issued by the Assurance Services Executive Committee of the AICPA (the committee). The boundaries of a system are the specific aspects of a service organization s infrastructure, software, people, procedures, and data necessary to provide its services. 5 Information Systems Audit and Controls Association

Key terms relative to SOC reports (cont.) Engagement letter Management assertion Management representation letter Test of controls A formal letter representing the written contract between the service auditor and the service organization to perform SOC services. A written statement by management of the service organization regarding the description of the service organization s system; the suitability of the design of the controls; and in a Type 2 report, the operating effectiveness of the controls. A letter signed by management of the service organization that includes written statements of facts or representations that controls are suitably designed and implemented (Type 1) and operating effectively (Type 2). A procedure designed to evaluate the operating effectiveness of controls in achieving the control objectives stated in management s description of the service organization s system. Additional definitions are available in Appendix D of the AICPA Guide, Reporting on Controls at a Service Organization Relevant to Security, Availability, Processing Integrity, Confidentiality, or Privacy (SOC 2) 6 Information Systems Audit and Controls Association

Overview of SOC 2 reports

SOC 2 overview Topic Professional guidance SOC 2 guidance AICPA Attestation engagement under AT section 101 AICPA Guide, Reporting on Controls at a Service Organization Relevant to Security, Availability, Processing Integrity, Confidentiality, or Privacy Effective date As of May 2011 Scope Application of SOC 2 Controls at a service organization intended to mitigate risks related to security, availability, processing integrity, confidentiality, or privacy (trust services principles) SOC 2 can be applied for regulatory or non-regulatory purposes to cover business areas outside of financial reporting. The report can be distributed to customers and other stakeholders to demonstrate a focus on system and processing controls to meet their requirements. SOC 2 can be applied to virtually every industry and business sector. SOC 2 will allow service organizations to provide assurance to customers and other stakeholders that effective internal controls are in place. 8 Information Systems Audit and Controls Association

SOC 2 overview (cont.) SOC 2 is an AICPA report that allows service auditor to provide an opinion on the following principles: Security Availability Processing integrity Confidentiality Privacy Can include one or more of the above trust services principles but may need to address entire principle scoped in unless it was deemed not applicable. That would need to be documented. In a SOC 2 report, the AICPA has supplied the criteria, where in a Statement on Standards for Attestation Engagements No. 16 (SSAE 16)/SOC 1, management specifies the objectives and controls. So, SOC 2 reports should be much more consistent across the marketplace. Exception is for SOC 2 reports which cover privacy. These reports would also need to include the service organization s privacy policy, which could obviously vary from organization to organization. 9 Information Systems Audit and Controls Association

SOC 2 principles Security IT security policy Security awareness and communication Risk assessment Logical access Physical access Environmental controls Security monitoring (breaches) User authentication Incident management Asset classification and management Systems development and maintenance Configuration management Availability Confidentiality Processing integrity Privacy Availability policy Backup and restoration Disaster recovery Confidentiality policy Confidentiality of inputs Confidentiality of data processing Confidentiality of outputs Information disclosures (including third parties) Confidentiality of Information in systems development System processing integrity policies Completeness, accuracy, timeliness, and authorization of inputs, system processing, and outputs Information tracing from source to disposition Notice Choice On-ward transfer Access Security Data Integrity Training and awareness Enforcement and compliance 10 Information Systems Audit and Controls Association

Security versus privacy These terms are often confused. Security relates to the authorization of transactions and protection of the integrity of those transactions throughout the system and also protecting personal and other information from unauthorized use or disclosure from the time it is collected until the time it is disposed of. Security may also relate to the protection of the system from interruptions in processing availability. Privacy encompasses a much broader set of activities beyond security that contribute to the effectiveness of a privacy program, including, for example, providing users with the following: Notice of the service organization s privacy commitments and practices Choice regarding the use and disclosure of their personal information (PII) Access to their personal information for review and update An inquiry, complaint, and dispute resolution process 11 Information Systems Audit and Controls Association

Service Auditor s opinion on a SOC 2 engagement In a SOC 2 report, the service auditor expresses an opinion on the following: Whether the description of the service organization s system is fairly presented Whether the controls are suitably designed to provide reasonable assurance that the applicable trust services criteria could be met if the controls operated effectively In Type 2 reports, whether the controls were operating effectively to meet the applicable trust services criteria In engagements to report on the privacy principle, whether the service organization complied with the commitments in its statement of privacy practices 12 Information Systems Audit and Controls Association

