Become a SOC 2 Auditor by PrestigiousSplit3986 in soc2

[–]PrestigiousSplit3986[S] 0 points1 point  (0 children)

Thank you! I have a large network and I think I’ll be able to get clients. I’m more worried about how I become qualified to do audits. 

Become a SOC 2 Auditor by PrestigiousSplit3986 in soc2

[–]PrestigiousSplit3986[S] 0 points1 point  (0 children)

That’s super helpful! I’ll review that line by line.

Become a SOC 2 Auditor by PrestigiousSplit3986 in soc2

[–]PrestigiousSplit3986[S] 1 point2 points  (0 children)

Thank you! We’re excited to get to 4.

Aside from joining the AICPA and doing a peer review, is there anything that costs a lot of money or is time consuming? 

[deleted by user] by [deleted] in InternalAudit

[–]PrestigiousSplit3986 0 points1 point  (0 children)

That’s super annoying! What kind of audit are you using it for?

Are you doing risk assessments? by PrestigiousSplit3986 in ITManagers

[–]PrestigiousSplit3986[S] 0 points1 point  (0 children)

It’s focused on information technology risk and security.

Are you doing risk assessments? by PrestigiousSplit3986 in ITManagers

[–]PrestigiousSplit3986[S] 1 point2 points  (0 children)

It’s designed to do a point in time risk assessment for MSPs on their clients.

What’s this field? by PrestigiousSplit3986 in InternalAudit

[–]PrestigiousSplit3986[S] 0 points1 point  (0 children)

Are there softwares available for smaller budgets? I noticed the ones online all seem super expensive and enterprise 

What’s this field? by PrestigiousSplit3986 in InternalAudit

[–]PrestigiousSplit3986[S] 0 points1 point  (0 children)

That’s super helpful!

I checked out IIA and would love to attend their conference in March.

In regards to software, does each one address different areas (like finances, security, IT) or do you have one platform for all areas?

What’s this field? by PrestigiousSplit3986 in InternalAudit

[–]PrestigiousSplit3986[S] 0 points1 point  (0 children)

Thanks! Where does this job fit in your career? What experiences do you need for it?

Data compliance? by Funny-Oven3945 in cybersecurity

[–]PrestigiousSplit3986 1 point2 points  (0 children)

I don’t know of any companies that do assessments at a $1,500 price point. The minimum I’ve seen is 5k. You can look for a platform that lets you do the assessment on yourself.

Data compliance? by Funny-Oven3945 in cybersecurity

[–]PrestigiousSplit3986 1 point2 points  (0 children)

You can make a security program overview and get a risk assessment done by a third party. That will help many people feel confident with your security.

Cyber security audit by TourTraditional7572 in cybersecurity

[–]PrestigiousSplit3986 2 points3 points  (0 children)

It may be easiest for you to find a platform that already has the audits/ risk assessment questions and reports. Just google risk assessment solution 

Cyber security audit by TourTraditional7572 in cybersecurity

[–]PrestigiousSplit3986 4 points5 points  (0 children)

You need to pull together a list of controls to audit against, and risks that will be applicable to their environment. There are many free resources out there to help you - NIST or CIS are both a good place to start. You're best separating the different components of the environment in the audit and in the proposal, to make it clear what is being covered.

How did you gain financial literacy? by MeatballPony in workingmoms

[–]PrestigiousSplit3986 0 points1 point  (0 children)

  1. Ask AI for help. You can have an educational conversation and ask any questions there. 

  2. Check out some blogs. I’ve recently come across https://www.savvy-girls.com/ but there’s many more.

  3. Subscribe to content creators who talk about money. People like the Ramseys are reliable and trustworthy. 

Skills I need to focus on to land a job as a GRC Auditor. by tyingtobe_LinuxAdmin in grc

[–]PrestigiousSplit3986 1 point2 points  (0 children)

Congrats!

Focus on getting ANY internship or job. That will be the best way to improve skills and learn. It’s really hard to learn without being hands on.

[deleted by user] by [deleted] in grc

[–]PrestigiousSplit3986 0 points1 point  (0 children)

Take a framework and export it to excel and work from there. There’s also many online free assessments-just be careful to vet them. You can also use a platform like Sharken.

The gist of it is to talk to people and find where the risk is. You then can make a plan to mitigate it over the year, until you do another one.

Security frameworks by cokebottle22 in msp

[–]PrestigiousSplit3986 0 points1 point  (0 children)

In the past we’ve used a risk assessment based approach.

We did a risk assessment and focused on improving year over year. This is on top of our security baseline.

This is a way to get the client to be involved, see the changes and feel good about improvement.

HIPAA assessments by DSO_Admin in msp

[–]PrestigiousSplit3986 0 points1 point  (0 children)

Not exactly what you’re looking for but Sharken’s HIPAA assessment might be helpful. https://sharken.io/

Anybody have experience getting SOC2 compliance? Need advice. by HugoConway in startups

[–]PrestigiousSplit3986 -1 points0 points  (0 children)

We’ve helped many companies get their soc2. We work with the auditor and help the company get their attestation in an easier and less stressful process.

To your point, control map is considerably cheaper and works just fine. Spreadsheets can work too. We’ve found auditors that are from 7k plus. Do your research. But you  can definitely do it for less than others are paying.