1/269
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
types of services provided by a service organization
outsourced payroll processors
CSPs
credit card processing orgs
enterprise IT outsourcing services
fintech services
customer support services
SOC 1 engagements for service orgs
ICOFR
use restricted to:
management of the service org
user entities of the service org
independent auditors
& excludes potential users of the service org
SOC 2 engagement for service orgs
5 trust services criteria (TSC)
use intended for those who have sufficient knowledge and understanding of:
the service org
the services it provides
the system used to provide those services
etc.
service auditor reports on whether controls within the system were effective to provide reasonable assurance that the service commitments and system requirements were achieved
SOC 3 engagement for service orgs
5 trust services criteria (TSC)
same as SOC 2, but intended for general use (those who lack the knowledge and understanding required for a SOC 2 report)
service auditor reports on whether controls within the system were effective to provide reasonable assurance that the service commitments and system requirements were achieved
type 1 report
reports on fairness of the presentation of management’s description of the service org’s system and the suitability of the design of the controls to achieve the related control objectives included in the description as of a specified date
type 2 report
reports on fairness of the presentation of management’s description of the service org’s system and the suitability of the design and operating effectiveness of the controls to achieve the related control objectives included in the description throughout a specified period
5 trust services categories
confidentiality
availability
processing integrity
privacy
security
5 components of COSO framework
control environment
risk assessment
(existing) control activities
information and communication
monitoring activities
what should the service auditor evaluate when forming an opinion on the subject matter of a SOC engagement?
the sufficiency and appropriateness of the evidence obtained
whether uncorrected misstatements, individually or in the aggregate, are material
what does the opinion of a service auditor in a SOC engagement focus on?
fair presentation of management’s description of the service org’s system
the suitability of the design of the controls related to the control objectives stated in management’s description
type 2 only → the effective operation of the controls stated in management’s description
4 key components of a SOC report
management’s description of the system
management’s assertion
independent service auditor’s report
auditor’s ToC and results of tests
responsibility of service org’s management - SOC 1
documenting the description of the service org’s system, which must be sufficient to allow a user auditor to understand how the service org’s processing affects the user entity’s FS and to assess the RMM of the user entity’s financial statements
responsibility of service org’s management - SOC 2
presenting a description of the system to enable report users, such as user entities, business partners, or other relevant parties, to understand the system and the processing and flow of data throughout and from the system
SOC 1 & 2 report elements
title
addressee
scope
service org’s responsibilities
service auditor’s responsibilities
inherent limitations
type 2 only → description of ToC
type 1 only → other matter
opinion
restricted use
service auditor’s signature, city and state, date of service auditor’s report
when would a vendor used by a service org be considered a subservice org for SOC 1 engagements?
the services provided by the vendor are likely relevant to the user entities’ ICOFR
controls implemented at the subservice org are necessary to achieve the control objectives stated in management’s description of the service org’s system
when would a vendor used by a service org be considered a subservice org for SOC 2 & 3 engagements?
the services provided by the vendor are relevant to report users’ understanding of the service org’s system as it relates to the applicable TSC
controls at the subservice org are necessary, in combination with the service org’s controls, to provide reasonable assurance that the service commitments and system requirements are achieved
carve-out method
addresses the services provided by a subservice org in which the complementary subservice organization controls (CSOCs) of the subservice org are excluded from the description of the service org’s system and from the scope of the engagement
inclusive method
addresses the services provided by a subservice org in which the description of the service org’s system includes a description of the nature of the services provided by the subservice org and the components of the subservice org’s system used to provide services to the service org
complementary user entity controls (CUECs)
controls that are necessary to be implemented by the user entity, in combination with the service org’s controls, to provide reasonable assurance that the control objectives stated in the management’s description of the service org’s system (SOC 1) or the service org’s service commitments and system requirements (SOC 2) were achieved
examples of CUECs
security monitoring
managed service provider (MSP) environment changes
encrypted financial data
physical access controls
authorization policies
key differences between CSOCs and CUECs
CSOCs are controls that a subservice org must execute in order for a service org’s controls to function effectively
CUECs are controls that a user must employ for the service org’s controls to function
in both, the service org relies on other entities, vendor or client, for their own controls to work properly
what must a service auditor do in the report when a modified opinion is appropriate during a SOC engagement?