Type 1 and Type 2 SOC 2 reports Type 1 Reports on controls placed in operation (as of a point in time) Looks at the design and implementation of controls; not operating effectiveness Considered for information purposes only Often performed only in the first year a client has a SOC report completed Type 2 Reports on the design, implementation and operating effectiveness over a period of time (generally not less than six months) Includes tests of operating effectiveness and results More comprehensive Requires more internal and external effort More emphasis on evidential matter Neither a Type 1 or Type 2 SOC 2 report can be used for reliance purposes by financial auditors. 13 Information Systems Audit and Controls Association

SOC 2 reports summary of benefits Reports can be referenced by boards as part of their oversight responsibility of service providers Reduces questions and site visits from clients, prospective clients to the service provider Often requested by prospective clients during the due diligence process Can act as a differentiator from competitors during new business negotiation process Certain organizations are requiring the issuance of SOC 2 reports as a part of the service contracts and agreements Demonstrate compliance with regulatory and legal requirements (such as Federal Information Security Management Act (FISMA)) 14 Information Systems Audit and Controls Association

Components of a SOC 2 report Baseline walkthrough The purpose of the baseline walkthrough is to gather engagement planning information required for a SOC 2. 1 2 weeks* COSO* walkthrough This information covers governance and higher level entity controls to understand how the organization provides fundamental discipline and structure to its internal control system. 1 2 weeks* Topical areas walkthrough Topical areas relate to how organizations look at their business. 2 4 weeks* Testing phase The description of controls are tested in this phase for operating effectiveness. 4 8 weeks* SOC 2 report The Final SOC2 report contains: Executive summary Section I: Independent Service Auditors Report Section II: Management Assertion Section III: System Description Overview Section IV: Description of Controls and tests of operating effectiveness Section V: Other Information Provided by the service organization Committee of Sponsoring Organizations of the Treadway Commission (COSO) 15 Information Systems Audit and Controls Association

How does SOC 2 differ from SSAE 16/SOC 1? Similar in structure and general approach to SOC 1: An option for a Type 1 or Type 2 report. An opinion An assertion A section describing the processing environment Description of control objectives, control activities, and tests Management representation letter A SOC 2 report does not need to cover processing related to financial reporting, nor is it intended to support financial reporting for your users. SOC 2 can be supplied to a wider audience. Intended users are management of the service organization, user entities, and other specified parties. Specified parties can be anyone who understands the nature of the services being provided by the service organization, how the service organization operates, and internal controls. 16 Information Systems Audit and Controls Association

How does SOC 2 differ from SSAE 16/SOC 1? Many practitioners who have looked at SOC 2 feel it will provide more technical detail throughout the report; narrative section, control activities, tests, etc. than the existing SOC 1 reports. 17 Information Systems Audit and Controls Association

Is SOC 2 the right report for your purpose? SOC 1 report SOC 2 report SOC 3 report Professional standard used AT 801 AT 101 AT 101 Used by auditors to plan and perform financial audits Yes No No Used by user entities to gain confidence and place trust in service organization systems No Yes Yes Obtain details of the processing performed and related controls, the tests performed by the service auditor and results of those tests Yes Yes No Report generally available can be freely distributed or posted on a website as a SysTrust for Service Organizations seal No No Yes 18 Information Systems Audit and Controls Association

Is SOC 2 the right report for your purpose? Challenges Deciding on the right principle(s) to include in scope We recommend inventorying customers requests Align with overall departmental/company strategies Drawing report boundaries Few organizations had a previous need to look at their systems in the manner needed for a SOC 2 Example tracing PII through the environment Smaller, non-public organizations selling to SEC Filers Extent of policies and procedures needed seen as extensive Level of precision to meet principles and criteria 19 Information Systems Audit and Controls Association

SOC 2 reports industry application

SOC 2 reports industry application Market feedback Marketplace appears to be embracing the product: Security principal is being used extensively Software as a Service (SAAS) providers are taking advantage of full reports by covering all 5 areas Smaller service organizations are issuing SOC 2 reports Jury is still out on standalone Privacy reports Service providers appreciate the closed nature of SOC 2 Guidance: Trust Principles draw some bright lines around definitions of sound security, privacy, etc. Guidance seen as proscriptive Can be provided to both current users as well as prospective users Still to come: SOC 2 to replace individual on-site audits and questionnaires SOC 2 to replace aspects of regulatory exams 21 Information Systems Audit and Controls Association

