Research Paper MIS - SOC 2 Compliance

sirivasu
SOC2Breakdown.pdf

BREAKDOWN

hen the American Institute of Certified Public Accountants (AICPA) released guidance for three new Service Organization Control (SOC) reports in May 2011, auditors, management, and other interested parties asked: "How do these SOC reports differ from the Statement on Auditing Standards No. 70 (SAS 70) report? What's the difference between a SOC 1, SOC 2, and SOC 3 report? Are all three reports necessary? Where do I start?"

In particular, internal auditors have struggled to understand the requirements and implications of the SOC 2 report—a new concept for reporting on controls over compliance and operations—and who should be its primary requester or user. Internal auditors of companies that outsource their processes and specifically focus on SOC 2 reporting, its interested parties, criteria, applicability, and rel- evance can benefit from guidance on this rigorous framework.

54 INTERNAL AUDITOR FEBRUARY 2012

Vickie Choe

David Taylor

Aleksei Brizhik

REV.I.E.W.REP.QRI.D.IEF.ERE.N.ŒS

S AS 70 reports—put forth by the AICPA's Auditing Standards Board—have often been errone-

ously interpreted as certifying controls over compliance and operations. How- ever, the original purpose of the SAS 70 was to evaluate the effectiveness of internal controls over financial report- ing. The introduction of SOC 1, 2, and 3 clears up confusion about the focus of service organization reports and their intended audience. SOC 1 ( T y p e I a n d II) F o r m e r l y

known as the SAS 70 report, the SOC 1 report is now governed under Statement on Standards for Attestation Engagements (SSAE) 16: Reporting on Controls at a Service Organization. Major differences between the SAS 70 and SOC 1 report include management assertion and timing. In the SOC 1 Type I report, management is required to provide an assertion on the fair description of the system and related controls and the design of controls and its suitability to meet control objec- tives. The certified public accountant (CPA) then opines on these assertions. The SOC 1 Type II report contains the information included in the Type I report, as well as management's

assertion on the operat- ing effectiveness of con- trols, the CPA's opinion on all management asser- tions, and a description of the CPA's testing and results. Under SAS 70, the evaluation of controls over financial reporting occurred as of a point in time (e.g., as of June 15, 2011). Under SSAE 16, the SOC 1 Type I report evaluates controls as of a point in time, and the SOC 1 Type II report evalu- ates controls for a period of at least six months (e.g., from Dec. 15, 2010, to June 15, 2011). The type of SOC 1 report chosen is at the discretion of management, auditors, and related par- ties based on the intended audience and the use of the report. SOC 2 ( T y p e I and II) T h e S O C 2

reports follow the same management assertion and timing guidelines as SOC 1. However, the major difference is that SOC 2 reports on controls over compliance and operations, according to the U.S. Public Company Account- ing Oversight Board's (PCAOB's) Attest Engagements Section 101 (AT 101). The Trust Services Principles and

Criteria (TSPC) — put forth by the AICPA and the Canadian Institute for Chartered Accountants — forms the basis of SOC 2 reporting and includes security, availability, processing integ- rity, confidentiality, and privacy of service provider systems. SOC 3 The SOC 3 report is founded on the same TSPCs as SOC 2. How- ever, the main differences are that SOC 3 does not require management assertions, does not provide an audited opinion of such assertions, and does not incorporate Type I/Type 11 reports. SOC 3 is an unaudited report of con- trols over compliance and operations in which the CPA opines on the service organization's maintenance of effective system controls related to the TSPCs. Unlike SOC 1 and 2, the SOC 3 report is available to the general public.

FEBRUARY 2012 INTERNAL AUDITOR 55

s o c 2 BREAKDOWN

..KN.OV\Í..IH.E.PAB.T.IE5..I.N.VQLV.ED..

T he SOC 2 report is intended for knowledgeable parties and stakeholders who have an under- standing of how the service organization's system

interfaces with, or is used by, the user organization, which includes the nature of the service provided, as well as internal controls and their inherent limitations.

Service Organization Management/IT The service organization provides services to the user organization. Service organization management, together with the IT function, should assess compliance and operations controls related to the TSPCs. Service organization management should meet with the contracted service auditors to discuss S O C 2 reporting and the scope of work under the new attestation standards.

Service Organization Auditor or CPA The service organization auditor or CPA provides attestation services based on the service organization's management assertions. Auditors should become familiar with service organization reporting changes to provide value to user organizations that rely on the SOC 2 report. User Organization Finance Management User organiza- tion finance management should consider the need for a report on controls over compliance and operations for outsourced services. The company's exposure to risks related to TSPCs, the corresponding impact of a realized risk, and the value of a SOC 2 report for shareholders also should be assessed. User Organization IT Management User organization IT management should assess the sufficiency of a service organization's IT function and related controls. Further, IT management should advise finance management of the value gained through outsourcing and the service organization's ability to meet the business needs of the user organization and its customers. User Organization Auditor or CPA The user organization auditor or CPA reviews the SOC 2 report and considers the service auditor's opinion on the effectiveness of controls over compliance and operations. Whereas in the past, the user auditor may have requested the SAS 70 report to certify con- trols over financial reporting and operations, the user auditor now should consider the value of requesting both SOC 1 and SOC 2 reports to determine the degree of reliance placed on the service organization's overall control environment. External Regulators External regulators monitor service organization compliance with rules defined by industry stan- dards. Companies should ensure that their IT systems adhere to industry requirements such as those specific to financial services, energy, and defense.

