Article

The Truth About Audits

Jemurai

The Compass:

More posts

Article
SOC 2® Reports and Penetration Tests

We get asked a lot about whether penetration testing is required to complete a SOC 2 report. Our latest article explores this question and more.

READ MORE
Article
Mike DeKock on Building Competitive Advantage

How do the value creation principles of subjective value, entrepreneurship and creativity apply in a highly technical rules-based environment like SOC Compliance audits. These are objective validations of data security measures based on customer-defined criteria similar to traditional financial audits but more specific and subjective.

READ MORE
Blog Post
7 min read
What controls are required for SOC 2® reports?

There is nuance to this question, and other well-meaning and very smart people that I respect might give a different answer. But within the volumes of literature that set the standards, the true answer is this: There are absolutely no control requirements for SOC 2 reports.

READ MORE