a separate paragraph should be added to the service auditor’s report to explain the matter giving rise to the modification
before accepting a SOC engagment, what is the service auditor required to do?
establish an understanding with the service org’s management about its responsibilities and the responsibilities of the service auditor
in a SOC 1 engagement, what is the management of the service org required to disclose to the service auditor?
incidents of noncompliance w laws and regulations, fraud, or uncorrected misstatements that may affect user entities
knowledge of any intentional acts that could adversely affect the description presentation of the service org’s system or the completeness or achievement of the control objectives stated in the description
any known deficiencies in the design of controls
all instances where controls have not operated as described
any events subsequent to the period covered by the description of the service org’s system, up to the date of the report, that could have a significant effect on management’s assertion
key difference between management responsibilities in a SOC 2 vs. 3 engagement
management does not prepare a system description in a SOC 3 engagement
responsibilities of the service auditor during SOC engagement planning
determining whether to accept or continue the engagement
agreeing on engagement terms
reaching an understanding w management regarding a written assertion
additional responsibilities of the service auditor during SOC 1 engagement planning
assessing RMM
obtaining an understanding of the service org’s system and assessing the suitability of the criteria used by management in preparing its system description
additional responsibilities of the service auditor during SOC 2 & 3 engagement planning
establishing an overall strategy for the engagement
performing risk assessment procedures
common terms when discussing misstatements related to the different subject matters in a SOC engagement
description misstatement
deviation or exception
deficiency in the design
deficiency in the operating effectiveness
system (in the context of a SOC 2 engagement)
the infrastructure, software, procedures, and data that are designed, implemented, and operated by people to achieve 1+ of the org’s specific business objectives in accordance with management-specified requirements
deficiency in the design
refers to either necessary controls that are missing, or existing controls that are not designed properly to achieve their control objectives
deficiency in the operating effectiveness
refers to when properly designed controls fail to operate as designed, or when the person performing the control does not possess the competency necessary to perform the control effectively
written assertion (in the context of a SOC engagement)
a statement made by the responsible party that addresses the measurement or evaluation of the subject matter against the criteria (SOC 1) or the subject matters in the examination (SOC 2 & 3)
key areas of engagement performance once initial risk assessment procedures by the service auditor are complete
respond to assessed risks
evaluate whether management’s description of the service org’s system is fairly presented in accordance with the description criteria
obtain and evaluate evidence regarding the suitability of the design of controls
type 2 only → obtain and evaluate evidence regarding the operating effectiveness of controls
evaluate the results of the procedures
form the opinion
assessment of the RMM is impacted by the following factors when performing a SOC engagment:
materiality considerations
the service auditor’s understanding of the effectiveness of the control environment
other components of internal control related to the service provided to user entities and business partners
overall responses by the service auditor to address the assessed RMM:
maintaining professional skepticism
assigning more experienced staff using specialists
providing additional supervision over audit procedures
incorporating elements of unpredictability in the selection of procedures to be performed
making changed to the NET of procedures
procedures the service auditor may perform to evaluate whether the description of the service org’s system is fairly presented in a SOC 1 engagement:
considering the nature of the user entities
reading contracts with user entities
observing procedures performed by personnel
reviewing the service org’s policies and procedures and other system documentation
performing WT of transactions through the service org’s system
what makes a description of a service org’s system in a SOC 2 engagement present in accordance with the description criteria?
