SlideShare a Scribd company logo
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
SOC 2:
Build Trust & Confidence
Overview & Considerations
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
01. Background / Overview of SOC 2
02. The AICPA Framework
03. Purpose and Scope
04. The Anatomy
05. Considerations
06. Mapping – Other Standards
06. Q/A
Contents
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
Background
& Overview
01
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
Growth &
Popularity
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
Service
Auditors
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
Service
Providers
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
User Entities
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
Why Do You Need a SOC Report?
Regulatory requirements
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
Why Do You Need a SOC Report?
Regulatory requirements
User entity mandates
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
Why Do You Need a SOC Report?
Regulatory requirements
User entity mandates
Vendor management programs
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
Why Do You Need a SOC Report?
Regulatory requirements
User entity mandates
Vendor management programs
Due diligence
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
Why Do You Need a SOC Report?
Regulatory requirements
User entity mandates
Vendor management programs
Due diligence
Independent 3rd party opinion
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
Why Do You Need a SOC Report?
Regulatory requirements
User entity mandates
Vendor management programs
Due diligence
Independent 3rd party opinion
Competition and market
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
Overview
• What is a SOC 2 report?
• How does a SOC 2 differ from a SOC 1 report
• SOC 2 versus SOC 3
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
Overview of the
AICPA Framework
02
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
AICPA SOC Framework
Applicable SOC-1 SOC-2 SOC-3
Standard/Guidance
SSAE 16:
AICPA Guide (2013)
AT 101:
AICPA Guide (2013)
AT 101:
Technical Practice Aid
(2014)
Scope ICFR Security/Systems, Privacy Security/Systems, Privacy
Criteria Control Objectives
Trust Services
Principles/GAPP
Trust Services
Principles/GAPP
Usage of report
User auditor, user entity,
management of SO
Knowledgeable parties Anyone
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
Purpose
& Scope
03
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
Purpose
• What SOC 2 does cover?
• What SOC 2 does cover?
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
• System
• Boundaries
• Commitments
• System Requirements
Scope
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
Principles
• Security
• Availability
• Processing Integrity
• Confidentiality
• Privacy
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
Common Criteria (Security):
1: Organization & Mgmt
2: Communications
3: Risk Mgmt & Controls
4: Monitoring of Controls
5: Logical and Physical Access
6: System Operations
7: Change Management
Principles
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
Principles
Availability Common Criteria: +3
Processing Integrity Common Criteria: +6
Confidentiality Common Criteria: +6
Privacy Common Criteria: +74
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
• Type 1
• Type 2
Report Type
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
The
Anatomy
04
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
Service Auditor’s Report – “The Opinion”
Management’s Assertion
Description of the System
Tests of Controls and Corresponding Results
Additional Information – Provided by Service Organization
Report Structure
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
Unqualified vs. Qualified
Service Auditor’s Report
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
• Commitment - suitability and accuracy
• Subservice organizations
Management’s Assertion
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
• Management’s objective description of the
services provided to user entities
• Components of a System Description
System Description
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
• Test procedures
• Results
• Deviations / Exceptions
Test of Controls / Results
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
Intended Use
• Management of service organization
• User entities of the services
• Other knowledgeable parties
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
Considerations
05
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
Relevance To The User
• RFP requirements
• Customer mandates
• Regulatory needs
• Vendor management process
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
Understanding Reporting
• SOC 1 vs. SOC 2
• AT 101
• AT 601
• Agreed Upon Procedures
• Readiness Assessment
• PCI
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
Education & Preparedness
• Contracts, RFP, SLA
• AICPA website
• Training and awareness
• Executive communication
• Discussion with service auditor
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
Control Environment
• Start-up
• Developing systems
• No customers yet
• Lack of documentation /evidence
• No monitoring of controls
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
Carve-out Vs Inclusive
• Subservice organization
• Carve-out method emphasis
• Inclusive method requirements
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
Perform a risk assessment
Risk Assessment & Scope
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
• Internally
• Service auditors
Readiness Assessment
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
• Policies / Procedures
• Segregation of duties
• Monitoring
Remediation
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
• Licensed CPA firm
• Independent
• Single vendor approach
• Audit team
Audit Firm Selection
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
Mapping to Other
Standards
06
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
• SOC 1
• ISO 27001
• HIPAA
• HITRUST
• PCI
Other Standards
©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
View the WebinarView the Webinar

