{"id":42123,"date":"2022-02-21T01:45:47","date_gmt":"2022-02-21T06:45:47","guid":{"rendered":"https:\/\/simfoni.com\/?p=42123"},"modified":"2022-06-07T05:18:29","modified_gmt":"2022-06-07T10:18:29","slug":"the-road-to-soc2-through-controls-that-build-trust","status":"publish","type":"post","link":"https:\/\/simfoni.com\/engineering\/the-road-to-soc2-through-controls-that-build-trust\/","title":{"rendered":"The Road to SOC2 through Controls that build trust"},"content":{"rendered":"<div data-elementor-type=\"wp-post\" data-elementor-id=\"42123\" class=\"elementor elementor-42123\" data-elementor-post-type=\"post\">\n\t\t\t\t\t\t<section class=\"has_eae_slider elementor-section elementor-top-section elementor-element elementor-element-a5b6c7c elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-eae-slider=\"64432\" data-id=\"a5b6c7c\" data-element_type=\"section\" data-e-type=\"section\" data-settings='{\"pix_scale_in\":\"none\"}'>\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"has_eae_slider elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-41bdbb1\" data-eae-slider=\"10108\" data-id=\"41bdbb1\" data-element_type=\"column\" data-e-type=\"column\" data-settings='{\"pix_scale_in\":\"none\"}'>\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-f59ed89 elementor-blockquote--skin-border elementor-widget elementor-widget-blockquote\" data-id=\"f59ed89\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"blockquote.default\">\n\t\t\t\t\t\t\t<blockquote class=\"elementor-blockquote\">\n\t\t\t<p class=\"elementor-blockquote__content\">\n\t\t\t\tSOC2 tests compliance on a few trust principles namely Security, Availability, Processing Integrity, Confidentiality and Privacy of data. \t\t\t<\/p>\n\t\t\t\t\t<\/blockquote>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"has_eae_slider elementor-section elementor-top-section elementor-element elementor-element-4b4293d elementor-reverse-mobile elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-eae-slider=\"71392\" data-id=\"4b4293d\" data-element_type=\"section\" data-e-type=\"section\" data-settings='{\"pix_scale_in\":\"none\"}'>\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"has_eae_slider elementor-column elementor-col-50 elementor-top-column elementor-element elementor-element-0f1b1fe\" data-eae-slider=\"49861\" data-id=\"0f1b1fe\" data-element_type=\"column\" data-e-type=\"column\" data-settings='{\"pix_scale_in\":\"none\"}'>\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-f45d932 elementor-widget elementor-widget-text-editor\" data-id=\"f45d932\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>Some basics about SOC2 (Service Organizational Control ver 2) is that it is a compliance standard set by AICPA(It is the body of Certified Public Accountants). It tests compliance on a few trust principles namely Security, Availability, Processing Integrity, Confidentiality and Privacy of data. As organizations we often try to get SOC 2 certified and show the world we are compliant and secure. I am trying to take a different approach to this. If we break down the trust principles into Controls and create a roadmap to implement those controls, then we become ready not just for SOC2 but also other parallel certifications.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t<div class=\"has_eae_slider elementor-column elementor-col-50 elementor-top-column elementor-element elementor-element-a371a28\" data-eae-slider=\"39401\" data-id=\"a371a28\" data-element_type=\"column\" data-e-type=\"column\" data-settings='{\"pix_scale_in\":\"none\"}'>\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-b3effe6 elementor-widget elementor-widget-image\" data-id=\"b3effe6\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img fetchpriority=\"high\" decoding=\"async\" width=\"1920\" height=\"1080\" src=\"https:\/\/simfoni.com\/wp-content\/uploads\/2022\/02\/SOC2-Security-scaled.jpg\" class=\"attachment-full size-full wp-image-42128\" alt=\"SOC2 Security\" srcset=\"https:\/\/simfoni.com\/wp-content\/uploads\/2022\/02\/SOC2-Security-scaled.jpg 1920w, https:\/\/simfoni.com\/wp-content\/uploads\/2022\/02\/SOC2-Security-300x169.jpg 300w, https:\/\/simfoni.com\/wp-content\/uploads\/2022\/02\/SOC2-Security-1024x576.jpg 1024w, https:\/\/simfoni.com\/wp-content\/uploads\/2022\/02\/SOC2-Security-768x432.jpg 768w, https:\/\/simfoni.com\/wp-content\/uploads\/2022\/02\/SOC2-Security-1536x864.jpg 1536w, https:\/\/simfoni.com\/wp-content\/uploads\/2022\/02\/SOC2-Security-2048x1152.jpg 2048w, https:\/\/simfoni.com\/wp-content\/uploads\/2022\/02\/SOC2-Security-150x84.jpg 150w\" sizes=\"(max-width: 1920px) 100vw, 1920px\"\/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"has_eae_slider elementor-section elementor-top-section elementor-element elementor-element-82d8bc3 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-eae-slider=\"64422\" data-id=\"82d8bc3\" data-element_type=\"section\" data-e-type=\"section\" data-settings='{\"pix_scale_in\":\"none\"}'>\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"has_eae_slider elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-9fefa8d\" data-eae-slider=\"13497\" data-id=\"9fefa8d\" data-element_type=\"column\" data-e-type=\"column\" data-settings='{\"pix_scale_in\":\"none\"}'>\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-81d0686 elementor-widget elementor-widget-text-editor\" data-id=\"81d0686\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>&nbsp;FedRamp, ISO 270001 are some of those. We will not discuss them here but SOC2 will overlap with other certifications for sure. Its important that we focus on getting the controls in place first rather than scramble for a certificate and make the actual certificate a last step. It makes us secure internally first and lets us run our business with confidence.