U N D E R S T A W D THE TSPCS

T he foundation of SOC 2 reporting is defined by five TSPCs, which act as a guide for the evaluation of

control objecdves, risks, vulnerabilities, and potential impact. Security The system is protected from unauthorized logical and physi- cal access. Topics to consider include IT security policy, security awareness

56 INTERNAL AUDITOR FEBRUARY 2012

I T management of user organizations should consider requesting a SOC 2 report for services that are often out- sourced, which can include:

Cloud Computing —allows an unlimited number of ma- chines to act as one system, or "cloud," which is accessible by the user. This allows for easy integration of technical resourc- es, higher performance, and lack of a single point of failure.

Data Center Activities — manages, operates, and main- tains the user's data center, infrastructure, and applications. Functional fT support related to physical security, hardware, change management, and environmental controls is provided. Payroll Processing — processes payroll runs, updates pay- roll data based on employee changes, offers payroll payment options, and generates payroll reports. Health-care Processing — processes health insurance claims, maintains medical records, and communicates related information to medical providers, employees, and employers. Financial Transaction Processing — performs tasks for the customer on behalf of the financial institution, which includes processing securities transactions, maintaining account records, providing transaction confirmations, and delivering account statements. Customer Service — responds to the user entity's customer inquiries through online or telephone support. Services include troubleshooting, warranty solutions, and customer complaint resolution. Sales — takes and processes customer orders, tracks orders, manages sales contracts, responds to customer inquiries, and generates sales forecasts.

Outsourcing is becoming more common, increasing the risk that service organizations may not meet the needs of users.

training, logical access, physical access, security monitoring, user authentica- tion settings, asset classification and lnanagement, configuration manage- ment, and change management. Availability The system is available for use per terms agreed upon by the service and user organization. Issues to consider include recovery time objec- tive, availability policy, backup and retention policy, disaster recovery plan, and business continuity management.

Processing Integrity The system processes authorized transactions timely with completeness and accuracy. Areas to consider include processing integrity policies, accuracy checks (e.g., cyclical redundancy check), tracing, vouching, timeliness, authorization (e.g., func- tional acknowledgments), and accuracy of inputs. Confidentiality The system is designed to safeguard against the leak- age of sensitive information. Areas to

consider include the confidentiality policy, confidentiality of inputs and outputs, data processing, and informa- tion disclosures. Privacy The system collects, uses, retains, and discloses personal infor- mation per the service organization's privacy policy and AICPA privacy prin- ciples. Areas to consider include the pri- vacy policy, collection process, data use and retention, data access, information disclosures, and privacy monitoring.

FEBRUARY 2012 INTERNAL AUDITOR 57

s o c 2 BREAKDOWN TO COMMENT on this article, EMAIL the the authors at vickie.choe@>theiia.org

C.QN.S.I.DER.RE.AL:.LIF.E.£;XAM.PLE.S

S everal examples of cyberattacks launched in 2011 have an underlying theme: Organizational dependence on technology often outweighs the defense of such technology. In all cases, two or more of the TSPCs

were compromised beginning with security. Such cases highlight the value that a S O C 2 report may provide in assessing the TSPCs as they relate to real-life threats.

Epsilon Data Management The email marketing company sends more than 40 billion emails a year on behalf of more than 2,500 clients. The privacy and confidentiality of customer data was compromised when a security breach exposed the customer names and email addresses of big-name companies such

as Best Buy, Cap- ital One, Hilton, and Target. The biggest concern was that hackers would use such information to attempt phishing attacks, whereby the attacker sends the unknow- ing ctistomer an email request to provide sensitive information such as user name,

password, and credit card details, often by directing the customer to a fictitious website. Customers of the many clients that use Epsilon may have received an email notifying them of the security breach and warning them of potential phishing attacks. Sony PlayStation The popular gaming network was hacked, and the personal information of more than 70 million subscribers was compromised, including names, email addresses, account login credentials, password verification answers, and credit card data. The attack disrupted network availability for 23 days, resulting in a company loss of US $171 million. Hyundai Capital Hackers stole personal information and passwords of 420,000 customers from the auto financer's database, jeopardizing the security of the database, confidentiality of data, and customer privacy. To add insult to injury, the hackers demanded a ransom for the stolen data. The company noti- fied the police and agreed to pay a partial ransom. One hacker was arrested after being captured on video withdrawing the ransom money from an ATM. U.S. Department of Defense Hackers, assumed to be backed by a foreign government, stole 24,000 files from a Pentagon contractor's computer system in March 2011. The breach, which exposed top military and intellectual property, prompted the Obama administration to push for a cybersecurity initiative that will regard cyberspace as a military domain equivalent to land, sea, and air.

THE VALUE OF SOC In today's global economy, outsourc- ing—whether it be tasks, processes, or entire functions—is becoming more and more common. Such dependence on third-party systems increases the risk that service organizations may not meet the needs of users. With the introduc- tion of the SOC reports, it is clear that a singular report on controls over finan- cial reporting is no longer sufficient. SOC 2 attempts to bridge this gap and build confidence in service organization systems. Its creation addresses the dis- tinct possibility that ineffective service controls over operations can have a fatal financial impact on user organizations. The recent increase in the severity of cyberattacks further emphasizes the importance of service systems' security, reliability, and recovery. Therefore, user organizations should take the time to consider the value of SOC 2 and the assurance it may provide for controls over operations and compliance. ^

VICKIE CHOE, CPA, CISA, is a senior iT

auditor with AES Corp. in Arlington, Va.

DAVID TAYLOR, CISA, is a senior

manager of internai audit with AES Corp.

ALEKSEI BRiZHIK, CPA, CFE, CiSA, is

the internal audit director of Sarbanes-

Oxiey compliance with AES Corp.

58 INTERNAL AUDITOR FEBRUARY 2012

Copyright of Internal Auditor is the property of Internal Auditor and its content may not be copied or emailed to

multiple sites or posted to a listserv without the copyright holder's express written permission. However, users

may print, download, or email articles for individual use.