ISMS Copilot Docs

Підказки для розробки та впровадження контролів SOC 2

Використовуйте ці підказки для розробки, документування та впровадження контролів, які відповідають Критеріям довірчих послуг і демонструють їх ефективну роботу аудиторам.

Розробка контролів SOC 2

Використовуйте ці підказки для розробки, документування та впровадження контролів, які відповідають Критеріям довірчих послуг і демонструють їх ефективну роботу аудиторам.

Розробка матриці контролів

Повна матриця контролів

Create a comprehensive SOC 2 control matrix for [organization name] covering [list applicable criteria: Security, Availability, etc.]. For each Trust Services Criterion in scope, provide:
- Criterion reference (e.g., CC6.1)
- Control objective
- Our control activity description
- Control type (preventive/detective/corrective)
- Control frequency (continuous/daily/monthly/quarterly/annual)
- Control owner (role)
- Evidence of operation

Our environment: [describe systems, organization size, tech stack]
Audit type: [Type I or Type II]

Пріоритизація контролів на основі ризиків

Help me prioritize SOC 2 control implementation based on risk. Analyze:
- Our risk assessment results: [summarize key risks]
- Criteria in scope: [Security, Availability, etc.]
- Current control maturity: [describe current state]
- Time to audit: [months until readiness assessment]
- Resource constraints: [team size, budget]

Provide a prioritized control implementation roadmap with quick wins and critical controls.

Почніть з Загальних критеріїв безпеки (CC1-CC9), оскільки вони є обов'язковими для всіх аудитів SOC 2, а потім додайте додаткові контролі, специфічні для критеріїв.

Контролі загальних критеріїв

Контрольне середовище (CC1)

Design controls for CC1 (Control Environment) addressing:
- CC1.1 (integrity and ethical values): Code of conduct, ethics training
- CC1.2 (board oversight): [describe your governance structure]
- CC1.3 (organizational structure): Roles and responsibilities for security
- CC1.4 (competence): Training and qualification requirements
- CC1.5 (accountability): Performance management and enforcement

Our organization:
- Size: [employee count]
- Governance: [board structure, committees]
- Leadership: [who owns security/compliance]

Комунікація та інформація (CC2)

Create controls for CC2 (Communication and Information) covering:
- CC2.1 (security objectives): Як ми повідомляємо про цілі безпеки
- CC2.2 (internal communication): [tools and channels for security communications]
- CC2.3 (external communication): Комунікація з клієнтами та постачальниками щодо безпеки

Include specific control activities, frequency, and responsible parties for our environment: [describe communication channels and stakeholders]

Оцінка ризиків (CC3)

Design a risk assessment control framework for CC3.1 through CC3.4:
- CC3.1 (objectives): Зобов'язання щодо послуг та вимоги до системи
- CC3.2 (risk identification): Методологія виявлення загроз
- CC3.3 (risk analysis): Оцінка ймовірності та впливу
- CC3.4 (fraud risk): Сценарії ризиків шахрайства, специфічні для [your service type]

Our risk profile:
- Service type: [SaaS/PaaS/other]
- Threat landscape: [industry-specific threats]
- Previous incidents: [if any]

Provide control descriptions, frequency (how often risk assessments occur), and deliverables.

Моніторингові заходи (CC4)

Generate monitoring controls for CC4.1 and CC4.2:
- CC4.1 (ongoing monitoring): Безперервний моніторинг [list key systems/controls]
- CC4.2 (remediation): Процес усунення недоліків

Include:
- Monitoring tools: [SIEM, log management, vulnerability scanners]
- Metrics and dashboards
- Review frequency and responsibilities
- Escalation and remediation workflows

Current monitoring capabilities: [describe existing tools and practices]

Контрольні заходи (CC5)

Design control activities for CC5.1 through CC5.3:
- CC5.1 (selection and development): Вибір технологічних контролів
- CC5.2 (general controls): Загальні ІТ-контролі (доступ, зміни, резервне копіювання)
- CC5.3 (deployment): Впровадження та налаштування контролів

Technology environment:
- Infrastructure: [cloud/on-prem/hybrid]
- Key technologies: [AWS/Azure/GCP, databases, applications]
- Automation level: [manual/semi-automated/fully automated]

For each control, specify the technology involved, how it operates, and who maintains it.

