Confluence policy management: beyond a wiki page
What policy management needs beyond a wiki page, how to set up a policy area in Confluence by hand, and where manual document control breaks down.
Practical notes on running a compliance program in Confluence: SOC 2 in practice, getting ready for an audit, and what's new in Compliance in a Box.
What policy management needs beyond a wiki page, how to set up a policy area in Confluence by hand, and where manual document control breaks down.
Why page views, likes and comments don't prove anyone read a Confluence page, where the usual workarounds break, and what a read confirmation should record.
What the SOC 2 CC3 criteria expect from a risk assessment, a step-by-step annual process for small teams, a risk register template and the mistakes to avoid.
How to manage vendor risk for SOC 2: a vendor inventory, risk tiers, reading vendor SOC 2 reports, subservice organizations, the annual review and the evidence to keep.
SOC 2 has no mandated controls list. How criteria, controls and evidence differ, common controls for a small SaaS company by area, and how a controls matrix ties them together.
A plain-English reference to the SOC 2 trust services criteria: the five categories, the Common Criteria CC1 to CC9, the optional series, and how to choose your scope.
What to write in each section of your information security policy, with example wording to adapt, what to leave to topic policies, and how to approve, review and roll it out.
What a SOC 2 access control policy should cover: least privilege, joiners and leavers, MFA and passwords, admin and shared accounts, reviews, exceptions and evidence.
Why SOC 2 auditors look for security awareness training, what a small company's program should cover, how often to train, and how to keep material, rosters and follow-ups as evidence.
How to run vulnerability management for SOC 2: what to scan, a monthly scan review, remediation SLAs by severity, risk acceptance, and the evidence auditors expect.
Whether SOC 2 requires a penetration test, how it differs from a vulnerability scan, and how to scope, time, run and evidence an annual pen test for your audit.
Prove your backups work: RTO and RPO in plain terms, a step-by-step quarterly restore test with a record template, an annual DR test, and the evidence SOC 2 auditors look for.
What security questionnaires are, the common formats, how to answer honestly before you have a SOC 2 report, and how to build an answer library that doubles as a readiness plan.
A seven-phase SOC 2 readiness checklist for small teams, from scoping and owners to policies, controls, evidence, picking an auditor and the weeks before fieldwork.
The SOC 2 policies an audit expects, grouped by topic, with what each covers and the criteria it supports, plus how to own, approve, review and roll them out.
What SOC 2 Type 1 and Type 2 reports test, how to choose which to get first, and what the observation period demands: every control running and leaving evidence, every period.
Why Confluence suits a SOC 2 program, how to lay out a compliance space, and the five gaps plain Confluence leaves in an audit (and how to close them).
SOC 2 controls recur. A calendar of the recurring activities by cadence, the evidence each should produce, and how to set owners, due dates and notice so audits are not a scramble.
What counts as SOC 2 evidence, how auditors sample it, and how to build an evidence library filed by control and period as the work happens.
An approval only covers the exact text that was approved. What auditors check in policy version control, and an approval workflow that keeps approvals and published policies in step.
What auditors expect from employee policy acknowledgements, when to ask people again after a policy changes, and how to track completion without chasing people by hand.
A step-by-step guide to the SOC 2 user access review: scoping systems, choosing reviewers, what to check, fixing what you find and the evidence to keep.
Test your incident response plan in about 90 minutes: who to invite, a simple agenda, five ready-to-use scenarios with injects, and what to record for your SOC 2 auditor.