ISMS Copilot Docs

SOC 2-ontwerp en implementatie van controles

Gebruik deze prompts om controles te ontwerpen, documenteren en implementeren die voldoen aan de Trust Services Criteria en effectieve werking aantonen aan auditors.

Ontwerpen van SOC 2-controles

Gebruik deze prompts om controles te ontwerpen, documenteren en implementeren die voldoen aan de Trust Services Criteria en effectieve werking aantonen aan auditors.

Ontwikkeling van de controlematrix

Volledige controlematrix

Create a comprehensive SOC 2 control matrix for [organization name] covering [list applicable criteria: Security, Availability, etc.]. For each Trust Services Criterion in scope, provide:
- Criterion reference (e.g., CC6.1)
- Control objective
- Our control activity description
- Control type (preventive/detective/corrective)
- Control frequency (continuous/daily/monthly/quarterly/annual)
- Control owner (role)
- Evidence of operation

Our environment: [describe systems, organization size, tech stack]
Audit type: [Type I or Type II]

Risicogebaseerde prioritering van controles

Help me prioritize SOC 2 control implementation based on risk. Analyze:
- Our risk assessment results: [summarize key risks]
- Criteria in scope: [Security, Availability, etc.]
- Current control maturity: [describe current state]
- Time to audit: [months until readiness assessment]
- Resource constraints: [team size, budget]

Provide a prioritized control implementation roadmap with quick wins and critical controls.

Begin met de Security Common Criteria (CC1-CC9), aangezien deze verplicht zijn voor alle SOC 2-audits, en voeg vervolgens criteria-specifieke controles toe.

Common Criteria-controles

Beheersomgeving (CC1)

Design controls for CC1 (Control Environment) addressing:
- CC1.1 (integrity and ethical values): Code of conduct, ethics training
- CC1.2 (board oversight): [describe your governance structure]
- CC1.3 (organizational structure): Roles and responsibilities for security
- CC1.4 (competence): Training and qualification requirements
- CC1.5 (accountability): Performance management and enforcement

Our organization:
- Size: [employee count]
- Governance: [board structure, committees]
- Leadership: [who owns security/compliance]

Communicatie en informatie (CC2)

Create controls for CC2 (Communication and Information) covering:
- CC2.1 (security objectives): Hoe we beveiligingsdoelen communiceren
- CC2.2 (internal communication): [tools en kanalen voor beveiligingscommunicatie]
- CC2.3 (external communication): Communicatie over beveiliging met klanten en leveranciers

Include specific control activities, frequency, and responsible parties for our environment: [describe communication channels and stakeholders]

Risicobeoordeling (CC3)

Design a risk assessment control framework for CC3.1 through CC3.4:
- CC3.1 (objectives): Service commitment and system requirements
- CC3.2 (risk identification): Methodologie voor het identificeren van bedreigingen
- CC3.3 (risk analysis): Beoordeling van waarschijnlijkheid en impact
- CC3.4 (fraud risk): Frauderisicoscenario's specifiek voor [your service type]

Our risk profile:
- Service type: [SaaS/PaaS/other]
- Threat landscape: [industrie-specifieke bedreigingen]
- Previous incidents: [if any]

Provide control descriptions, frequency (hoe vaak risicobeoordelingen plaatsvinden), en deliverables.

Monitoringactiviteiten (CC4)

Generate monitoring controls for CC4.1 and CC4.2:
- CC4.1 (ongoing monitoring): Continue monitoring van [list key systems/controls]
- CC4.2 (remediation): Proces voor het aanpakken van tekortkomingen

Include:
- Monitoring tools: [SIEM, log management, vulnerability scanners]
- Metrics and dashboards
- Review frequency and responsibilities
- Escalation and remediation workflows

Current monitoring capabilities: [describe existing tools and practices]

Beheersactiviteiten (CC5)

Design control activities for CC5.1 through CC5.3:
- CC5.1 (selection and development): Selectie van technologische controles
- CC5.2 (general controls): Algemene IT-controles (toegang, wijzigingen, back-ups)
- CC5.3 (deployment): Implementatie en configuratie van controles

Technology environment:
- Infrastructure: [cloud/on-prem/hybrid]
- Key technologies: [AWS/Azure/GCP, databases, applications]
- Automation level: [manual/semi-automated/fully automated]

For each control, specify the technology involved, how it operates, and who maintains it.