Логічний та фізичний доступ (CC6)

Create detailed access control controls for CC6.1 through CC6.8:
- CC6.1 (access management): Процес надання/скасування доступу
- CC6.2 (authentication): [MFA requirements, password standards]
- CC6.3 (provisioning/deprovisioning): Робочий процес для нових співробітників, переміщень та звільнень
- CC6.6 (physical access): [data center/office security if applicable]
- CC6.7 (access reviews): Щоквартальні перевірки доступу
- CC6.8 (credentials): Управління привілейованим доступом

Our access landscape:
- User count: [total users, admin users]
- Systems: [SSO, directory services, privileged access tools]
- Physical locations: [office locations, data centers]

Include who performs access reviews, what evidence is retained, and how exceptions are handled.

Системні операції (CC7)

Design system operations controls for CC7.1 through CC7.5:
- CC7.1 (change detection): Моніторинг цілісності файлів, виявлення відхилень конфігурації
- CC7.2 (security incidents): Виявлення та оповіщення про інциденти безпеки
- CC7.3 (incident response): Плани та процедури реагування на інциденти
- CC7.4 (incident mitigation): Локалізація та усунення наслідків
- CC7.5 (logging): [log sources, retention: X months/years]

Our operations:
- Monitoring tools: [SIEM, IDS/IPS, EDR]
- Incident history: [types of incidents experienced]
- Log infrastructure: [centralized logging, SIEM]

Specify how each control operates, evidence generated, and responsible teams.

Управління змінами (CC8)

Create change management controls for CC8.1:
- Change request and approval workflow
- Change categories: [standard/normal/emergency]
- Testing requirements: [dev/staging/production pipeline]
- Deployment controls: [CI/CD gates, approvals]
- Backout procedures
- Post-implementation validation

Our development environment:
- Methodology: [Agile/Waterfall/DevOps]
- Release frequency: [continuous/weekly/monthly]
- Tools: [Jira, ServiceNow, GitHub, Jenkins, etc.]

Detail the control at each stage (request → approval → testing → deployment → validation) and who is responsible.

Пом'якшення ризиків (CC9)

Design risk mitigation controls for CC9.1 and CC9.2:
- CC9.1 (backups, disaster recovery): Процедури резервного копіювання та аварійного відновлення
- CC9.2 (vendor management): Управління ризиками третіх сторін

Backup and DR:
- Backup frequency: [daily incremental, weekly full]
- Retention: [30 days online, 1 year archive]
- DR testing: [annual/semi-annual]
- RTO/RPO: [targets]

Vendor management:
- Critical vendors: [list key subservice organizations]
- Due diligence: [SOC 2 report review, security assessments]
- Contract requirements: [audit rights, SLAs]
- Monitoring: [annual reviews]

Provide detailed control descriptions with specific activities, frequency, and evidence.

Контролі доступності

Набір контролів доступності

Generate controls specific to SOC 2 Availability criteria (A1.1, A1.2, A1.3):
- A1.1 (availability objectives): Цілі щодо доступності та їх вимірювання
- A1.2 (capacity): Моніторинг, планування та масштабування потужностей
- A1.3 (monitoring and incident response): Управління інцидентами доступності

Our availability commitments:
- SLA: [99.9% uptime or specific commitment]
- Systems: [production services in scope]
- Infrastructure: [cloud provider, redundancy approach]
- Historical performance: [past availability metrics]

For each control, specify monitoring tools, thresholds, escalation, and how we demonstrate compliance.

