Difference between SOC1 and SOC 2

A common question we are always asked is...."What is the different between SOC 1 and SOC2". Is it the same as Sox Audit. Is SOC 1 and SSAE the same. The confusion is endless.

On this page, we want to clarify the difference between SOC1 and SOC2.

SOC 1 audits (Also known as SSAE 16 audits) are primarily geared towards providing comfort to user auditor that there are adequate internal controls to ensure that the financial reporting related controls are adequate. The controls are more financial and less operational.

SOC2 audits, also part of the SSAE work, on the other hand are all about operatoinal controls. There are five principles that form the backbone of SSAE 16 (SOC 2 engagements).

• Security – The system is protected against unauthorized access (both physical and logical).
• Availability –The system is available for operation and use as committed or agreed upon.
• Processing Integrity – System processing is complete, accurate, timely, and authorized.
• Confidentiality –Information designated as confidential is protected as committed or agreed upon.
• Privacy –Personal information is collected, used, retained, disclosed, and/or destroyed in accordance with established standards.

So, if your customers are concerned that you may not have an environment where there information is secure or can be processed in a confidential manner, you are a good candidate for SOC 2 audits.

Ofcourse, if you are still figuring out what all this means, a two words email at manoj.jain@riskpro.in (Subject "Contact Me") will solve all your worries.

Other Services of Interest

  • India: Data Protection Services

    The EU General Data Protection Regulation (GDPR) is the most important change in data privacy regulation in 20 years. Now India has its own version of Data protection regulation that will change...
  • Fire Safety Assessments and Training

    Some of our features of Fire Safety Assessments and Training • Fire Science • The common causes of fire • Identify fire hazards • Types of fires and extinguishers • Fire...
  • Data Protection Officer (DPO) Services

    Why a DPO The General Data Protection Regulation (GDPR) makes it compulsory for certain companies to appoint a DPO. this is a mandatory position that is expected to carry out certain defined tasks....
  • GDPR Countdown

    Riskpro is working hard so that clients can GDPR deadline as the clock ticks away.
  • EU-US Privacy Shield for Data Transfers

    Come GDPR (General Data Protection Act) and EU-US PRivacy shield will assume more importance. Privacy Shield Overview The Privacy Shield program, which is administered by the International Trade...
  • Reduce your GDPR implementation Costs - Hire GDPR Experts in India

    Reduce cost for GDPR Compliance - Remote Consulting from India GDPR readiness assessment and implementation can be costly. And time is short. Instead of paying premium fees to local GDPR consultants...
  • Riskpro India on top of Emerging Risks that bother you

    Riskpro India is well positioned to offer advisory services for emerging risks such as Data Protection (GDPR), information security, assurance services such as Third party risk management, internal...
  • Assurance Services

    In Riskpro we believe that Internal audit function has to align its activities with business activities of any organisation to achieve its objectives. IA can be of significant value if it maintains...
  • Risk Based Internal Audit Services

    Why Internal Audit Matters In order to run your business, you develop processes to manage the factors that drive performance and help control internal and external risks that could prevent you from...
  • Go to top