SOC 2 illustrative applications Illustrative applications of SOC 2 reports SOC 2 reports provide a way to build trust with customers and demonstrate compliance in controls with various industry regulations and standards. Cloud Computing Consolidation SOC 2 Multiple surveys or questionnaires from user entities can be encompassed under a consolidated SOC 2 report. ISO ISO 27001, 27002 regulations can be reported under the SOC 2 reporting framework. Career College Initiative For-profit colleges can provide assurance that they meet a voluntary set of operating standards. FISMA Agencies with federal contracts can demonstrate that controls meet the FISMA requirements. Smart Grid Smart grid companies can demonstrate compliance with various regulatory body requirements, industry frameworks, and standards. Cloud service providers can give their customers assurance of effective controls across the SOC 2 Trust Principles. 22 Information Systems Audit and Controls Association

SOC 2 illustrative applications Call centers Call center services SOC 1 may not be a good fit because while call center services are important from a business perspective, the processes executed may not be financially significant for customers of a service provider. User organizations may be concerned about handling of end-customer information and a SOC 2 report may demonstrate that there are controls encompassing the security, confidentiality, and privacy of information. 23 Information Systems Audit and Controls Association

SOC 2 illustrative applications Medical claims processing Medical claims processing service provider A SOC 2 report focused on processing integrity (completeness, accuracy, timelines, etc.) could provide customers with comfort regarding the controls over transactions in claims processing. This may be prepared in addition to a SOC 1 report leveraging existing controls and testing. 24 Information Systems Audit and Controls Association

SOC 2 illustrative applications Information technology services Data center hosting SOC 1 or SOC 2 may be a good fit for these types of services. Hosting does have relevance to Internal Controls over Financial Reporting (ICFR), however there could be security and availability concerns that may be addressed with a SOC 2 report. Cloud service providers Cloud service providers need to provide their customers assurance of effective controls across the SOC 2 trust principles in order for those customers to comfortably entrust the cloud provider with their sensitive data and critical computing needs. SOC 2 reports provide a way to build trust with customers and demonstrate compliance in controls with various industry regulations and standards (e.g., The Health Insurance Portability and Accountability Act/Health Information Technology for Economic and Clinical Health Act (HIPAA/HITECH), Gramm-Leach-Bliley Act (GLBA), FISMA). 25 Information Systems Audit and Controls Association

SOC 2 illustrative applications Financial services Credit card processing A SOC 1 or SOC 2 are both alternatives. Payment card processing may have relevance to a user s ICFR, thus fitting the SOC 1 criteria. From a SOC 2 perspective the report may cover a number of principles of interest including security, confidentiality, availability, integrity of processing, and privacy of the credit card holders personal information. 26 Information Systems Audit and Controls Association

SOC 2 illustrative applications Power and utility companies Power and utility compliance Power and utilities companies can leverage SOC 2 to demonstrate compliance with various regulatory body requirements, industry frameworks, and standards such as Natural Environment Research Council (NERC) Critical Infrastructure Protection (NERC CIP), Smart Grid: National Institute of Standards and Technology (NIST) IR 7628 Guidelines for Smart Grid Cyber Security, Advanced Metering Infrastructure (AMI) Securities and Exchange Commission (SEC) System Security Requirements, and state privacy requirements. 27 Information Systems Audit and Controls Association

Questions?

This presentation contains general information only and Deloitte is not, by means of this presentation, rendering accounting, business, financial, investment, legal, tax, or other professional advice or services. This presentation is not a substitute for such professional advice or services, nor should it be used as a basis for any decision or action that may affect your business. Before making any decision or taking any action that may affect your business, you should consult a qualified professional advisor. Deloitte, its affiliates, and related entities shall not be responsible for any loss sustained by any person who relies on this presentation. About Deloitte Deloitte refers to one or more of Deloitte Touche Tohmatsu Limited, a UK private company limited by guarantee, and its network of member firms, each of which is a legally separate and independent entity. Please see www.deloitte.com/about for a detailed description of the legal structure of Deloitte Touche Tohmatsu Limited and its member firms. Please see www.deloitte.com/us/about for a detailed description of the legal structure of Deloitte LLP and its subsidiaries. Certain services may not be available to attest clients under the rules and regulations of public accounting. 36 USC 220506 Member of Deloitte Touche Tohmatsu Limited