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-39b40cf elementor-widget elementor-widget-text-editor\" data-id=\"39b40cf\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><strong>Read More:-&nbsp; <a href=\"https:\/\/simfoni.com\/procurement\/\" target=\"_blank\" rel=\"noopener\">What is Procurement<\/a> and How To Optimize Processes, Performance, and Technology?<\/strong><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-8c6df30 elementor-widget elementor-widget-image\" data-id=\"8c6df30\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" width=\"1920\" height=\"1338\" src=\"https:\/\/simfoni.com\/wp-content\/uploads\/2022\/02\/Compliance-Infrastructure-scaled.jpg\" class=\"elementor-animation-hang attachment-full size-full wp-image-42130\" alt=\"Compliance Infrastructure\" srcset=\"https:\/\/simfoni.com\/wp-content\/uploads\/2022\/02\/Compliance-Infrastructure-scaled.jpg 1920w, https:\/\/simfoni.com\/wp-content\/uploads\/2022\/02\/Compliance-Infrastructure-300x209.jpg 300w, https:\/\/simfoni.com\/wp-content\/uploads\/2022\/02\/Compliance-Infrastructure-1024x714.jpg 1024w, https:\/\/simfoni.com\/wp-content\/uploads\/2022\/02\/Compliance-Infrastructure-768x535.jpg 768w, https:\/\/simfoni.com\/wp-content\/uploads\/2022\/02\/Compliance-Infrastructure-1536x1070.jpg 1536w, https:\/\/simfoni.com\/wp-content\/uploads\/2022\/02\/Compliance-Infrastructure-2048x1427.jpg 2048w, https:\/\/simfoni.com\/wp-content\/uploads\/2022\/02\/Compliance-Infrastructure-150x105.jpg 150w\" sizes=\"(max-width: 1920px) 100vw, 1920px\"\/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-5b50803 elementor-widget elementor-widget-text-editor\" data-id=\"5b50803\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>Now a word about controls. What is control? Well, a control is a system, process, or policy meant to mitigate a &ldquo;mal&rdquo; event. In real life video cameras are on the periphery of yours. Home is a system, background checks before you let someone in to meet a leader would be a process, and ensuring all check-ins are accompanied by an original ID card is a policy. All of the above are controls. The next thing to know is that SOC2 has 2 parts and for good reasons. The first part is to have the controls in place (policy written, systems installed, process documented). This is essential because now you have an inventory of controls that map to the 5 trust principles. You decide what those controls are and put them in place and get them approved by the certifier. You need to note here that you do not need to have any of this operational for a <a href=\"https:\/\/simfoni.com\/trust\/#soc2\" target=\"_blank\" rel=\"noopener\"><strong>SOC2 Type 1 certification<\/strong><\/a>. You are capable of it, you have the inventory BUT you are not yet running it. The next step is to switch on all your controls. To run them, to monitor them, to keep trails. Then after a while (I am not going into the specifics of the certification here) you call someone to audit what you promised in Part 1 and verify they are implemented. This is Part 2 and the actual completion of SOC2.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-f645673 elementor-widget elementor-widget-text-editor\" data-id=\"f645673\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>We will now as an exercise create a set of controls mapped to each one of the trust principles that form the core of SOC2. This should illustrate how your roadmap should look like. The controls are by no means comprehensive but rather illustrative.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-245a24e elementor-widget elementor-widget-toggle\" data-id=\"245a24e\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"toggle.default\">\n\t\t\t\t\t\t\t<div class=\"elementor-toggle\">\n\t\t\t\t\t\t\t<div class=\"elementor-toggle-item\">\n\t\t\t\t\t<div id=\"elementor-tab-title-3811\" class=\"elementor-tab-title\" data-tab=\"1\" role=\"button\" aria-controls=\"elementor-tab-content-3811\" aria-expanded=\"false\">\n\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-toggle-icon elementor-toggle-icon-left\" aria-hidden=\"true\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-toggle-icon-closed\"><svg class=\"e-font-icon-svg e-fas-caret-right\" viewbox=\"0 0 192 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M0 384.662V127.338c0-17.818 21.543-26.741 34.142-14.142l128.662 128.662c7.81 7.81 7.81 20.474 0 28.284L34.142 398.804C21.543 411.404 0 402.48 0 384.662z\"><\/path><\/svg><\/span>\n\t\t\t\t\t\t\t\t<span class=\"elementor-toggle-icon-opened\"><svg class=\"elementor-toggle-icon-opened e-font-icon-svg e-fas-caret-up\" viewbox=\"0 0 320 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M288.662 352H31.338c-17.818 0-26.741-21.543-14.142-34.142l128.662-128.662c7.81-7.81 20.474-7.81 28.284 0l128.662 128.662c12.6 12.599 3.676 34.142-14.142 34.142z\"><\/path><\/svg><\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"elementor-toggle-title\" tabindex=\"0\">Security <\/a>\n\t\t\t\t\t<\/div>\n\n\t\t\t\t\t<div id=\"elementor-tab-content-3811\" class=\"elementor-tab-content elementor-clearfix\" data-tab=\"1\" role=\"region\" aria-labelledby=\"elementor-tab-title-3811\"><ul><li>Password