<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <title>Compliance in a Box blog</title>
  <subtitle>Practical notes on running a SOC 2 compliance program in Confluence.</subtitle>
  <link href="https://compliance.auralitesolutions.com/blog/feed.xml" rel="self" type="application/atom+xml"/>
  <link href="https://compliance.auralitesolutions.com/blog/" rel="alternate" type="text/html"/>
  <id>https://compliance.auralitesolutions.com/blog/</id>
  <updated>2026-10-01T00:00:00Z</updated>
  <author><name>Auralite Solutions</name></author>
  <icon>https://compliance.auralitesolutions.com/assets/favicon-32.png</icon>
  <entry>
    <title>Confluence policy management: beyond a wiki page</title>
    <link href="https://compliance.auralitesolutions.com/blog/confluence-policy-management.html"/>
    <id>https://compliance.auralitesolutions.com/blog/confluence-policy-management.html</id>
    <published>2026-10-01T00:00:00Z</published>
    <updated>2026-10-01T00:00:00Z</updated>
    <category term="Confluence"/>
    <summary>What policy management needs beyond a wiki page, how to set up a policy area in Confluence by hand, and where manual document control breaks down.</summary>
  </entry>
  <entry>
    <title>Confluence read confirmation: proving people read a page</title>
    <link href="https://compliance.auralitesolutions.com/blog/confluence-read-confirmation.html"/>
    <id>https://compliance.auralitesolutions.com/blog/confluence-read-confirmation.html</id>
    <published>2026-10-01T00:00:00Z</published>
    <updated>2026-10-01T00:00:00Z</updated>
    <category term="Confluence"/>
    <summary>Why page views, likes and comments don't prove anyone read a Confluence page, where the usual workarounds break, and what a read confirmation should record.</summary>
  </entry>
  <entry>
    <title>SOC 2 risk assessment: a step-by-step guide with template</title>
    <link href="https://compliance.auralitesolutions.com/blog/soc2-risk-assessment.html"/>
    <id>https://compliance.auralitesolutions.com/blog/soc2-risk-assessment.html</id>
    <published>2026-10-01T00:00:00Z</published>
    <updated>2026-10-01T00:00:00Z</updated>
    <category term="SOC 2 basics"/>
    <summary>What the SOC 2 CC3 criteria expect from a risk assessment, a step-by-step annual process for small teams, a risk register template and the mistakes to avoid.</summary>
  </entry>
  <entry>
    <title>Vendor risk management for SOC 2: a practical guide</title>
    <link href="https://compliance.auralitesolutions.com/blog/vendor-risk-management.html"/>
    <id>https://compliance.auralitesolutions.com/blog/vendor-risk-management.html</id>
    <published>2026-10-01T00:00:00Z</published>
    <updated>2026-10-01T00:00:00Z</updated>
    <category term="Evidence"/>
    <summary>How to manage vendor risk for SOC 2: a vendor inventory, risk tiers, reading vendor SOC 2 reports, subservice organizations, the annual review and the evidence to keep.</summary>
  </entry>
  <entry>
    <title>SOC 2 controls list: common controls for small SaaS teams</title>
    <link href="https://compliance.auralitesolutions.com/blog/soc2-controls-list.html"/>
    <id>https://compliance.auralitesolutions.com/blog/soc2-controls-list.html</id>
    <published>2026-10-01T00:00:00Z</published>
    <updated>2026-10-01T00:00:00Z</updated>
    <category term="SOC 2 basics"/>
    <summary>SOC 2 has no mandated controls list. How criteria, controls and evidence differ, common controls for a small SaaS company by area, and how a controls matrix ties them together.</summary>
  </entry>
  <entry>
    <title>SOC 2 trust services criteria explained, and which to choose</title>
    <link href="https://compliance.auralitesolutions.com/blog/trust-services-criteria.html"/>
    <id>https://compliance.auralitesolutions.com/blog/trust-services-criteria.html</id>
    <published>2026-10-01T00:00:00Z</published>
    <updated>2026-10-01T00:00:00Z</updated>
    <category term="SOC 2 basics"/>
    <summary>A plain-English reference to the SOC 2 trust services criteria: the five categories, the Common Criteria CC1 to CC9, the optional series, and how to choose your scope.</summary>
  </entry>
  <entry>
    <title>An information security policy template, section by section</title>
    <link href="https://compliance.auralitesolutions.com/blog/information-security-policy.html"/>
    <id>https://compliance.auralitesolutions.com/blog/information-security-policy.html</id>
    <published>2026-10-01T00:00:00Z</published>
    <updated>2026-10-01T00:00:00Z</updated>
    <category term="Policies"/>
    <summary>What to write in each section of your information security policy, with example wording to adapt, what to leave to topic policies, and how to approve, review and roll it out.</summary>
  </entry>