Logische en fysieke toegang (CC6)

Create detailed access control controls for CC6.1 through CC6.8:
- CC6.1 (access management): Proces voor inrichten en intrekken van toegang
- CC6.2 (authentication): [MFA-vereisten, wachtwoordstandaarden]
- CC6.3 (provisioning/deprovisioning): Workflow voor indiensttreding, overplaatsing en vertrek
- CC6.6 (physical access): [beveiliging van datacenters/kantoren indien van toepassing]
- CC6.7 (access reviews): Kwartaalbeoordelingen van toegangsrechten
- CC6.8 (credentials): Beheer van bevoorrechte toegang

Our access landscape:
- User count: [totaal aantal gebruikers, beheerdersgebruikers]
- Systems: [SSO, directory services, tools voor bevoorrechte toegang]
- Physical locations: [kantoorlocaties, datacenters]

Include who performs access reviews, what evidence is retained, and how exceptions are handled.

Systeemoperaties (CC7)

Design system operations controls for CC7.1 through CC7.5:
- CC7.1 (change detection): Bestandsintegriteitsmonitoring, detectie van configuratiedrift
- CC7.2 (security incidents): Detectie en melding van incidenten
- CC7.3 (incident response): Responsprotocollen en procedures
- CC7.4 (incident mitigation): Inperking en herstel
- CC7.5 (logging): [logbronnen, retentie: X maanden/jaren]

Our operations:
- Monitoring tools: [SIEM, IDS/IPS, EDR]
- Incident history: [soorten incidenten die zijn opgetreden]
- Log infrastructure: [gecentraliseerd loggen, SIEM]

Specify how each control operates, evidence generated, and responsible teams.

Wijzigingsbeheer (CC8)

Create change management controls for CC8.1:
- Workflow voor wijzigingsverzoeken en goedkeuring
- Wijzigingscategorieën: [standaard/normaal/urgent]
- Testvereisten: [ontwikkel-/test-/productieomgeving]
- Implementatiecontroles: [CI/CD-controlepunten, goedkeuringen]
- Terugdraaiprocedures
- Validatie na implementatie

Our development environment:
- Methodology: [Agile/Waterfall/DevOps]
- Release frequency: [continu/wekelijks/maandelijks]
- Tools: [Jira, ServiceNow, GitHub, Jenkins, etc.]

Detail the control at each stage (request → approval → testing → deployment → validation) and who is responsible.

Risicomitigatie (CC9)

Design risk mitigation controls for CC9.1 and CC9.2:
- CC9.1 (backups, disaster recovery): Back-up- en DR-procedures
- CC9.2 (vendor management): Beheer van risico's van derden

Backup and DR:
- Backup frequency: [dagelijkse incrementele, wekelijkse volledige back-ups]
- Retention: [30 dagen online, 1 jaar archief]
- DR testing: [jaarlijks/halfjaarlijks]
- RTO/RPO: [doelstellingen]

Vendor management:
- Critical vendors: [lijst van belangrijke onderaannemers]
- Due diligence: [beoordeling van SOC 2-rapporten, beveiligingsbeoordelingen]
- Contract requirements: [auditrechten, SLA's]
- Monitoring: [jaarlijkse beoordelingen]

Provide detailed control descriptions with specific activities, frequency, and evidence.

Beschikbaarheidscontroles

Set van beschikbaarheidscontroles

Generate controls specific to SOC 2 Availability criteria (A1.1, A1.2, A1.3):
- A1.1 (availability objectives): Beschikbaarheidsdoelstellingen en meting
- A1.2 (capacity): Capaciteitsmonitoring, planning en schaling
- A1.3 (monitoring and incident response): Beheer van beschikbaarheidsincidenten

Our availability commitments:
- SLA: [99,9% uptime of specifieke toezegging]
- Systems: [productieservices binnen scope]
- Infrastructure: [cloudprovider, redundantiebenadering]
- Historical performance: [beschikbaarheidsmetingen uit het verleden]

For each control, specify monitoring tools, thresholds, escalation, and how we demonstrate compliance.

