Overview of AICPA SOC 2
SOC 2 is an attestation framework developed by the American Institute of Certified Public Accountants (AICPA). It evaluates an organization’s controls against the AICPA Trust Services Criteria. The Trust Services Criteria cover five areas:- Security: Protection of systems and information against unauthorized access, disclosure, damage, or disruption.
- Availability: Controls supporting the availability and operational performance of systems as committed to customers.
- Processing Integrity: Controls designed to ensure that system processing is complete, valid, accurate, timely, and authorized.
- Confidentiality: Protection of information designated as confidential throughout its lifecycle.
- Privacy: Controls relating to the collection, use, retention, disclosure, and disposal of personal information.
SOC 2 and Condense
Condense is Zeliot’s real-time data streaming and application platform, designed to support enterprise workloads that require reliable data movement and processing. SOC 2 controls supporting Condense address relevant aspects of:- Platform and infrastructure security
- Logical and physical access controls
- Protection of customer information
- System monitoring and operational controls
- Change management
- Risk management
- Incident response
- Availability and business continuity
- Vendor and third-party risk management
- Data protection and confidentiality
What SOC 2 Means for Condense Customers
For enterprises using Condense as part of their real-time data infrastructure, SOC 2 provides an independently assessed framework for understanding how controls are designed and operated to address relevant Trust Services Criteria. This includes:- Security Controls to protect systems and information from unauthorized access and other security threats.
- Access Management through defined processes for authentication, authorization, and management of access to systems and information.
- Change Management through controlled processes for changes to systems and platform components.
- Monitoring and Incident Management through processes for identifying, managing, and responding to security and operational events.
- Availability Controls supporting the reliable operation of systems and services within the applicable examination scope.
- Data Protection through controls designed to safeguard customer and confidential information.
- Vendor Management through processes for identifying and managing relevant risks associated with third-party service providers.
SOC 2 Compliance
SOC 2 is maintained through a structured program of controls, monitoring, assessment, and continuous improvement. Key activities include:- Ongoing monitoring of security and operational controls
- Periodic risk assessments
- Access reviews
- Security and operational monitoring
- Incident management and response
- Change management
- Vendor and third-party risk management
- Business continuity planning
- Internal control reviews and remediation
Certification and Examination Details
SOC 2 is an attestation report, rather than an ISO-style certification. The specific SOC 2 report should be referenced for the applicable:- Report Type: SOC 2 Type I or SOC 2 Type II
- Examination Period: Applicable reporting period
- Trust Services Criteria: Criteria included within the examination scope
- Service Organization: Zeliot Connected Services Pvt. Ltd.
- System or Service: Condense and applicable supporting systems
- Independent Service Auditor: As identified in the SOC 2 report