Контролі цілісності обробки

Набір контролів цілісності обробки

Create controls for SOC 2 Processing Integrity criteria (PI1.1 through PI1.5):
- PI1.1 (processing objectives): Цілі щодо точності та повноти обробки
- PI1.2 (inputs): Валідація та авторизація вхідних даних
- PI1.3 (processing): Контролі логіки обробки та обробка помилок
- PI1.4 (outputs): Валідація та звірка вихідних даних
- PI1.5 (data stores): Контролі цілісності даних

Our processing environment:
- Processing activities: [payment processing, data transformation, calculations]
- Input sources: [APIs, file uploads, manual entry]
- Validation requirements: [regulatory or business rules]
- Reconciliation frequency: [real-time/daily/monthly]

Describe automated and manual controls, validation rules, and exception handling.

Контролі конфіденційності

Набір контролів конфіденційності

Design controls for SOC 2 Confidentiality criteria (C1.1, C1.2):
- C1.1 (confidential information): Ідентифікація та класифікація
- C1.2 (disposal): Безпечне видалення та знищення

Confidential data we handle:
- Data types: [customer proprietary data, trade secrets, financial data]
- Storage locations: [databases, file systems, backups]
- Encryption: [at rest, in transit standards]
- Retention periods: [by data type]

Include data classification scheme, encryption controls, access restrictions, and secure disposal procedures with evidence of execution.

Контролі приватності

Набір контролів приватності

Generate controls for SOC 2 Privacy criteria (P1.0 through P8.0):
- P1.0 (notice): Надання та оновлення повідомлень про приватність
- P2.0 (choice and consent): Збір та управління згодою
- P3.0 (collection): Мінімізація даних та обмеження цілей
- P4.0 (use, retention, disposal): Дотримання графіка зберігання
- P5.0 (access): Обробка запитів на доступ до даних суб'єктів
- P6.0 (disclosure to third parties): Контролі передачі даних третім сторонам
- P7.0 (security): Контролі безпеки, специфічні для приватності
- P8.0 (quality): Точність даних та виправлення

Our privacy landscape:
- Personal data: [categories collected]
- Data subjects: [customers, employees, end users]
- Regulations: [GDPR, CCPA, other]
- Privacy tools: [consent management, DSR platforms]

For each principle, provide specific controls, automation where possible, and evidence of operation.

Контролі приватності часто перетинаються з контролем безпеки та конфіденційності. Задокументуйте ці перетини, щоб уникнути дублювання збору доказів під час аудитів.

Тестування та валідація контролів

Оцінка дизайну контролю

Evaluate the design of my control for [Trust Services Criterion reference]:

Control description:
[Paste your control description]

Assess:
- Чи достатньо цей контроль відповідає вимогам критерію та ключовим аспектам?
- Чи є прогалини або слабкі місця в дизайні?
- Чи є частота контролю відповідною?
- Чи підходить роль власника контролю?
- Які докази повинен генерувати цей контроль?

Provide recommendations for strengthening the control design.

Планування операційної ефективності

I need to demonstrate operating effectiveness for my SOC 2 Type II audit covering [date range]. For control [control ID/description]:
- Control frequency: [daily/monthly/quarterly]
- Control type: [automated/manual/hybrid]
- Evidence generated: [logs, tickets, approvals, reports]

Help me plan:
- Sample size auditors will expect (for manual controls)
- Evidence retention and organization
- Documentation of exceptions and how they were resolved
- Testing approach to validate effectiveness before the audit

Provide a testing plan and evidence checklist.

Для аудитів типу II контролі повинні ефективно працювати протягом усього періоду аудиту (зазвичай 3-12 місяців). Плануйте збір доказів з першого дня, а не лише перед аудитом.

Автоматизація контролів

Можливості автоматизації

Review my control set for [criteria in scope] and identify automation opportunities:

Current controls:
[List your controls and whether they're manual/automated]

Available technologies:
[List tools and platforms you have: SIEM, IaC, policy-as-code, etc.]

Recommend:
- Which controls can be fully automated
- Tools or scripts to implement automation
- Continuous compliance approaches
- How automation improves audit evidence quality

Prioritize by impact and implementation effort.

Автоматизовані контролі забезпечують більш надійні та послідовні аудиторські докази, ніж ручні. Надайте пріоритет автоматизації для високочастотних контролів та тих, що схильні до людських помилок.

On this page