Verwerkingsintegriteitscontroles

Set van verwerkingsintegriteitscontroles

Create controls for SOC 2 Processing Integrity criteria (PI1.1 through PI1.5):
- PI1.1 (processing objectives): Doelstellingen voor nauwkeurigheid en volledigheid
- PI1.2 (inputs): Validatie en autorisatie van invoer
- PI1.3 (processing): Controles op verwerkingslogica en foutafhandeling
- PI1.4 (outputs): Validatie en afstemming van uitvoer
- PI1.5 (data stores): Integriteitscontroles voor gegevensopslag

Our processing environment:
- Processing activities: [betalingsverwerking, gegevenstransformatie, berekeningen]
- Input sources: [API's, bestandsuploads, handmatige invoer]
- Validation requirements: [regelgevende of bedrijfsregels]
- Reconciliation frequency: [real-time/dagelijks/maandelijks]

Describe automated and manual controls, validation rules, and exception handling.

Vertrouwelijkheidscontroles

Set van vertrouwelijkheidscontroles

Design controls for SOC 2 Confidentiality criteria (C1.1, C1.2):
- C1.1 (confidential information): Identificatie en classificatie
- C1.2 (disposal): Veilige verwijdering en vernietiging

Confidential data we handle:
- Data types: [eigendomsgegevens van klanten, bedrijfsgeheimen, financiële gegevens]
- Storage locations: [databases, bestandssystemen, back-ups]
- Encryption: [standaarden voor versleuteling in rust en tijdens transport]
- Retention periods: [per gegevenstype]

Include data classification scheme, encryption controls, access restrictions, and secure disposal procedures with evidence of execution.

Privacycontroles

Set van privacycontroles

Generate controls for SOC 2 Privacy criteria (P1.0 through P8.0):
- P1.0 (notice): Verstrekking en updates van het privacybeleid
- P2.0 (choice and consent): Verzameling en beheer van toestemming
- P3.0 (collection): Gegevensminimalisatie en doelbinding
- P4.0 (use, retention, disposal): Handhaving van bewaartermijnen
- P5.0 (access): Afhandeling van verzoeken tot inzage door betrokkenen
- P6.0 (disclosure to third parties): Controles op gegevensdeling met derden
- P7.0 (security): Privacy-specifieke beveiligingscontroles
- P8.0 (quality): Nauwkeurigheid en correctie van gegevens

Our privacy landscape:
- Personal data: [verzamelde categorieën]
- Data subjects: [klanten, medewerkers, eindgebruikers]
- Regulations: [GDPR, CCPA, andere]
- Privacy tools: [consent management, DSR-platforms]

For each principle, provide specific controls, automation where possible, and evidence of operation.

Privacycontroles overlappen vaak met beveiligings- en vertrouwelijkheidscontroles. Documenteer deze overlappingen om dubbele bewijsverzameling tijdens audits te voorkomen.

Testen en validatie van controles

Beoordeling van controleontwerp

Evaluate the design of my control for [Trust Services Criterion reference]:

Control description:
[Paste your control description]

Assess:
- Voldoet deze controle adequaat aan de vereisten en aandachtspunten van het criterium?
- Zijn er ontwerpgaten of zwakke punten?
- Is de controlefrequentie geschikt?
- Is de rol van de controle-eigenaar passend?
- Welk bewijs moet deze controle genereren?

Provide recommendations for strengthening the control design.

Planning van operationele effectiviteit

I need to demonstrate operating effectiveness for my SOC 2 Type II audit covering [date range]. For control [control ID/description]:
- Control frequency: [daily/monthly/quarterly]
- Control type: [automated/manual/hybrid]
- Evidence generated: [logs, tickets, approvals, reports]

Help me plan:
- Steekproefgrootte die auditors verwachten (voor handmatige controles)
- Bewaartermijn en organisatie van bewijsmateriaal
- Documentatie van uitzonderingen en hoe deze zijn opgelost
- Testaanpak om effectiviteit vóór de audit te valideren

Provide a testing plan and evidence checklist.

Voor Type II-audits moeten controles gedurende de hele auditperiode (meestal 3-12 maanden) effectief functioneren. Plan de bewijsverzameling vanaf dag één, niet pas vlak voor de audit.

Automatisering van controles

Automatiseringsmogelijkheden

Review my control set for [criteria in scope] and identify automation opportunities:

Current controls:
[List your controls and whether they're manual/automated]

Available technologies:
[List tools and platforms you have: SIEM, IaC, policy-as-code, etc.]

Recommend:
- Which controls can be fully automated
- Tools or scripts to implement automation
- Continuous compliance approaches
- How automation improves audit evidence quality

Prioritize by impact and implementation effort.

Geautomatiseerde controles leveren sterker en consistenter auditbewijs dan handmatige controles. Prioriteer automatisering voor hoogfrequente controles en controles die gevoelig zijn voor menselijke fouten.

On this page