More Related Content

PPTX
SOC 2 Compliance and Certification
PDF
SOC 2 and You
PDF
SOC-2 Framework - Plan, Budget, Design, Integrate & Audit Security Controls
PDF
PPTX
HITRUST Certification
PPTX
SOC 2 presentation. Overview of SOC 2 assessment
PDF
EY Advisory Services
PPSX
GRC Governance, Risk mgmt. & Compliance Executive
SOC 2 Compliance and Certification
SOC 2 and You
SOC-2 Framework - Plan, Budget, Design, Integrate & Audit Security Controls
HITRUST Certification
SOC 2 presentation. Overview of SOC 2 assessment
EY Advisory Services
GRC Governance, Risk mgmt. & Compliance Executive

What's hot (20)

PDF
SOC2 Intro and Mindfulness
PPTX
CISSP - Chapter 1 - Security Concepts
PPT
isms-presentation.ppt
PPTX
Soc 2 attestation or ISO 27001 certification - Which is better for organization
PDF
ISO/IEC 27001:2013 An Overview
PDF
Cybersecurity Roadmap Development for Executives
PDF
Enterprise Cybersecurity: From Strategy to Operating Model
PDF
Cybersecurity roadmap : Global healthcare security architecture
PPTX
27001 awareness Training
PPTX
Introduction to PCI DSS
PDF
NIST cybersecurity framework
PPTX
SOC Architecture Workshop - Part 1
PPTX
Control Standards for Information Security
PDF
NIST Cybersecurity Framework 101
PPTX
New ISO 20000-1:2018 Changes, Implementation Steps
PDF
What is ISO 27001 ISMS
PPTX
Project plan for ISO 27001
PDF
SOC 1 Overview
PDF
Soc 2 vs iso 27001 certification withh links converted-converted
SOC2 Intro and Mindfulness
CISSP - Chapter 1 - Security Concepts
isms-presentation.ppt
Soc 2 attestation or ISO 27001 certification - Which is better for organization
ISO/IEC 27001:2013 An Overview
Cybersecurity Roadmap Development for Executives
Enterprise Cybersecurity: From Strategy to Operating Model
Cybersecurity roadmap : Global healthcare security architecture
27001 awareness Training
Introduction to PCI DSS
NIST cybersecurity framework
SOC Architecture Workshop - Part 1
Control Standards for Information Security
NIST Cybersecurity Framework 101
New ISO 20000-1:2018 Changes, Implementation Steps
What is ISO 27001 ISMS
Project plan for ISO 27001
SOC 1 Overview
Soc 2 vs iso 27001 certification withh links converted-converted
Ad

Similar to SOC 2: Build Trust and Confidence (20)

PDF
Hitrust: Navigating to 2017, Your Map to HITRUST Certification
PDF
CSA STAR Program
PDF
Salesforce.com Relaunch Featuring Customer Success Story From Aon
PPTX
Issues Management In The Digital Age
PPTX
Achieving SSAE 16 Certification
PDF
Facilities Management - Extending Service Automation to Outside Contractors
PDF
EPCS Overview
PPTX
Service Organizational Control (SOC 2) Compliance - Kloudlearn
PPTX
Empowering ACOs: Leveraging Quality Management Tools for MIPS and Beyond
PPTX
Innovation TVA Presentation Deck
PDF
CQS_ISO 2015_ASQR (4-16-15)
PDF
2016 AICPA Bank - CECL Governance
PPTX
Auditor Report on Controls to be used as Template.pptx
PDF
Cigniti joint webinar with Soasta - Agile DevOps: Test-driven IT Environment ...
PDF
PPTX
Customer Success in the Healthcare Industry
PDF
So CaTec 2015 metrics
PPTX
BSW Value of Muni Audits
PDF
The Future of Auditing and Fraud Detection
PDF
AgileCamp Silicon Valley 2015: Unlock Excellence with Agile Metrics
Hitrust: Navigating to 2017, Your Map to HITRUST Certification
CSA STAR Program
Salesforce.com Relaunch Featuring Customer Success Story From Aon
Issues Management In The Digital Age
Achieving SSAE 16 Certification
Facilities Management - Extending Service Automation to Outside Contractors
EPCS Overview
Service Organizational Control (SOC 2) Compliance - Kloudlearn
Empowering ACOs: Leveraging Quality Management Tools for MIPS and Beyond
Innovation TVA Presentation Deck
CQS_ISO 2015_ASQR (4-16-15)
2016 AICPA Bank - CECL Governance
Auditor Report on Controls to be used as Template.pptx
Cigniti joint webinar with Soasta - Agile DevOps: Test-driven IT Environment ...
Customer Success in the Healthcare Industry
So CaTec 2015 metrics
BSW Value of Muni Audits
The Future of Auditing and Fraud Detection
AgileCamp Silicon Valley 2015: Unlock Excellence with Agile Metrics
Ad