  <entry>
    <title>Access control policy for SOC 2: what it should say</title>
    <link href="https://compliance.auralitesolutions.com/blog/access-control-policy.html"/>
    <id>https://compliance.auralitesolutions.com/blog/access-control-policy.html</id>
    <published>2026-10-01T00:00:00Z</published>
    <updated>2026-10-01T00:00:00Z</updated>
    <category term="Access control"/>
    <summary>What a SOC 2 access control policy should cover: least privilege, joiners and leavers, MFA and passwords, admin and shared accounts, reviews, exceptions and evidence.</summary>
  </entry>
  <entry>
    <title>Security awareness training for SOC 2: what auditors expect</title>
    <link href="https://compliance.auralitesolutions.com/blog/security-awareness-training.html"/>
    <id>https://compliance.auralitesolutions.com/blog/security-awareness-training.html</id>
    <published>2026-10-01T00:00:00Z</published>
    <updated>2026-10-01T00:00:00Z</updated>
    <category term="Policies"/>
    <summary>Why SOC 2 auditors look for security awareness training, what a small company's program should cover, how often to train, and how to keep material, rosters and follow-ups as evidence.</summary>
  </entry>
  <entry>
    <title>Vulnerability management for SOC 2: the monthly scan review</title>
    <link href="https://compliance.auralitesolutions.com/blog/vulnerability-management.html"/>
    <id>https://compliance.auralitesolutions.com/blog/vulnerability-management.html</id>
    <published>2026-10-01T00:00:00Z</published>
    <updated>2026-10-01T00:00:00Z</updated>
    <category term="Evidence"/>
    <summary>How to run vulnerability management for SOC 2: what to scan, a monthly scan review, remediation SLAs by severity, risk acceptance, and the evidence auditors expect.</summary>
  </entry>
  <entry>
    <title>SOC 2 penetration test: is it required, and how to run one</title>
    <link href="https://compliance.auralitesolutions.com/blog/soc2-penetration-test.html"/>
    <id>https://compliance.auralitesolutions.com/blog/soc2-penetration-test.html</id>
    <published>2026-10-01T00:00:00Z</published>
    <updated>2026-10-01T00:00:00Z</updated>
    <category term="Evidence"/>
    <summary>Whether SOC 2 requires a penetration test, how it differs from a vulnerability scan, and how to scope, time, run and evidence an annual pen test for your audit.</summary>
  </entry>
  <entry>
    <title>How to run a backup restore test and a DR test for SOC 2</title>
    <link href="https://compliance.auralitesolutions.com/blog/backup-restore-dr-testing.html"/>
    <id>https://compliance.auralitesolutions.com/blog/backup-restore-dr-testing.html</id>
    <published>2026-10-01T00:00:00Z</published>
    <updated>2026-10-01T00:00:00Z</updated>
    <category term="Evidence"/>
    <summary>Prove your backups work: RTO and RPO in plain terms, a step-by-step quarterly restore test with a record template, an annual DR test, and the evidence SOC 2 auditors look for.</summary>
  </entry>
  <entry>
    <title>How to answer a security questionnaire before your SOC 2</title>
    <link href="https://compliance.auralitesolutions.com/blog/security-questionnaires.html"/>
    <id>https://compliance.auralitesolutions.com/blog/security-questionnaires.html</id>
    <published>2026-10-01T00:00:00Z</published>
    <updated>2026-10-01T00:00:00Z</updated>
    <category term="SOC 2 basics"/>
    <summary>What security questionnaires are, the common formats, how to answer honestly before you have a SOC 2 report, and how to build an answer library that doubles as a readiness plan.</summary>
  </entry>
  <entry>
    <title>SOC 2 readiness checklist for small teams</title>
    <link href="https://compliance.auralitesolutions.com/blog/soc2-audit-readiness-checklist.html"/>
    <id>https://compliance.auralitesolutions.com/blog/soc2-audit-readiness-checklist.html</id>
    <published>2026-10-01T00:00:00Z</published>
    <updated>2026-10-01T00:00:00Z</updated>
    <category term="SOC 2 basics"/>
    <summary>A seven-phase SOC 2 readiness checklist for small teams, from scoping and owners to policies, controls, evidence, picking an auditor and the weeks before fieldwork.</summary>
  </entry>
  <entry>
    <title>Which SOC 2 policies do you need? A practical list</title>
    <link href="https://compliance.auralitesolutions.com/blog/soc2-policies-list.html"/>
    <id>https://compliance.auralitesolutions.com/blog/soc2-policies-list.html</id>
    <published>2026-10-01T00:00:00Z</published>
    <updated>2026-10-01T00:00:00Z</updated>
    <category term="Policies"/>
    <summary>The SOC 2 policies an audit expects, grouped by topic, with what each covers and the criteria it supports, plus how to own, approve, review and roll them out.</summary>
  </entry>
  <entry>