requirement<\/li><li>Password policies<\/li><li>Security Training at appropriate levels for personnel<\/li><li>Access into physical offices (everything from entry systems to badges that need to be physically verified)<\/li><li>Multi factor authentication<\/li><\/ul><\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t<div class=\"elementor-toggle-item\">\n\t\t\t\t\t<div id=\"elementor-tab-title-3812\" class=\"elementor-tab-title\" data-tab=\"2\" role=\"button\" aria-controls=\"elementor-tab-content-3812\" aria-expanded=\"false\">\n\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-toggle-icon elementor-toggle-icon-left\" aria-hidden=\"true\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-toggle-icon-closed\"><svg class=\"e-font-icon-svg e-fas-caret-right\" viewbox=\"0 0 192 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M0 384.662V127.338c0-17.818 21.543-26.741 34.142-14.142l128.662 128.662c7.81 7.81 7.81 20.474 0 28.284L34.142 398.804C21.543 411.404 0 402.48 0 384.662z\"><\/path><\/svg><\/span>\n\t\t\t\t\t\t\t\t<span class=\"elementor-toggle-icon-opened\"><svg class=\"elementor-toggle-icon-opened e-font-icon-svg e-fas-caret-up\" viewbox=\"0 0 320 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M288.662 352H31.338c-17.818 0-26.741-21.543-14.142-34.142l128.662-128.662c7.81-7.81 20.474-7.81 28.284 0l128.662 128.662c12.6 12.599 3.676 34.142-14.142 34.142z\"><\/path><\/svg><\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"elementor-toggle-title\" tabindex=\"0\">Availability<\/a>\n\t\t\t\t\t<\/div>\n\n\t\t\t\t\t<div id=\"elementor-tab-content-3812\" class=\"elementor-tab-content elementor-clearfix\" data-tab=\"2\" role=\"region\" aria-labelledby=\"elementor-tab-title-3812\"><ul><li><span class=\"\" data-mobile-support=\"0\" data-gt-translate-attributes='[{\"attribute\":\"data-cmtooltip\", \"format\":\"html\"}]' tabindex=\"0\" role=\"link\">Disaster recovery<\/span><\/li><li>Backup and recovery<\/li><li>Load balancers<\/li><li>DDOS prevention<\/li><\/ul><\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t<div class=\"elementor-toggle-item\">\n\t\t\t\t\t<div id=\"elementor-tab-title-3813\" class=\"elementor-tab-title\" data-tab=\"3\" role=\"button\" aria-controls=\"elementor-tab-content-3813\" aria-expanded=\"false\">\n\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-toggle-icon elementor-toggle-icon-left\" aria-hidden=\"true\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-toggle-icon-closed\"><svg class=\"e-font-icon-svg e-fas-caret-right\" viewbox=\"0 0 192 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M0 384.662V127.338c0-17.818 21.543-26.741 34.142-14.142l128.662 128.662c7.81 7.81 7.81 20.474 0 28.284L34.142 398.804C21.543 411.404 0 402.48 0 384.662z\"><\/path><\/svg><\/span>\n\t\t\t\t\t\t\t\t<span class=\"elementor-toggle-icon-opened\"><svg class=\"elementor-toggle-icon-opened e-font-icon-svg e-fas-caret-up\" viewbox=\"0 0 320 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M288.662 352H31.338c-17.818 0-26.741-21.543-14.142-34.142l128.662-128.662c7.81-7.81 20.474-7.81 28.284 0l128.662 128.662c12.6 12.599 3.676 34.142-14.142 34.142z\"><\/path><\/svg><\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"elementor-toggle-title\" tabindex=\"0\">Processing Integrity<\/a>\n\t\t\t\t\t<\/div>\n\n\t\t\t\t\t<div id=\"elementor-tab-content-3813\" class=\"elementor-tab-content elementor-clearfix\" data-tab=\"3\" role=\"region\" aria-labelledby=\"elementor-tab-title-3813\"><ul><li>Role based Access<\/li><li>Delivery of processed data only to authorized parties<\/li><li><span class=\"\" data-mobile-support=\"0\" data-gt-translate-attributes='[{\"attribute\":\"data-cmtooltip\", \"format\":\"html\"}]' tabindex=\"0\" role=\"link\">Audit trail<\/span> of all output deliveries<\/li><li>Secure storage of processed data<\/li><\/ul><\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t<div class=\"elementor-toggle-item\">\n\t\t\t\t\t<div id=\"elementor-tab-title-3814\" class=\"elementor-tab-title\" data-tab=\"4\" role=\"button\" aria-controls=\"elementor-tab-content-3814\" aria-expanded=\"false\">\n\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-toggle-icon elementor-toggle-icon-left\" aria-hidden=\"true\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-toggle-icon-closed\"><svg class=\"e-font-icon-svg e-fas-caret-right\" viewbox=\"0 0 192 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M0 384.662V127.338c0-17.818 21.543-26.741 34.142-14.142l128.662 128.662c7.81 7.81 7.81 20.474 0 28.284L34.142 398.804C21.543 411.404 0 402.48 0 384.662z\"><\/path><\/svg><\/span>\n\t\t\t\t\t\t\t\t<span class=\"elementor-toggle-icon-opened\"><svg class=\"elementor-toggle-icon-opened e-font-icon-svg e-fas-caret-up\" viewbox=\"0 0 320 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M288.662 352H31.338c-17.818 0-26.741-21.543-14.142-34.142l128.662-128.662c7.81-7.81 20.474-7.81 28.284 0l128.662 128.662c12.6 12.599 3.676 34.142-14.142 34.142z\"><\/path><\/svg><\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"elementor-toggle-title\" tabindex=\"0\">Confidentiality<\/a>\n\t\t\t\t\t<\/div>\n\n\t\t\t\t\t<div id=\"elementor-tab-content-3814\" class=\"elementor-tab-content elementor-clearfix\" data-tab=\"4\" role=\"region\" aria-labelledby=\"elementor-tab-title-3814\"><ul><li>Non Disclosure agreements<\/li><li>Test data that does not compromise customer confidentiality<\/li><li>Transaction logs protection<\/li><li>Authorized access to sensitive information<\/li><\/ul><\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t<div