More from Schellman & Company (15)

PDF
Privacy in the Cloud- Introduction to ISO 27018
PDF
Demystifying the Cyber NISTs
PDF
Determining Scope for PCI DSS Compliance
PDF
Privacy shield: What You Need To Know About Storing EU Data
PDF
Everything You Need To Know About SOC 1
PDF
Work With Federal Agencies? Here's What You Should Know About FedRAMP Assessm...
PDF
PA-DSS and Application Penetration Testing
PDF
The CSA STAR Program: Certification & Attestation
PDF
Get Ready Now for HITRUST 2017
PDF
STAND OUT: Why You Should Become ISO 27001 Certified
PDF
Locking Up Your Cloud Environment: An Introduction to ISO/IEC 27017 and 27018
PDF
12 Steps to Preparing for a QAR
PDF
PCI DSS 3.0 Overview and Key Updates
PDF
10 Steps Toward FedRAMP Compliance
PDF
Your've Been Hacked in Florida! Now What?
Privacy in the Cloud- Introduction to ISO 27018
Demystifying the Cyber NISTs
Determining Scope for PCI DSS Compliance
Privacy shield: What You Need To Know About Storing EU Data
Everything You Need To Know About SOC 1
Work With Federal Agencies? Here's What You Should Know About FedRAMP Assessm...
PA-DSS and Application Penetration Testing
The CSA STAR Program: Certification & Attestation
Get Ready Now for HITRUST 2017
STAND OUT: Why You Should Become ISO 27001 Certified
Locking Up Your Cloud Environment: An Introduction to ISO/IEC 27017 and 27018
12 Steps to Preparing for a QAR
PCI DSS 3.0 Overview and Key Updates
10 Steps Toward FedRAMP Compliance
Your've Been Hacked in Florida! Now What?

Recently uploaded (20)

PPTX
breach-and-attack-simulation-cybersecurity-india-chennai-defenderrabbit-2025....
PPTX
Understanding_Digital_Forensics_Presentation.pptx
PPTX
Big Data Technologies - Introduction.pptx
PDF
Dropbox Q2 2025 Financial Results & Investor Presentation
PPT
“AI and Expert System Decision Support & Business Intelligence Systems”
PDF
Empathic Computing: Creating Shared Understanding
PDF
NewMind AI Monthly Chronicles - July 2025
PDF
GamePlan Trading System Review: Professional Trader's Honest Take
PDF
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
PDF
Advanced IT Governance
PDF
Advanced Soft Computing BINUS July 2025.pdf
PDF
Electronic commerce courselecture one. Pdf
PDF
NewMind AI Weekly Chronicles - August'25 Week I
PDF
Mobile App Security Testing_ A Comprehensive Guide.pdf
PDF
CIFDAQ's Market Insight: SEC Turns Pro Crypto
PDF
Chapter 3 Spatial Domain Image Processing.pdf
PDF
Unlocking AI with Model Context Protocol (MCP)
PDF
Review of recent advances in non-invasive hemoglobin estimation
PDF
Machine learning based COVID-19 study performance prediction
PPTX
20250228 LYD VKU AI Blended-Learning.pptx
breach-and-attack-simulation-cybersecurity-india-chennai-defenderrabbit-2025....
Understanding_Digital_Forensics_Presentation.pptx
Big Data Technologies - Introduction.pptx
Dropbox Q2 2025 Financial Results & Investor Presentation
“AI and Expert System Decision Support & Business Intelligence Systems”
Empathic Computing: Creating Shared Understanding
NewMind AI Monthly Chronicles - July 2025
GamePlan Trading System Review: Professional Trader's Honest Take
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
Advanced IT Governance
Advanced Soft Computing BINUS July 2025.pdf
Electronic commerce courselecture one. Pdf
NewMind AI Weekly Chronicles - August'25 Week I
Mobile App Security Testing_ A Comprehensive Guide.pdf
CIFDAQ's Market Insight: SEC Turns Pro Crypto
Chapter 3 Spatial Domain Image Processing.pdf
Unlocking AI with Model Context Protocol (MCP)
Review of recent advances in non-invasive hemoglobin estimation
Machine learning based COVID-19 study performance prediction
20250228 LYD VKU AI Blended-Learning.pptx

