OUR THOUGHTS ON:

Postcard from the 2018 AICPA SOC for Cybersecurity Conference

Cybersecurity|SSAE 18/SOC

By Troy Fine

I recently attended the AICPA’s SOC for Cybersecurity conference at the AICPA’s headquarters in Durham, North Carolina.  The conference covered the following areas:

  • The AICPA's Cybersecurity Risk Management reporting framework and how it may be used by organizations and practitioners to evaluate controls and communicate certain cybersecurity information to interested parties;
  • The components of an organization's cybersecurity risk management program;
  • The performance and reporting requirements of a SOC for Cybersecurity examination;
  • The description criteria that must be used by an organization when writing its description of its cybersecurity risk management program;
  • Key considerations prior to accepting a cybersecurity examination engagement and  planning considerations;
  • Key steps involved in performing the cybersecurity risk management examination; and
  • Key factors to consider while forming the opinion and preparing the practitioner's report.

Those in attendance at the conference received the SOC for Cybersecurity Certificate, which demonstrates the ability to apply the AICPA’s cybersecurity risk management reporting framework, analyze and examine an organization’s cybersecurity risk management program and report on an organization’s cybersecurity risk management program.

Overall, the conference was very insightful.  The audience was diverse and included representatives from public accounting firms and other organizations vested in SOC reporting (third-party service providers, users of the reports, consultants, etc.) from throughout the United States.

Schneider Downs’ participation at the SOC for Cybersecurity conference and other SOC professional forums demonstrates our firm’s commitment to remaining on the leading edge of SOC practices and ensuring that our team applies techniques that adhere to AICPA standards.  This commitment ensures that our clients’ examinations are conducted effectively and in accordance with current authoritative guidance aligned with leading practices.

For more information on the new SOC for Cybersecurity reporting framework, please contact Schneider Downs.

You’ve heard our thoughts… We’d like to hear yours

The Schneider Downs Our Thoughts On blog exists to create a dialogue on issues that are important to organizations and individuals. While we enjoy sharing our ideas and insights, we’re especially interested in what you may have to say. If you have a question or a comment about this article – or any article from the Our Thoughts On blog – we hope you’ll share it with us. After all, a dialogue is an exchange of ideas, and we’d like to hear from you. Email us at contactSD@schneiderdowns.com.

Material discussed is meant for informational purposes only, and it is not to be construed as investment, tax, or legal advice. Please note that individual situations can vary. Therefore, this information should be relied upon when coordinated with individual professional advice.

© 2018 Schneider Downs. All rights-reserved. All content on this site is property of Schneider Downs unless otherwise noted and should not be used without written permission.

comments