class=\"elementor-toggle-item\">\n\t\t\t\t\t<div id=\"elementor-tab-title-3815\" class=\"elementor-tab-title\" data-tab=\"5\" role=\"button\" aria-controls=\"elementor-tab-content-3815\" aria-expanded=\"false\">\n\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-toggle-icon elementor-toggle-icon-left\" aria-hidden=\"true\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-toggle-icon-closed\"><svg class=\"e-font-icon-svg e-fas-caret-right\" viewbox=\"0 0 192 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M0 384.662V127.338c0-17.818 21.543-26.741 34.142-14.142l128.662 128.662c7.81 7.81 7.81 20.474 0 28.284L34.142 398.804C21.543 411.404 0 402.48 0 384.662z\"><\/path><\/svg><\/span>\n\t\t\t\t\t\t\t\t<span class=\"elementor-toggle-icon-opened\"><svg class=\"elementor-toggle-icon-opened e-font-icon-svg e-fas-caret-up\" viewbox=\"0 0 320 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M288.662 352H31.338c-17.818 0-26.741-21.543-14.142-34.142l128.662-128.662c7.81-7.81 20.474-7.81 28.284 0l128.662 128.662c12.6 12.599 3.676 34.142-14.142 34.142z\"><\/path><\/svg><\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"elementor-toggle-title\" tabindex=\"0\">Privacy<\/a>\n\t\t\t\t\t<\/div>\n\n\t\t\t\t\t<div id=\"elementor-tab-content-3815\" class=\"elementor-tab-content elementor-clearfix\" data-tab=\"5\" role=\"region\" aria-labelledby=\"elementor-tab-title-3815\"><ul><li>Protect PII<\/li><li>Credit card and banking information<\/li><\/ul><\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"has_eae_slider elementor-section elementor-top-section elementor-element elementor-element-12b6e7f elementor-reverse-mobile elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-eae-slider=\"78873\" data-id=\"12b6e7f\" data-element_type=\"section\" data-e-type=\"section\" data-settings='{\"pix_scale_in\":\"none\"}'>\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"has_eae_slider elementor-column elementor-col-50 elementor-top-column elementor-element elementor-element-fbfa589\" data-eae-slider=\"52827\" data-id=\"fbfa589\" data-element_type=\"column\" data-e-type=\"column\" data-settings='{\"pix_scale_in\":\"none\"}'>\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-d386808 elementor-widget elementor-widget-text-editor\" data-id=\"d386808\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>All of the above are examples of Controls that will form part of your SOC2. Create a list of your controls that are relevant to you and make sense for you to implement. Separate them into buckets, acquire the controls, and set them up and when you are ready turn them on in small chunks. In the end, you will have a well-lighted room that can be trusted by your customers and partners. Remember as you evolve you grow your controls, remove obsolete ones and create a better and better security and compliance infrastructure. Basically, you build your trust.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t<div class=\"has_eae_slider elementor-column elementor-col-50 elementor-top-column elementor-element elementor-element-5163ebf\" data-eae-slider=\"97875\" data-id=\"5163ebf\" data-element_type=\"column\" data-e-type=\"column\" data-settings='{\"pix_scale_in\":\"none\"}'>\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-655306d elementor-widget elementor-widget-image\" data-id=\"655306d\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" width=\"1920\" height=\"1196\" src=\"https:\/\/simfoni.com\/wp-content\/uploads\/2022\/02\/SOC2-Importance-scaled.jpg\" class=\"attachment-full size-full wp-image-42129\" alt=\"SOC2 Importance\" srcset=\"https:\/\/simfoni.com\/wp-content\/uploads\/2022\/02\/SOC2-Importance-scaled.jpg 1920w, https:\/\/simfoni.com\/wp-content\/uploads\/2022\/02\/SOC2-Importance-300x187.jpg 300w, https:\/\/simfoni.com\/wp-content\/uploads\/2022\/02\/SOC2-Importance-1024x638.jpg 1024w, https:\/\/simfoni.com\/wp-content\/uploads\/2022\/02\/SOC2-Importance-768x479.jpg 768w, https:\/\/simfoni.com\/wp-content\/uploads\/2022\/02\/SOC2-Importance-1536x957.jpg 1536w, https:\/\/simfoni.com\/wp-content\/uploads\/2022\/02\/SOC2-Importance-2048x1276.jpg 2048w, https:\/\/simfoni.com\/wp-content\/uploads\/2022\/02\/SOC2-Importance-150x93.jpg 150w\" sizes=\"(max-width: 1920px) 100vw, 1920px\"\/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"has_eae_slider elementor-section elementor-top-section elementor-element elementor-element-f824144 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-eae-slider=\"68356\" data-id=\"f824144\" data-element_type=\"section\" data-e-type=\"section\" data-settings='{\"background_background\":\"classic\",\"pix_scale_in\":\"none\"}'>\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"has_eae_slider elementor-column elementor-col-50 elementor-top-column elementor-element elementor-element-fac2a9c\" data-eae-slider=\"89151\" data-id=\"fac2a9c\" data-element_type=\"column\" data-e-type=\"column\" data-settings='{\"pix_scale_in\":\"none\"}'>\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-7aac2ef elementor-author-box--align-left elementor-widget elementor-widget-author-box\" data-id=\"7aac2ef\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"author-box.default\">\n\t\t\t\t\t\t\t<div class=\"elementor-author-box\">\n\t\t\t\t\t\t\t<a href=\"https:\/\/www.linkedin.com\/in\/mohan-gopalakrishnan-323325\/\" class=\"elementor-author-box__avatar\">\n\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/simfoni.com\/wp-content\/uploads\/2022\/02\/Mohan-Gopalakrishnan.jpg\" alt=\"Picture