Blog

Practical notes on running a compliance program in Confluence: SOC 2 in practice, getting ready for an audit, and what's new in Compliance in a Box.

  1. Confluence policy management: beyond a wiki page

    What policy management needs beyond a wiki page, how to set up a policy area in Confluence by hand, and where manual document control breaks down.

  2. Vendor risk management for SOC 2: a practical guide

    How to manage vendor risk for SOC 2: a vendor inventory, risk tiers, reading vendor SOC 2 reports, subservice organizations, the annual review and the evidence to keep.

  3. Access control policy for SOC 2: what it should say

    What a SOC 2 access control policy should cover: least privilege, joiners and leavers, MFA and passwords, admin and shared accounts, reviews, exceptions and evidence.

  4. How to answer a security questionnaire before your SOC 2

    What security questionnaires are, the common formats, how to answer honestly before you have a SOC 2 report, and how to build an answer library that doubles as a readiness plan.

  5. SOC 2 readiness checklist for small teams

    A seven-phase SOC 2 readiness checklist for small teams, from scoping and owners to policies, controls, evidence, picking an auditor and the weeks before fieldwork.

  6. Which SOC 2 policies do you need? A practical list

    The SOC 2 policies an audit expects, grouped by topic, with what each covers and the criteria it supports, plus how to own, approve, review and roll them out.

  7. Policy version control and approvals auditors accept

    An approval only covers the exact text that was approved. What auditors check in policy version control, and an approval workflow that keeps approvals and published policies in step.

  8. How to run a user access review for SOC 2

    A step-by-step guide to the SOC 2 user access review: scoping systems, choosing reviewers, what to check, fixing what you find and the evidence to keep.

  9. How to run an incident response tabletop exercise

    Test your incident response plan in about 90 minutes: who to invite, a simple agenda, five ready-to-use scenarios with injects, and what to record for your SOC 2 auditor.