describes the system that the service org has implemented
includes info about each description criterion, to the extent it is relevant to the system being described
does not inadvertently or intentionally omit or distort info that is likely to be relevant to report users’ decisions
additional engagement disclosures in a SOC 2 engagement
significant interpretations made in applying the criteria in the engagement circumstances
subsequent events, depending on nature and significance
procedures that can be performed when obtaining evidence about the suitability of the design of controls in a SOC 2 engagement
inquiry of service org personnel about the design and operation of controls or system events
inspection of documentation
additional WTs
reading applicable supporting system documentation
determining whether attacks, vulnerability exploitations, emerging risks, or threats have been adequately addressed
potential actions a service auditor should take if management refuses to disclose a subsequent event that, if undisclosed, would mislead report users
modifying the auditor’s report and disclosing the event
withdrawing from the engagement
description criteria (in the context of a SOC engagement)
the criteria used to determine whether the description of the service org’s system is presented fairly and includes relevant information
3 primary components to manage cybersecurity risk (NIST CSF)
CSF core
CSF tiers
CSF organizational profiles
NIST CSF core
govern
identify
protect
detect
respond
recover
represents different points in the cybersecurity risk management life cycle
NIST CSF tier levels
tier 1 partial
tier 2 risk-informed
tier 3 repeatable
tier 4 adaptive
current profile
the outcome that an organization is achieving or attempting to achieve based on the current cybersecurity posture
target profile
the desired outcome that an organization is prioritizing achieving, considering the anticipated changes to the organization’s cybersecurity posture
gap analysis
analysis to identify the differences between the current and future state
NIST privacy framework core
identify-p
govern-p
control-p
communicate-p
protect-p
common (inheritable) implementation
implementation approach in which controls are implemented at the organizational level, which are adopted by information systems
system-specific implementation
implementation approach in which controls are implemented at the information system level
hybrid implementation
implementation approach in which controls are implemented at the organizational level where appropriate, and the remainder at the information system level
system and information integrity (SI)
a control family in NIST SP 800-53 concerning the protection of accuracy, completeness, and reliability of information and the systems that process it
control implementations
3 approaches outlined in NIST SP 800-53 for implementing controls
common (inheritable)
system-specific
hybrid
*applied on a per-control basis
control objectives - NIST privacy framework
expressed as the framework core; consists of 8 functions and 29 categories, subdivided into 100 subcategories
organizational profiles
mechanisms by which NIST recommends companies measure cybersecurity risk and establish a roadmap to minimize such risk
NIST CSF tiers
act as benchmarks for an organization’s information security infrastructure sophistication, indicating the degree to which cybersecurity practices are integrated throughout the organization
cybersecurity risk governance
a component of CSF tiers focusing on the policies, procedures, and structures put in place by an organization’s leadership to oversee and manage cybersecurity risks
involves establishing accountability, defining roles and responsibilities, and ensuring that cybersecurity risk management aligns with the organization’s overall risk
cybersecurity risk management
a component of CSF tiers referring to the continuous process of identifying, assessing, and responding to cybersecurity threats and vulnerabilities to minimize impact on an organization’s operations, assets, and reputation
GOAL: balance needs of cybersecurity with business objectives
detective measures (NIST)
security measures that focus on identifying and detecting potential threats or breaches after they occur, such as monitoring and incident response systems
organizational responsibilities (NIST SP 800-53)
requirements, including well-defined security and privacy requirements, trustworthy information system components, security and privacy planning, and continuous monitoring of information systems
unintentional data breach
results from negligence from error
intentional data breach
results from bad actors illegally gaining access to data
HIPAA safeguards
administrative
physical
technical
principles for processing data (GDPR)
lawfulness, fairness, and transparency
purpose limitation
data minimization
accuracy
storage limitation
integrity and confidentiality
ALL processors or controllers of data shall be responsible for and able to demonstrate compliance with these principles (accountability)
goals of PCI DSS
build and maintain a secure network and systems
protect account data
maintain a vulnerability management program
implement strong access control measures
regularly monitor and test networks
maintain an information security policy
data privacy
the right of an individual to exercise control over how their personal data is collected, used, and shared by organizations
data privacy laws
legal regulations designed to protect an individual’s private life and personal details from being disclosed to the public
establishes rules for collecting, processing, maintaining, and disclosing private information to build trust between consumers and enterprises
breach notification rules (HIPAA)
a requirement added by HITECH; covered entities are required to notify individuals affected by a data breach within 60 days of discovery
control 01: inventory and control of enterprise assets