of Mohan Gopalakrishnan\" loading=\"lazy\"\/>\n\t\t\t\t<\/a>\n\t\t\t\n\t\t\t<div class=\"elementor-author-box__text\">\n\t\t\t\t\t\t\t\t\t<a href=\"https:\/\/www.linkedin.com\/in\/mohan-gopalakrishnan-323325\/\">\n\t\t\t\t\t\t<h4 class=\"elementor-author-box__name\">\n\t\t\t\t\t\t\tMohan Gopalakrishnan\t\t\t\t\t\t<\/h4>\n\t\t\t\t\t<\/a>\n\t\t\t\t\n\t\t\t\t\t\t\t\t\t<div class=\"elementor-author-box__bio\">\n\t\t\t\t\t\t<p>VP of Engineering at Simfoni<\/p>\n\t\t\t\t\t<\/div>\n\t\t\t\t\n\t\t\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t<div class=\"has_eae_slider elementor-column elementor-col-50 elementor-top-column elementor-element elementor-element-9c2fc32\" data-eae-slider=\"90306\" data-id=\"9c2fc32\" data-element_type=\"column\" data-e-type=\"column\" data-settings='{\"pix_scale_in\":\"none\"}'>\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-a2b4564 elementor-widget elementor-widget-author-box\" data-id=\"a2b4564\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"author-box.default\">\n\t\t\t\t\t\t\t<div class=\"elementor-author-box\">\n\t\t\t\t\t\t\t<a href=\"https:\/\/www.linkedin.com\/company\/simfoni\/\" class=\"elementor-author-box__avatar\">\n\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/simfoni.com\/wp-content\/uploads\/2020\/03\/Simfoni-Favicon-300x300.gif\" alt=\"Picture of Simfoni\" loading=\"lazy\"\/>\n\t\t\t\t<\/a>\n\t\t\t\n\t\t\t<div class=\"elementor-author-box__text\">\n\t\t\t\t\t\t\t\t\t<a href=\"https:\/\/www.linkedin.com\/company\/simfoni\/\">\n\t\t\t\t\t\t<h4 class=\"elementor-author-box__name\">\n\t\t\t\t\t\t\tSimfoni\t\t\t\t\t\t<\/h4>\n\t\t\t\t\t<\/a>\n\t\t\t\t\n\t\t\t\t\t\t\t\t\t<div class=\"elementor-author-box__bio\">\n\t\t\t\t\t\t<p>Follow Simfoni on LinkedIn<\/p>\n\t\t\t\t\t<\/div>\n\t\t\t\t\n\t\t\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>SOC2 tests compliance on a few trust principles namely Security, Availability, Processing Integrity, Confidentiality and Privacy of data. Some basics about SOC2 (Service Organizational Control ver 2) is that it is a compliance standard set by AICPA(It is the body&hellip;<\/p>\n","protected":false},"author":1,"featured_media":42125,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"give_campaign_id":0,"footnotes":""},"categories":[2768],"tags":[],"class_list":["post-42123","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-engineering"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.2 (Yoast SEO v27.2) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>The Road to SOC2 through Controls that build trust - Simfoni.com<\/title>\n<meta name=\"description\" content=\"SOC2 tests compliance on a few trust principles namely Security, Availability, Processing Integrity, Confidentiality, and Privacy of data\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/simfoni.com\/engineering\/the-road-to-soc2-through-controls-that-build-trust\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"The Road to SOC2 through Controls that build trust - Simfoni Engineering Blog\" \/>\n<meta property=\"og:description\" content=\"Some basics about SOC2 (Service Organizational Control ver 2) is that it is a compliance standard set by AICPA(It is the body of Certified Public Accountants). It tests compliance on a few trust principles namely Security, Availability, Processing Integrity, Confidentiality, and Privacy of data\" \/>\n<meta property=\"og:url\" content=\"https:\/\/simfoni.com\/engineering\/the-road-to-soc2-through-controls-that-build-trust\/\" \/>\n<meta property=\"og:site_name\" content=\"Simfoni\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/SimfoniApps\/\" \/>\n<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/SimfoniApps\/\" \/>\n<meta property=\"article:published_time\" content=\"2022-02-21T06:45:47+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2022-06-07T10:18:29+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/simfoni.com\/wp-content\/uploads\/2022\/02\/SOC2.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"628\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Simfoni\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/simfoni.com\/engineering\/the-road-to-soc2-through-controls-that-build-trust\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/simfoni.com\/engineering\/the-road-to-soc2-through-controls-that-build-trust\/\"},\"author\":{\"name\":\"Simfoni\",\"@id\":\"https:\/\/simfoni.com\/#\/schema\/person\/afc4d1749ccc888582602619fc5b02b8\"},\"headline\":\"The Road to SOC2 through Controls that build trust\",\"datePublished\":\"2022-02-21T06:45:47+00:00\",\"dateModified\":\"2022-06-07T10:18:29+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/simfoni.com\/engineering\/the-road-to-soc2-through-controls-that-build-trust\/\"},\"wordCount\":673,\"publisher\":{\"@id\":\"https:\/\/simfoni.com\/#organization\"},\"image\":{\"@id\":\"https:\/\/simfoni.com\/engineering\/the-road-to-soc2-through-controls-that-build-trust\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/simfoni.com\/wp-content\/uploads\/2022\/02\/SOC2.jpg\",\"articleSection\":[\"Engineering\"],\"inLanguage\":\"en\",\"copyrightYear\":\"2022\",\"copyrightHolder\":{\"@id\":\"https:\/\/simfoni.com\/#organization\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/simfoni.com\/engineering\/the-road-to-soc2-through-controls-that-build-trust\/\",\"url\":\"https:\/\/simfoni.com\/engineering\/the-road-to-soc2-through-controls-that-build-trust\/\",\"name\":\"The Road to SOC2 through Controls that build trust - Simfoni.com\",\"isPartOf\":{\"@id\":\"https:\/\/simfoni.