SOC 2 Type II Readiness
0 of 10 questions answered
—
Yes
0
Partial
0
No
0
Do you have a formal information security policy?
Documented security policies reviewed and approved by management.
Are access controls enforced with least-privilege?
Role-based access control (RBAC) with regular access reviews.
Do you perform regular vulnerability assessments?
Scheduled vulnerability scans and penetration testing.
Is data encrypted at rest and in transit?
AES-256 for data at rest, TLS 1.2+ for data in transit.
Do you have an incident response plan?
Documented IR plan with defined roles and communication procedures.
Are system changes managed through a change control process?
Formal change management with approvals and rollback plans.
Do you maintain audit logs for critical systems?
Centralized logging with tamper-evident storage and retention policies.
Is there a business continuity / disaster recovery plan?
Documented BCP/DR with defined RPO/RTO and regular testing.
Are vendor/third-party risks assessed?
Third-party risk management program with periodic assessments.
Do employees undergo security awareness training?
Annual security training with phishing simulations.
This tool provides a general readiness assessment and is not a substitute for a formal compliance audit. Consult with a qualified auditor for certification.