actively manage all enterprise assets connected to the infrastructure, physically, virtually, remotely, and those within cloud environments, to accurately know the totality of assets that need to be monitored and protected within the enterprise
control 02: inventory and control of software assets
actively manage all software on the network so that only authorized software is installed and can execute, and that unauthorized and unmanaged software is found and prevented from installation or execution
control 03: data protection
develop processes and technical controls to identify, classify, securely handle, retain, and dispose of data
control 04: secure configuration of enterprise assets and software
establish and maintain the secure configuration of enterprise assets and software
control 05: account management
use processes and tools to assign and manage authorization to credentials for user accounts, including administrator accounts as well as service accounts, to enterprise assets and software
control 06: access control management
use processes and tools to create, assign, manage, and revoke access credentials and privileges for user, administrator, and service accounts for enterprise assets and software
control 07: continuous vulnerability management
develop a plan to continuously assess and track vulnerabilities on all enterprise assets within the enterprise’s infrastructure, in order to remediate and minimize the window of opportunity for attackers
monitor public and private industry sources for new threat and vulnerability management
control 08: audit log management
collect, alert, review, and retain audit logs of events that could help detect, understand, or recover from an attack
control 09: email and web browser protections
improve protections and detections of threats from email and web vectors, as these are opportunities for attackers to manipulate human behavior through direct engagement
CIS controls - design principles - context
an enhancement to the scope and practical applicability of safeguards through incorporation of examples and explanations
CIS controls - design principles - coexistence
alignment with evolving industry standards and frameworks, including NIST CSF 2.0 framework
CIS controls - design principles - consistency
disruption to controls users are minimized, not impacting implementation groups
CIS benchmarks
publicly available security standards, used by organizations as a starting point for asset reconfiguration
adhering to these standards helps organizations in complying with any applicable laws and regulations
CIS controls
a set of recommended actions, processes, and best practices for organizations to strengthen their cybersecurity defenses
they include measures to track and manage software applications, protect data, and configure enterprise assets securely
control 10: malware defenses
prevent or control the installation, spread, and execution of malicious applications, code, or scripts on enterprise assets
control 11: data recovery
establish and maintain data recovery practices sufficient to restore in-scope enterprise assets to a pre-incident and trusted state
control 12: network infrastructure management
establish, implement, and actively manage network devices in order to prevent attackers from exploiting vulnerable services and access points
control 13: network monitoring and defense
operate processes and tooling to establish and maintain comprehensive network monitoring and defense against security threats across the enterprise’s network infrastructure and user base
control 14: security awareness and skills training
establish and maintain a security awareness program to influence behavior among the workforce to be security conscious and properly skilled to reduce cybersecurity risks to the enterprise
control 15: service provider management
develop a process to evaluate service providers who hold sensitive data or are responsible for an enterprise’s critical IT platforms or processes to ensure these providers are protecting those platforms and data appropriately
control 16: application software security
manage the life cycle of in-house developed, hosted, or acquired software to prevent, detect, and remediate security weaknesses before they can impact the enterprise
control 17: incident response management
establish a program to develop and maintain an incident response capability to prepare, detect, and quickly respond to an attack
control 18: penetration testing
test the effectiveness and resiliency of enterprise assets through identifying and exploiting weaknesses in controls (people, processes, and tech), and simulating the objectives and actions of an attacker
penetration testing
a testing technique that simulates actual attacks to identify and exploit technical vulnerabilities in a defined scope (network/application/system)
red team exercises
a holistic, objective-driven adversarial simulation mimicking the tactics, techniques, and procedures (TTPs) of real-word attackers to test an organization’s detection and response capabilities
living-off-the-land (LotL) - control 10: malware defenses
a tactic used by attackers that leverages existing tools and applications within an organization against itself to avoid detection
COBIT framework - purpose
provides a roadmap that organizations can use to implement best practices IT governance and management
components used for development of COBIT 2019
COBIT 5
6 principles for a governance system
3 principles for a governance framework
other standards and regulations
community contribution
6 governance system principles (COBIT)
provide stakeholder value
holistic approach
dynamic governance system
governance distinct from management
tailored to enterprise needs
end-to-end governance system
3 principles for a governance framework (COBIT)
based on conceptual model
open and flexible
aligned to major standards
based on conceptual model
principle for a governance framework; governance frameworks should identify key components as well as the relationships between those components