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/simfoni.com\/engineering\/the-road-to-soc2-through-controls-that-build-trust\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/simfoni.com\/engineering\/the-road-to-soc2-through-controls-that-build-trust\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/simfoni.com\/wp-content\/uploads\/2022\/02\/SOC2.jpg\",\"datePublished\":\"2022-02-21T06:45:47+00:00\",\"dateModified\":\"2022-06-07T10:18:29+00:00\",\"description\":\"SOC2 tests compliance on a few trust principles namely Security, Availability, Processing Integrity, Confidentiality, and Privacy of data\",\"breadcrumb\":{\"@id\":\"https:\/\/simfoni.com\/engineering\/the-road-to-soc2-through-controls-that-build-trust\/#breadcrumb\"},\"inLanguage\":\"en\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/simfoni.com\/engineering\/the-road-to-soc2-through-controls-that-build-trust\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en\",\"@id\":\"https:\/\/simfoni.com\/engineering\/the-road-to-soc2-through-controls-that-build-trust\/#primaryimage\",\"url\":\"https:\/\/simfoni.com\/wp-content\/uploads\/2022\/02\/SOC2.jpg\",\"contentUrl\":\"https:\/\/simfoni.com\/wp-content\/uploads\/2022\/02\/SOC2.jpg\",\"width\":1200,\"height\":628,\"caption\":\"The Road to SOC2 through Controls that build trust\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/simfoni.com\/engineering\/the-road-to-soc2-through-controls-that-build-trust\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/simfoni.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"The Road to SOC2 through Controls that build trust\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/simfoni.com\/#website\",\"url\":\"https:\/\/simfoni.com\/\",\"name\":\"Simfoni\",\"description\":\"Spend Intelligence and Spend Automation\",\"publisher\":{\"@id\":\"https:\/\/simfoni.com\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/simfoni.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en\"},{\"@type\":[\"Organization\",\"Place\"],\"@id\":\"https:\/\/simfoni.com\/#organization\",\"name\":\"Simfoni\",\"alternateName\":\"Simfoni\",\"url\":\"https:\/\/simfoni.com\/\",\"logo\":{\"@id\":\"https:\/\/simfoni.com\/engineering\/the-road-to-soc2-through-controls-that-build-trust\/#local-main-organization-logo\"},\"image\":{\"@id\":\"https:\/\/simfoni.com\/engineering\/the-road-to-soc2-through-controls-that-build-trust\/#local-main-organization-logo\"},\"sameAs\":[\"https:\/\/www.facebook.com\/SimfoniApps\/\",\"https:\/\/x.com\/simfoniapps\",\"https:\/\/www.instagram.com\/simfoniapps\/\",\"https:\/\/www.linkedin.com\/company\/simfoni\/\",\"https:\/\/www.youtube.com\/@simfoni\",\"https:\/\/g.page\/r\/CTMP26g2qypHEBM\/\",\"https:\/\/www.capterra.com\/p\/206211\/Spend-Analytics\/\",\"https:\/\/www.g2.com\/products\/simfoni-spend-analytics\/\",\"https:\/\/www.glassdoor.com\/Overview\/Working-at-Simfoni-EI_IE3290778.11,18.htm\",\"https:\/\/sourceforge.net\/software\/product\/Simfoni\/\",\"https:\/\/news.google.com\/publications\/CAAqBwgKMMaWxAsw6bHbAw\"],\"description\":\"Simfoni is an AI-powered procurement and spend management platform designed to help enterprises gain complete visibility into organizational spend and turn procurement insight into measurable financial impact. The platform combines advanced spend analytics, intelligent sourcing automation, and tail spend management to enable procurement teams to identify savings opportunities, execute sourcing strategies efficiently, and improve supplier performance across global operations. Built for modern procurement organizations, Simfoni supports Chief Procurement Officers, strategic sourcing leaders, and finance teams who are responsible for driving cost optimization, supplier governance, and operational efficiency. By consolidating procurement data across multiple systems and suppliers, Simfoni provides a unified view of enterprise spend and enables organizations to prioritize sourcing initiatives that deliver measurable savings. Simfoni\u2019s platform integrates spend intelligence with automated sourcing execution, allowing procurement teams to scale sourcing activities without increasing headcount. The system helps organizations manage indirect spend, improve supplier engagement, and strengthen procurement governance through data-driven decision making. Trusted by global enterprises, Simfoni enables organizations to transform procurement from a reactive cost center into a strategic value driver by delivering visibility, automation, and measurable financial outcomes across the procurement lifecycle.\",\"legalName\":\"Simfoni\",\"foundingDate\":\"2015-08-25\",\"numberOfEmployees\":{\"@type\":\"QuantitativeValue\",\"minValue\":\"201\",\"maxValue\":\"500\"},\"address\":{\"@id\":\"https:\/\/simfoni.com\/engineering\/the-road-to-soc2-through-controls-that-build-trust\/#local-main-place-address\"},\"telephone\":[\"+1-973-718-7071\",\"+44-208-098-2115\"],\"openingHoursSpecification\":[{\"@type\":\"OpeningHoursSpecification\",\"dayOfWeek\":[\"Monday\",\"Tuesday\",\"Wednesday\",\"Thursday\",\"Friday\",\"Saturday\",\"Sunday\"],\"opens\":\"00:00\",\"closes\":\"23:59\"}],\"email\":\"info@simfoni.com\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/simfoni.com\/#\/schema\/person\/afc4d1749ccc888582602619fc5b02b8\",\"name\":\"Simfoni\",\"description\":\"Simfoni Delivers Next-generation Digital Procurement Transformation Through Spend Intelligence, Spend Automation &amp; Spend Analytics Software.