SOC 2: Build Trust and Confidence

  • 1. ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved SOC 2: Build Trust & Confidence Overview & Considerations
  • 2. ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved 01. Background / Overview of SOC 2 02. The AICPA Framework 03. Purpose and Scope 04. The Anatomy 05. Considerations 06. Mapping – Other Standards 06. Q/A Contents
  • 3. ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved Background & Overview 01 ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
  • 4. ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved Growth & Popularity ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
  • 5. ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved Service Auditors ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
  • 6. ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved Service Providers
  • 7. ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved User Entities
  • 8. ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved Why Do You Need a SOC Report? Regulatory requirements
  • 9. ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved Why Do You Need a SOC Report? Regulatory requirements User entity mandates
  • 10. ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved Why Do You Need a SOC Report? Regulatory requirements User entity mandates Vendor management programs
  • 11. ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved Why Do You Need a SOC Report? Regulatory requirements User entity mandates Vendor management programs Due diligence
  • 12. ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved Why Do You Need a SOC Report? Regulatory requirements User entity mandates Vendor management programs Due diligence Independent 3rd party opinion
  • 13. ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved Why Do You Need a SOC Report? Regulatory requirements User entity mandates Vendor management programs Due diligence Independent 3rd party opinion Competition and market
  • 14. ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved Overview • What is a SOC 2 report? • How does a SOC 2 differ from a SOC 1 report • SOC 2 versus SOC 3
  • 15. ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved Overview of the AICPA Framework 02 ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
  • 16. ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved AICPA SOC Framework Applicable SOC-1 SOC-2 SOC-3 Standard/Guidance SSAE 16: AICPA Guide (2013) AT 101: AICPA Guide (2013) AT 101: Technical Practice Aid (2014) Scope ICFR Security/Systems, Privacy Security/Systems, Privacy Criteria Control Objectives Trust Services Principles/GAPP Trust Services Principles/GAPP Usage of report User auditor, user entity, management of SO Knowledgeable parties Anyone
  • 17. ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved Purpose & Scope 03 ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
  • 18. ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved Purpose • What SOC 2 does cover? • What SOC 2 does cover?
  • 19. ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved • System • Boundaries • Commitments • System Requirements Scope
  • 20. ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved Principles • Security • Availability • Processing Integrity • Confidentiality • Privacy
  • 21. ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved Common Criteria (Security): 1: Organization & Mgmt 2: Communications 3: Risk Mgmt & Controls 4: Monitoring of Controls 5: Logical and Physical Access 6: System Operations 7: Change Management Principles
  • 22. ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved Principles Availability Common Criteria: +3 Processing Integrity Common Criteria: +6 Confidentiality Common Criteria: +6 Privacy Common Criteria: +74
  • 23. ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved • Type 1 • Type 2 Report Type
  • 24. ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved The Anatomy 04 ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
  • 25. ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved Service Auditor’s Report – “The Opinion” Management’s Assertion Description of the System Tests of Controls and Corresponding Results Additional Information – Provided by Service Organization Report Structure
  • 26. ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved Unqualified vs. Qualified Service Auditor’s Report
  • 27. ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved • Commitment - suitability and accuracy • Subservice organizations Management’s Assertion
  • 28. ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved • Management’s objective description of the services provided to user entities • Components of a System Description System Description
  • 29. ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved • Test procedures • Results • Deviations / Exceptions Test of Controls / Results
  • 30. ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved Intended Use • Management of service organization • User entities of the services • Other knowledgeable parties
  • 31. ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved Considerations 05 ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
  • 32. ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved Relevance To The User • RFP requirements • Customer mandates • Regulatory needs • Vendor management process
  • 33. ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved Understanding Reporting • SOC 1 vs. SOC 2 • AT 101 • AT 601 • Agreed Upon Procedures • Readiness Assessment • PCI
  • 34. ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved Education & Preparedness • Contracts, RFP, SLA • AICPA website • Training and awareness • Executive communication • Discussion with service auditor
  • 35. ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved Control Environment • Start-up • Developing systems • No customers yet • Lack of documentation /evidence • No monitoring of controls
  • 36. ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved Carve-out Vs Inclusive • Subservice organization • Carve-out method emphasis • Inclusive method requirements
  • 37. ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved Perform a risk assessment Risk Assessment & Scope
  • 38. ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved • Internally • Service auditors Readiness Assessment
  • 39. ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved • Policies / Procedures • Segregation of duties • Monitoring Remediation
  • 40. ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved • Licensed CPA firm • Independent • Single vendor approach • Audit team Audit Firm Selection
  • 41. ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved Mapping to Other Standards 06 ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved
  • 42. ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved • SOC 1 • ISO 27001 • HIPAA • HITRUST • PCI Other Standards
  • 43. ©2015 BrightLine CPAs & Associates, Inc. All Rights Reserved View the WebinarView the Webinar