ISMS Copilot Docs

Wskazówki dotyczące projektowania i wdrażania kontroli SOC 2

Wykorzystaj te wskazówki, aby zaprojektować, udokumentować i wdrożyć kontrole spełniające Kryteria Usług Zaufania oraz wykazać ich skuteczne działanie audytorom.

Projektowanie kontroli SOC 2

Wykorzystaj te wskazówki, aby zaprojektować, udokumentować i wdrożyć kontrole spełniające Kryteria Usług Zaufania oraz wykazać ich skuteczne działanie audytorom.

Tworzenie matrycy kontroli

Kompletna matryca kontroli

Create a comprehensive SOC 2 control matrix for [organization name] covering [list applicable criteria: Security, Availability, etc.]. For each Trust Services Criterion in scope, provide:
- Criterion reference (e.g., CC6.1)
- Control objective
- Our control activity description
- Control type (preventive/detective/corrective)
- Control frequency (continuous/daily/monthly/quarterly/annual)
- Control owner (role)
- Evidence of operation

Our environment: [describe systems, organization size, tech stack]
Audit type: [Type I or Type II]

Priorytetyzacja kontroli oparta na ryzyku

Help me prioritize SOC 2 control implementation based on risk. Analyze:
- Our risk assessment results: [summarize key risks]
- Criteria in scope: [Security, Availability, etc.]
- Current control maturity: [describe current state]
- Time to audit: [months until readiness assessment]
- Resource constraints: [team size, budget]

Provide a prioritized control implementation roadmap with quick wins and critical controls.

Rozpocznij od Kryteriów Wspólnych Bezpieczeństwa (CC1-CC9), ponieważ są one obowiązkowe we wszystkich audytach SOC 2, a następnie dodaj kontrole specyficzne dla dodatkowych kryteriów.

Kontrole Kryteriów Wspólnych

Środowisko kontroli (CC1)

Design controls for CC1 (Control Environment) addressing:
- CC1.1 (integrity and ethical values): Code of conduct, ethics training
- CC1.2 (board oversight): [describe your governance structure]
- CC1.3 (organizational structure): Roles and responsibilities for security
- CC1.4 (competence): Training and qualification requirements
- CC1.5 (accountability): Performance management and enforcement

Our organization:
- Size: [employee count]
- Governance: [board structure, committees]
- Leadership: [who owns security/compliance]

Komunikacja i informacja (CC2)

Create controls for CC2 (Communication and Information) covering:
- CC2.1 (security objectives): Jak komunikujemy cele bezpieczeństwa
- CC2.2 (internal communication): [tools and channels for security communications]
- CC2.3 (external communication): Komunikacja bezpieczeństwa z klientami/dostawcami

Include specific control activities, frequency, and responsible parties for our environment: [describe communication channels and stakeholders]

Ocena ryzyka (CC3)

Design a risk assessment control framework for CC3.1 through CC3.4:
- CC3.1 (objectives): Zobowiązanie do świadczenia usług i wymagania systemowe
- CC3.2 (risk identification): Metodologia identyfikacji zagrożeń
- CC3.3 (risk analysis): Ocena prawdopodobieństwa i wpływu
- CC3.4 (fraud risk): Scenariusze ryzyka oszustw specyficzne dla [your service type]

Our risk profile:
- Service type: [SaaS/PaaS/other]
- Threat landscape: [industry-specific threats]
- Previous incidents: [if any]

Provide control descriptions, frequency (how often risk assessments occur), and deliverables.

Działania monitorujące (CC4)

Generate monitoring controls for CC4.1 and CC4.2:
- CC4.1 (ongoing monitoring): Ciągłe monitorowanie [list key systems/controls]
- CC4.2 (remediation): Proces rozwiązywania niedociągnięć

Include:
- Monitoring tools: [SIEM, log management, vulnerability scanners]
- Metrics and dashboards
- Review frequency and responsibilities
- Escalation and remediation workflows

Current monitoring capabilities: [describe existing tools and practices]

Działania kontrolne (CC5)

Design control activities for CC5.1 through CC5.3:
- CC5.1 (selection and development): Wybór kontroli technologicznych
- CC5.2 (general controls): Ogólne kontrole IT (dostęp, zmiany, kopie zapasowe)
- CC5.3 (deployment): Wdrażanie i konfiguracja kontroli

Technology environment:
- Infrastructure: [cloud/on-prem/hybrid]
- Key technologies: [AWS/Azure/GCP, databases, applications]
- Automation level: [manual/semi-automated/fully automated]

For each control, specify the technology involved, how it operates, and who maintains it.

