ICE is now SOC 2 Type II Certified!
Less than 5% of Service Providers are SOC 2 Certified. Why it is important that yours is!
What is a SOC 2 Certification?
SOC 2 is a voluntary compliance standard for a service organization, developed by the American Institute of CPAs (AICPA), which specifies how the organization should manage customer data. The standard is based on the following Trust Service Criteria: security, availability, processing integrity, confidentiality, and privacy.
Why is it important to work with a SOC 2 Certified Service Provider?
In today’s cyberthreat-infested landscape, it is imperative that you demand honesty and transparency in how your sensitive data is handled. Information security is a reason for concern for all organizations, including those that outsource key business operations to third-party vendors (e.g., SaaS, cloud-computing providers). Rightfully so, since mishandled data—especially by application and network security providers—can leave enterprises vulnerable to attacks, such as data theft, extortion, and malware installation.
SOC 2 is an auditing procedure that ensures your service providers securely manage your data to protect the interests of your organization and the privacy of its clients. For security-conscious businesses.
Working with a provider who has completed their certification guarantees:
- They have the required security controls in place to protect your data against known and emerging threats
- They have set up alerts to detect anomalies and violations across your entire ecosystem easily
- Besides preventing risk situations, they can quickly repair damage and restore normalcy in case a rare data breach or system failure occurs
- Many of our clients today have different compliance requirements such as ISO, HIPAA, HI trust, CLIA, GDPR, NIST, and others—and all of these require that the IT service provider be SOC 2 certified.
What is the process a company must go through to get certified:
The service organization must undergo an audit by a 3rd party. A SOC 2 audit is an audit of a service organization’s non-financial reporting controls as they relate to the Trust Services Criteria – the security, availability, processing integrity, confidentiality, and privacy of a system. A SOC 2 audit report provides user entities with reasonable assurance and peace of mind that the non-financial reporting controls at a service organization are suitably designed, in place, and appropriately protecting sensitive client data. There are two types of SOC 2 audit reports: SOC 2 Type I and SOC 2 Type II.
Here is a basic SOC 2 compliance checklist, which includes controls covering safety standards:
- Access controls—logical and physical restrictions on assets to prevent access by unauthorized personnel.
- Change management—a-controlled process for managing changes to IT systems, and methods for preventing unauthorized changes.
- System operations—controls that can monitor ongoing operations, and detect and resolve any deviations from organizational procedures.
- Mitigating risk—methods and activities that allow the organization to identify risks, as well as respond to and mitigate them while addressing any subsequent business.
What is the difference between SOC 2 Type 1 and SOC 2 Type II:
SOC 2 Type 1— Type I describes a vendor’s systems and whether their design is suitable to meet relevant trust principles. It is an attestation of controls at a service organization at a specific point in time. SOC 2 Type I reports on the description of controls provided by the management of the service organization and attests that the controls are suitably designed and implemented.
SOC 2 Type 2— Type II details the operational effectiveness of those systems. It is an attestation of controls at a service organization over a minimum 4-month period. SOC 2 Type II reports on the description of controls provided by the management of the service organization, attests that the controls are suitably designed and implemented, and attests to the operating effectiveness of the controls.
During a SOC 2 Type II audit, the auditor will carry out fieldwork on a sample of days across the testing period to observe how controls are implemented and how effective they are.
As you can see, the key difference between SOC 2 Type I and SOC 2 Type II reports is that Type II reports are conducted over a significantly longer period. This allows Type II reports to attest to control effectiveness, something that is not possible with the shorter Type 1 report, which can only attest to the suitability of design and implementation.
The five trust principles explained:
The security principle refers to the protection of system resources against unauthorized access. Access controls help prevent potential system abuse, theft or unauthorized removal of data, misuse of the software, and improper alteration or disclosure of information. IT security tools such as network and web application firewalls (WAFs), two-factor authentication, and intrusion detection are useful in preventing security breaches that can lead to unauthorized access to systems and data.
The availability principle refers to the accessibility of the system, products, or services as stipulated by a contract or service level agreement (SLA). As such, the minimum acceptable performance level for system availability is set by both parties. This principle does not address system functionality and usability but does involve security-related criteria that may affect availability. Monitoring network performance and availability, site failover, and security incident handling are critical in this context.
The processing integrity principle addresses whether or not a system achieves its purpose (i.e., delivers the right data at the right price at the right time). Accordingly, data processing must be complete, valid, accurate, timely, and authorized.However, processing integrity does not necessarily imply data integrity. If data contains errors prior to being input into the system, detecting them is not usually the responsibility of the processing entity. Monitoring of data processing, coupled with quality assurance procedures, can help ensure processing integrity.
Data is considered confidential if its access and disclosure is restricted to a specified set of persons or organizations. Examples may include data intended only for company personnel, as well as business plans, intellectual property, internal price lists, and other types of sensitive financial information. Encryption is an important control for protecting confidentially during transmission. Network and application firewalls, together with rigorous access controls, can be used to safeguard information being processed or stored on computer systems.
The privacy principle addresses the system’s collection, use, retention, disclosure, and disposal of personal information in conformity with an organization’s privacy notice, as well as with criteria set forth in the AICPA’s generally accepted privacy principles (GAPP). Personal identifiable information (PII) refers to details that can distinguish an individual (e.g., name, address, Social Security number). Some personal data related to health, race, sexuality, and religion is also considered sensitive and generally requires an extra level of protection. Controls must be put in place to protect all PII from unauthorized access.
ICE Consulting is an IT and cybersecurity service provider dedicated to helping the Life Science Community grow. For over 25 years we have helped biotech companies scale from startup to commercialization. We are proud members and service providers for the California Life Science (CLS), Biocom, and SoCalBio communities.