PECB Certified Lead SOC 2 Analyst

Five-day PECB course on planning, implementing and maintaining SOC 2 compliance, with the certification exam on the final day.

Organisations that handle sensitive data or outsource key business operations need to show that data security and privacy are being looked after. SOC 2 is the framework used to demonstrate that. This course gives you the basis to manage and mitigate information security risk, align with regulatory requirements, and build trust with clients and stakeholders.

Who the course is for

  • Managers and consultants who want to broaden their knowledge of SOC 2 compliance and controls
  • IT professionals and information security risk managers who want to strengthen their grasp of SOC 2 requirements and practice
  • Compliance officers responsible for establishing, implementing and managing SOC 2 compliance programmes
  • Members of audit and compliance teams involved in SOC 2 readiness assessments and internal audits
  • Professionals who need to establish and manage information security and compliance controls that meet the SOC 2 criteria
  • Executives and business leaders who need to understand SOC 2 to support their organisation's risk management and compliance work
  • Security analysts and incident response coordinators responsible for the security, availability, processing integrity, confidentiality and privacy of information systems

Content

  • Day 1: Introduction to the SOC 2 framework: course objectives and structure, information security standards and regulations, overview of SOC 2, Trust Services Criteria (TSC), initiating the compliance programme, analysing the requirements and defining scope
  • Day 2: Risk management and policy development: gap analysis and remediation, risk management, documentation requirements and policy development, roles and responsibilities
  • Day 3: Implementing SOC 2 controls and incident response: implementation of controls, awareness and training, continued work on controls, incident management and business continuity and disaster recovery (BCDR)
  • Day 4: Auditing, reporting and continual improvement: SOC 2 audit readiness and analysis, monitoring and reporting, continual improvement and closing of the course
  • Day 5: Certification exam

Certification

The exam runs for three hours and covers five competency domains: the fundamental principles and concepts of SOC 2, the SOC 2 criteria, planning the implementation, implementing the requirements, and monitoring security measures and preparing for a SOC 2 certification audit. Passing the exam lets you apply for one of PECB's SOC 2 credentials. Which one you receive depends on your education, work experience and documented project experience. The "PECB Certified Lead SOC 2 Analyst" credential requires five years of work experience, two of them in information security, 300 hours of SOC 2 project experience, and signing the PECB Code of Ethics. Exam and certification fees are included in the course, and participants who do not pass may retake the exam once at no cost within twelve months. Participants receive course material of more than 450 pages and an attestation worth 31 CPD credits.