Advanced SOC 2 Auditing

Dereje Deressa
3 min readJun 7, 2024

In a SOC 2 audit, the COSO (Committee of Sponsoring Organizations of the Treadway Commission) framework is commonly used to assess the effectiveness of an organization’s internal controls. Here are all the COSO principles that can be included in your study materials for a SOC 2 audit:

Control Environment

  1. Principle 1: The organization demonstrates a commitment to integrity and ethical values. The board of directors and senior management set the tone at the top and established standards of conduct.
  2. Principle 2: The board of directors demonstrates independence from management and exercises oversight of the development and performance of internal control. The board maintains oversight responsibilities and provides guidance on the internal control system.
  3. Principle 3: Management establishes, with board oversight, structures, reporting lines, and appropriate authorities and responsibilities to pursue objectives. The organization defines and assigns responsibilities and reporting lines to achieve its objectives.
  4. Principle 4: The organization demonstrates a commitment to attract, develop, and retain competent individuals who align with its objectives. The organization ensures that employees possess the necessary skills and knowledge.
  5. Principle 5: The organization holds individuals

--

--

Dereje Deressa

Cybersecurity Practitioner | Digital Entrepreneur | Technologist