\",\"sameAs\":[\"https:\/\/simfoni.com\/\",\"https:\/\/www.facebook.com\/SimfoniApps\/\",\"https:\/\/www.instagram.com\/simfoniapps\/\",\"https:\/\/www.linkedin.com\/company\/simfoni\/\",\"https:\/\/x.com\/simfoniapps\",\"https:\/\/www.youtube.com\/@simfoni\"]},{\"@type\":\"PostalAddress\",\"@id\":\"https:\/\/simfoni.com\/engineering\/the-road-to-soc2-through-controls-that-build-trust\/#local-main-place-address\",\"streetAddress\":\"90 Washington Valley Road\",\"addressLocality\":\"Bedminster\",\"postalCode\":\"07921\",\"addressRegion\":\"New Jersey\",\"addressCountry\":\"US\"},{\"@type\":\"ImageObject\",\"inLanguage\":\"en\",\"@id\":\"https:\/\/simfoni.com\/engineering\/the-road-to-soc2-through-controls-that-build-trust\/#local-main-organization-logo\",\"url\":\"https:\/\/simfoni.com\/wp-content\/uploads\/2021\/10\/Simfoni.com-Logo.jpg\",\"contentUrl\":\"https:\/\/simfoni.com\/wp-content\/uploads\/2021\/10\/Simfoni.com-Logo.jpg\",\"width\":1000,\"height\":1000,\"caption\":\"Simfoni\"}]}<\/script>\n<meta name=\"geo.placename\" content=\"Bedminster\" \/>\n<meta name=\"geo.region\" content=\"United States (US)\" \/>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"The Road to SOC2 through Controls that build trust - Simfoni.com","description":"SOC2 tests compliance on a few trust principles namely Security, Availability, Processing Integrity, Confidentiality, and Privacy of data","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/simfoni.com\/engineering\/the-road-to-soc2-through-controls-that-build-trust\/","og_locale":"en_US","og_type":"article","og_title":"The Road to SOC2 through Controls that build trust - Simfoni Engineering Blog","og_description":"Some basics about SOC2 (Service Organizational Control ver 2) is that it is a compliance standard set by AICPA(It is the body of Certified Public Accountants). It tests compliance on a few trust principles namely Security, Availability, Processing Integrity, Confidentiality, and Privacy of data","og_url":"https:\/\/simfoni.com\/engineering\/the-road-to-soc2-through-controls-that-build-trust\/","og_site_name":"Simfoni","article_publisher":"https:\/\/www.facebook.com\/SimfoniApps\/","article_author":"https:\/\/www.facebook.com\/SimfoniApps\/","article_published_time":"2022-02-21T06:45:47+00:00","article_modified_time":"2022-06-07T10:18:29+00:00","og_image":[{"width":1200,"height":628,"url":"https:\/\/simfoni.com\/wp-content\/uploads\/2022\/02\/SOC2.jpg","type":"image\/jpeg"}],"author":"Simfoni","schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/simfoni.com\/engineering\/the-road-to-soc2-through-controls-that-build-trust\/#article","isPartOf":{"@id":"https:\/\/simfoni.com\/engineering\/the-road-to-soc2-through-controls-that-build-trust\/"},"author":{"name":"Simfoni","@id":"https:\/\/simfoni.com\/#\/schema\/person\/afc4d1749ccc888582602619fc5b02b8"},"headline":"The Road to SOC2 through Controls that build trust","datePublished":"2022-02-21T06:45:47+00:00","dateModified":"2022-06-07T10:18:29+00:00","mainEntityOfPage":{"@id":"https:\/\/simfoni.com\/engineering\/the-road-to-soc2-through-controls-that-build-trust\/"},"wordCount":673,"publisher":{"@id":"https:\/\/simfoni.com\/#organization"},"image":{"@id":"https:\/\/simfoni.com\/engineering\/the-road-to-soc2-through-controls-that-build-trust\/#primaryimage"},"thumbnailUrl":"https:\/\/simfoni.com\/wp-content\/uploads\/2022\/02\/SOC2.jpg","articleSection":["Engineering"],"inLanguage":"en","copyrightYear":"2022","copyrightHolder":{"@id":"https:\/\/simfoni.com\/#organization"}},{"@type":"WebPage","@id":"https:\/\/simfoni.com\/engineering\/the-road-to-soc2-through-controls-that-build-trust\/","url":"https:\/\/simfoni.com\/engineering\/the-road-to-soc2-through-controls-that-build-trust\/","name":"The Road to SOC2 through Controls that build trust - Simfoni.com","isPartOf":{"@id":"https:\/\/simfoni.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/simfoni.com\/engineering\/the-road-to-soc2-through-controls-that-build-trust\/#primaryimage"},"image":{"@id":"https:\/\/simfoni.com\/engineering\/the-road-to-soc2-through-controls-that-build-trust\/#primaryimage"},"thumbnailUrl":"https:\/\/simfoni.com\/wp-content\/uploads\/2022\/02\/SOC2.jpg","datePublished":"2022-02-21T06:45:47+00:00","dateModified":"2022-06-07T10:18:29+00:00","description":"SOC2 tests compliance on a few trust principles namely Security, Availability, Processing Integrity, Confidentiality, and Privacy of data","breadcrumb":{"@id":"https:\/\/simfoni.com\/engineering\/the-road-to-soc2-through-controls-that-build-trust\/#breadcrumb"},"inLanguage":"en","potentialAction":[{"@type":"ReadAction","target":["https:\/\/simfoni.com\/engineering\/the-road-to-soc2-through-controls-that-build-trust\/"]}]},{"@type":"ImageObject","inLanguage":"en","@id":"https:\/\/simfoni.com\/engineering\/the-road-to-soc2-through-controls-that-build-trust\/#primaryimage","url":"https:\/\/simfoni.com\/wp-content\/uploads\/2022\/02\/SOC2.jpg","contentUrl":"https:\/\/simfoni.com\/wp-content\/uploads\/2022\/02\/SOC2.jpg","width":1200,"height":628,"caption":"The Road to SOC2 through Controls that build trust"},{"@type":"BreadcrumbList","@id":"https:\/\/simfoni.com\/engineering\/the-road-to-soc2-through-controls-that-build-trust\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/simfoni.com\/"},{"@type":"ListItem","position":2,"name":"The Road to SOC2 through Controls that build trust"}]},{"@type":"WebSite","@id":"https:\/\/simfoni.com\/#website","url":"https:\/\/simfoni.com\/","name":"Simfoni","description":"Spend Intelligence and Spend Automation","publisher":{"@id":"https:\/\/simfoni.