    <title>SOC 2 Type 1 vs Type 2: which report should you get first?</title>
    <link href="https://compliance.auralitesolutions.com/blog/soc2-type-1-vs-type-2.html"/>
    <id>https://compliance.auralitesolutions.com/blog/soc2-type-1-vs-type-2.html</id>
    <published>2026-10-01T00:00:00Z</published>
    <updated>2026-10-01T00:00:00Z</updated>
    <category term="SOC 2 basics"/>
    <summary>What SOC 2 Type 1 and Type 2 reports test, how to choose which to get first, and what the observation period demands: every control running and leaving evidence, every period.</summary>
  </entry>
  <entry>
    <title>How to run a SOC 2 compliance program in Confluence</title>
    <link href="https://compliance.auralitesolutions.com/blog/soc2-in-confluence.html"/>
    <id>https://compliance.auralitesolutions.com/blog/soc2-in-confluence.html</id>
    <published>2026-10-01T00:00:00Z</published>
    <updated>2026-10-01T00:00:00Z</updated>
    <category term="Confluence"/>
    <summary>Why Confluence suits a SOC 2 program, how to lay out a compliance space, and the five gaps plain Confluence leaves in an audit (and how to close them).</summary>
  </entry>
  <entry>
    <title>The SOC 2 compliance calendar: recurring controls by cadence</title>
    <link href="https://compliance.auralitesolutions.com/blog/soc2-compliance-calendar.html"/>
    <id>https://compliance.auralitesolutions.com/blog/soc2-compliance-calendar.html</id>
    <published>2026-10-01T00:00:00Z</published>
    <updated>2026-10-01T00:00:00Z</updated>
    <category term="SOC 2 basics"/>
    <summary>SOC 2 controls recur. A calendar of the recurring activities by cadence, the evidence each should produce, and how to set owners, due dates and notice so audits are not a scramble.</summary>
  </entry>
  <entry>
    <title>SOC 2 evidence collection: building an audit-ready library</title>
    <link href="https://compliance.auralitesolutions.com/blog/soc2-evidence-collection.html"/>
    <id>https://compliance.auralitesolutions.com/blog/soc2-evidence-collection.html</id>
    <published>2026-10-01T00:00:00Z</published>
    <updated>2026-10-01T00:00:00Z</updated>
    <category term="Evidence"/>
    <summary>What counts as SOC 2 evidence, how auditors sample it, and how to build an evidence library filed by control and period as the work happens.</summary>
  </entry>
  <entry>
    <title>Policy version control and approvals auditors accept</title>
    <link href="https://compliance.auralitesolutions.com/blog/policy-approval-version-control.html"/>
    <id>https://compliance.auralitesolutions.com/blog/policy-approval-version-control.html</id>
    <published>2026-10-01T00:00:00Z</published>
    <updated>2026-10-01T00:00:00Z</updated>
    <category term="Policies"/>
    <summary>An approval only covers the exact text that was approved. What auditors check in policy version control, and an approval workflow that keeps approvals and published policies in step.</summary>
  </entry>
  <entry>
    <title>Policy acknowledgement tracking for SOC 2: a practical guide</title>
    <link href="https://compliance.auralitesolutions.com/blog/policy-acknowledgement-tracking.html"/>
    <id>https://compliance.auralitesolutions.com/blog/policy-acknowledgement-tracking.html</id>
    <published>2026-10-01T00:00:00Z</published>
    <updated>2026-10-01T00:00:00Z</updated>
    <category term="Policies"/>
    <summary>What auditors expect from employee policy acknowledgements, when to ask people again after a policy changes, and how to track completion without chasing people by hand.</summary>
  </entry>
  <entry>
    <title>How to run a user access review for SOC 2</title>
    <link href="https://compliance.auralitesolutions.com/blog/user-access-review.html"/>
    <id>https://compliance.auralitesolutions.com/blog/user-access-review.html</id>
    <published>2026-10-01T00:00:00Z</published>
    <updated>2026-10-01T00:00:00Z</updated>
    <category term="Access control"/>
    <summary>A step-by-step guide to the SOC 2 user access review: scoping systems, choosing reviewers, what to check, fixing what you find and the evidence to keep.</summary>
  </entry>
  <entry>
    <title>How to run an incident response tabletop exercise</title>
    <link href="https://compliance.auralitesolutions.com/blog/incident-response-tabletop-exercise.html"/>
    <id>https://compliance.auralitesolutions.com/blog/incident-response-tabletop-exercise.html</id>
    <published>2026-10-01T00:00:00Z</published>
    <updated>2026-10-01T00:00:00Z</updated>
    <category term="Incident response"/>
    <summary>Test your incident response plan in about 90 minutes: who to invite, a simple agenda, five ready-to-use scenarios with injects, and what to record for your SOC 2 auditor.</summary>
  </entry>
</feed>
