Open main menu
Home
Blog
About
Login
SOC 2 Assessment
SOC 2 Type 1 and Type 2 Self Assessment Questionnaire
0
Step 1
1
Step 2
2
Step 3
3
Review
Do you have an employee handbook that describes the responsibilities and expected behavior with regard to data and information system usage?
Yes
No
Are employees required to acknowledge the employee handbook as a part of onboarding?
Yes
No
Do you have a confidentiality agreement that prohibits any disclosure of information and other data to which the employee has been granted access?
Yes
No
Are employees required to acknowledge the confidentiality agreement as a part of onboarding?
Yes
No
Are managers required to complete performance reviews for direct reports at least annually?
Yes
No
Does your company perform background checks on all prospective employees who will potentially interact with sensitive data?
Yes
No
Does your company have a Board of Directors (or even an informal committee) that oversees your organizational security and/or compliance?
Yes
No
Does this group have any members who are independent from your company's management team?
Yes
No
Does this group meet at least annually and maintain formal meeting minutes?
Yes
No
Does this group have a documented charter of its roles and responsibilities as related to security and compliance oversight?
Yes
No
Does your company maintain an organizational chart? (Note - this might be automatically captured within your HR Integration).
Yes
No
Has management established defined roles and responsibilities to oversee implementation of the information security policy (such as a formal security team or manager)?
Yes
No
Are job descriptions documented for open positions as a part of the hiring process?
Yes
No
Are job descriptions maintained for existing positions which are critical to the function of your system/business?
Yes
No
Do employees complete security awareness training as a part of onboarding?
Yes
No
Do employees complete security awareness training at least annually?
Yes
No
Are employees and contractors who violate the code of conduct, subject to disciplinary actions documented in a formalized policy?
Yes
No
Next