Logiczny i fizyczny dostęp (CC6)

Create detailed access control controls for CC6.1 through CC6.8:
- CC6.1 (access management): Procesy provisioningu/deprovisioningu
- CC6.2 (authentication): [MFA requirements, password standards]
- CC6.3 (provisioning/deprovisioning): Procesy dla nowych pracowników, zmian stanowisk i odejść
- CC6.6 (physical access): [data center/office security if applicable]
- CC6.7 (access reviews): Kwartalne przeglądy dostępu
- CC6.8 (credentials): Zarządzanie dostępem uprzywilejowanym

Our access landscape:
- User count: [total users, admin users]
- Systems: [SSO, directory services, privileged access tools]
- Physical locations: [office locations, data centers]

Include who performs access reviews, what evidence is retained, and how exceptions are handled.

Operacje systemowe (CC7)

Design system operations controls for CC7.1 through CC7.5:
- CC7.1 (change detection): Monitorowanie integralności plików, wykrywanie dryfu konfiguracji
- CC7.2 (security incidents): Wykrywanie i alertowanie incydentów
- CC7.3 (incident response): Playbooki i procedury reagowania
- CC7.4 (incident mitigation): Izolacja i naprawa
- CC7.5 (logging): [log sources, retention: X months/years]

Our operations:
- Monitoring tools: [SIEM, IDS/IPS, EDR]
- Incident history: [types of incidents experienced]
- Log infrastructure: [centralized logging, SIEM]

Specify how each control operates, evidence generated, and responsible teams.

Zarządzanie zmianami (CC8)

Create change management controls for CC8.1:
- Change request and approval workflow
- Change categories: [standard/normal/emergency]
- Testing requirements: [dev/staging/production pipeline]
- Deployment controls: [CI/CD gates, approvals]
- Backout procedures
- Post-implementation validation

Our development environment:
- Methodology: [Agile/Waterfall/DevOps]
- Release frequency: [continuous/weekly/monthly]
- Tools: [Jira, ServiceNow, GitHub, Jenkins, etc.]

Detail the control at each stage (request → approval → testing → deployment → validation) and who is responsible.

Łagodzenie ryzyka (CC9)

Design risk mitigation controls for CC9.1 and CC9.2:
- CC9.1 (backups, disaster recovery): Procedury tworzenia kopii zapasowych i odtwarzania po awarii
- CC9.2 (vendor management): Zarządzanie ryzykiem stron trzecich

Backup and DR:
- Backup frequency: [daily incremental, weekly full]
- Retention: [30 days online, 1 year archive]
- DR testing: [annual/semi-annual]
- RTO/RPO: [targets]

Vendor management:
- Critical vendors: [list key subservice organizations]
- Due diligence: [SOC 2 report review, security assessments]
- Contract requirements: [audit rights, SLAs]
- Monitoring: [annual reviews]

Provide detailed control descriptions with specific activities, frequency, and evidence.

Kontrole Dostępności

Zestaw kontroli Dostępności

Generate controls specific to SOC 2 Availability criteria (A1.1, A1.2, A1.3):
- A1.1 (availability objectives): Cele dotyczące dostępności i pomiar
- A1.2 (capacity): Monitorowanie pojemności, planowanie i skalowanie
- A1.3 (monitoring and incident response): Zarządzanie incydentami dostępności

Our availability commitments:
- SLA: [99.9% uptime or specific commitment]
- Systems: [production services in scope]
- Infrastructure: [cloud provider, redundancy approach]
- Historical performance: [past availability metrics]

For each control, specify monitoring tools, thresholds, escalation, and how we demonstrate compliance.

Kontrole Integralności Przetwarzania

Zestaw kontroli Integralności Przetwarzania

Create controls for SOC 2 Processing Integrity criteria (PI1.1 through PI1.5):
- PI1.1 (processing objectives): Cele dotyczące dokładności i kompletności
- PI1.2 (inputs): Walidacja i autoryzacja danych wejściowych
- PI1.3 (processing): Kontrole logiki przetwarzania i obsługi błędów
- PI1.4 (outputs): Walidacja i uzgadnianie danych wyjściowych
- PI1.5 (data stores): Kontrole integralności danych

Our processing environment:
- Processing activities: [payment processing, data transformation, calculations]
- Input sources: [APIs, file uploads, manual entry]
- Validation requirements: [regulatory or business rules]
- Reconciliation frequency: [real-time/daily/monthly]

Describe automated and manual controls, validation rules, and exception handling.