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/simfoni.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en"},{"@type":["Organization","Place"],"@id":"https:\/\/simfoni.com\/#organization","name":"Simfoni","alternateName":"Simfoni","url":"https:\/\/simfoni.com\/","logo":{"@id":"https:\/\/simfoni.com\/engineering\/the-road-to-soc2-through-controls-that-build-trust\/#local-main-organization-logo"},"image":{"@id":"https:\/\/simfoni.com\/engineering\/the-road-to-soc2-through-controls-that-build-trust\/#local-main-organization-logo"},"sameAs":["https:\/\/www.facebook.com\/SimfoniApps\/","https:\/\/x.com\/simfoniapps","https:\/\/www.instagram.com\/simfoniapps\/","https:\/\/www.linkedin.com\/company\/simfoni\/","https:\/\/www.youtube.com\/@simfoni","https:\/\/g.page\/r\/CTMP26g2qypHEBM\/","https:\/\/www.capterra.com\/p\/206211\/Spend-Analytics\/","https:\/\/www.g2.com\/products\/simfoni-spend-analytics\/","https:\/\/www.glassdoor.com\/Overview\/Working-at-Simfoni-EI_IE3290778.11,18.htm","https:\/\/sourceforge.net\/software\/product\/Simfoni\/","https:\/\/news.google.com\/publications\/CAAqBwgKMMaWxAsw6bHbAw"],"description":"Simfoni is an AI-powered procurement and spend management platform designed to help enterprises gain complete visibility into organizational spend and turn procurement insight into measurable financial impact. The platform combines advanced spend analytics, intelligent sourcing automation, and tail spend management to enable procurement teams to identify savings opportunities, execute sourcing strategies efficiently, and improve supplier performance across global operations. Built for modern procurement organizations, Simfoni supports Chief Procurement Officers, strategic sourcing leaders, and finance teams who are responsible for driving cost optimization, supplier governance, and operational efficiency. By consolidating procurement data across multiple systems and suppliers, Simfoni provides a unified view of enterprise spend and enables organizations to prioritize sourcing initiatives that deliver measurable savings. Simfoni\u2019s platform integrates spend intelligence with automated sourcing execution, allowing procurement teams to scale sourcing activities without increasing headcount. The system helps organizations manage indirect spend, improve supplier engagement, and strengthen procurement governance through data-driven decision making. Trusted by global enterprises, Simfoni enables organizations to transform procurement from a reactive cost center into a strategic value driver by delivering visibility, automation, and measurable financial outcomes across the procurement lifecycle.","legalName":"Simfoni","foundingDate":"2015-08-25","numberOfEmployees":{"@type":"QuantitativeValue","minValue":"201","maxValue":"500"},"address":{"@id":"https:\/\/simfoni.com\/engineering\/the-road-to-soc2-through-controls-that-build-trust\/#local-main-place-address"},"telephone":["+1-973-718-7071","+44-208-098-2115"],"openingHoursSpecification":[{"@type":"OpeningHoursSpecification","dayOfWeek":["Monday","Tuesday","Wednesday","Thursday","Friday","Saturday","Sunday"],"opens":"00:00","closes":"23:59"}],"email":"info@simfoni.com"},{"@type":"Person","@id":"https:\/\/simfoni.com\/#\/schema\/person\/afc4d1749ccc888582602619fc5b02b8","name":"Simfoni","description":"Simfoni Delivers Next-generation Digital Procurement Transformation Through Spend Intelligence, Spend Automation &amp; Spend Analytics Software.","sameAs":["https:\/\/simfoni.com\/","https:\/\/www.facebook.com\/SimfoniApps\/","https:\/\/www.instagram.com\/simfoniapps\/","https:\/\/www.linkedin.com\/company\/simfoni\/","https:\/\/x.com\/simfoniapps","https:\/\/www.youtube.com\/@simfoni"]},{"@type":"PostalAddress","@id":"https:\/\/simfoni.com\/engineering\/the-road-to-soc2-through-controls-that-build-trust\/#local-main-place-address","streetAddress":"90 Washington Valley Road","addressLocality":"Bedminster","postalCode":"07921","addressRegion":"New Jersey","addressCountry":"US"},{"@type":"ImageObject","inLanguage":"en","@id":"https:\/\/simfoni.com\/engineering\/the-road-to-soc2-through-controls-that-build-trust\/#local-main-organization-logo","url":"https:\/\/simfoni.com\/wp-content\/uploads\/2021\/10\/Simfoni.com-Logo.jpg","contentUrl":"https:\/\/simfoni.com\/wp-content\/uploads\/2021\/10\/Simfoni.com-Logo.jpg","width":1000,"height":1000,"caption":"Simfoni"}]},"geo.placename":"Bedminster","geo.region":"United States (US)"},"_links":{"self":[{"href":"https:\/\/simfoni.com\/wp-json\/wp\/v2\/posts\/42123","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/simfoni.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/simfoni.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/simfoni.com\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/simfoni.com\/wp-json\/wp\/v2\/comments?post=42123"}],"version-history":[{"count":0,"href":"https:\/\/simfoni.com\/wp-json\/wp\/v2\/posts\/42123\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/simfoni.com\/wp-json\/wp\/v2\/media\/42125"}],"wp:attachment":[{"href":"https:\/\/simfoni.com\/wp-json\/wp\/v2\/media?parent=42123"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/simfoni.com\/wp-json\/wp\/v2\/categories?post=42123"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/simfoni.com\/wp-json\/wp\/v2\/tags?post=42123"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}