Kontrole Poufności

Zestaw kontroli Poufności

Design controls for SOC 2 Confidentiality criteria (C1.1, C1.2):
- C1.1 (confidential information): Identyfikacja i klasyfikacja
- C1.2 (disposal): Bezpieczne usuwanie i niszczenie

Confidential data we handle:
- Data types: [customer proprietary data, trade secrets, financial data]
- Storage locations: [databases, file systems, backups]
- Encryption: [at rest, in transit standards]
- Retention periods: [by data type]

Include data classification scheme, encryption controls, access restrictions, and secure disposal procedures with evidence of execution.

Kontrole Prywatności

Zestaw kontroli Prywatności

Generate controls for SOC 2 Privacy criteria (P1.0 through P8.0):
- P1.0 (notice): Dostarczanie i aktualizacja informacji o prywatności
- P2.0 (choice and consent): Zbieranie i zarządzanie zgodami
- P3.0 (collection): Minimalizacja danych i ograniczenie celu
- P4.0 (use, retention, disposal): Egzekwowanie harmonogramu przechowywania
- P5.0 (access): Obsługa żądań dostępu podmiotów danych
- P6.0 (disclosure to third parties): Kontrole udostępniania danych stronom trzecim
- P7.0 (security): Kontrole bezpieczeństwa specyficzne dla prywatności
- P8.0 (quality): Dokładność danych i korekta

Our privacy landscape:
- Personal data: [categories collected]
- Data subjects: [customers, employees, end users]
- Regulations: [GDPR, CCPA, other]
- Privacy tools: [consent management, DSR platforms]

For each principle, provide specific controls, automation where possible, and evidence of operation.

Kontrole prywatności często pokrywają się z kontrolami Bezpieczeństwa i Poufności. Udokumentuj te nakładania, aby uniknąć dublowania zbierania dowodów podczas audytów.

Testowanie i walidacja kontroli

Ocena projektu kontroli

Evaluate the design of my control for [Trust Services Criterion reference]:

Control description:
[Paste your control description]

Assess:
- Czy ta kontrola odpowiednio adresuje wymagania kryterium i punkty skupienia?
- Czy występują luki lub słabości w projekcie?
- Czy częstotliwość kontroli jest odpowiednia?
- Czy rola właściciela kontroli jest odpowiednia?
- Jakie dowody powinna generować ta kontrola?

Provide recommendations for strengthening the control design.

Planowanie skuteczności operacyjnej

I need to demonstrate operating effectiveness for my SOC 2 Type II audit covering [date range]. For control [control ID/description]:
- Control frequency: [daily/monthly/quarterly]
- Control type: [automated/manual/hybrid]
- Evidence generated: [logs, tickets, approvals, reports]

Help me plan:
- Wielkość próby, jakiej oczekują audytorzy (dla kontroli manualnych)
- Przechowywanie i organizacja dowodów
- Dokumentacja wyjątków i sposobu ich rozwiązania
- Podejście do testowania w celu walidacji skuteczności przed audytem

Provide a testing plan and evidence checklist.

W audytach Type II kontrole muszą działać skutecznie przez cały okres audytu (zazwyczaj 3-12 miesięcy). Planuj zbieranie dowodów od pierwszego dnia, a nie tylko przed audytem.

Automatyzacja kontroli

Możliwości automatyzacji

Review my control set for [criteria in scope] and identify automation opportunities:

Current controls:
[List your controls and whether they're manual/automated]

Available technologies:
[List tools and platforms you have: SIEM, IaC, policy-as-code, etc.]

Recommend:
- Which controls can be fully automated
- Tools or scripts to implement automation
- Continuous compliance approaches
- How automation improves audit evidence quality

Prioritize by impact and implementation effort.

Zautomatyzowane kontrole dostarczają silniejszych i bardziej spójnych dowodów audytowych niż kontrole manualne. Priorytetyzuj automatyzację dla kontroli o wysokiej częstotliwości oraz tych podatnych na błędy ludzkie.

On this page