[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"detail-sidebar-cat-1-en-105":3,"doc-seo-191363-105":53,"doc-detail-191363-en":126},{"code":4,"msg":5,"data":6},0,"success",[7,14,19,24,29,34,39,44,49],{"id":8,"doc_module":9,"doc_module_name":10,"category_name":11,"show_sort_weight":12,"slug":13},11,1,"Template","Presentations",90,"presentations",{"id":15,"doc_module":9,"doc_module_name":10,"category_name":16,"show_sort_weight":17,"slug":18},12,"Resumes",80,"resumes",{"id":20,"doc_module":9,"doc_module_name":10,"category_name":21,"show_sort_weight":22,"slug":23},14,"Invoices",70,"invoices",{"id":25,"doc_module":9,"doc_module_name":10,"category_name":26,"show_sort_weight":27,"slug":28},15,"Posters",60,"posters",{"id":30,"doc_module":9,"doc_module_name":10,"category_name":31,"show_sort_weight":32,"slug":33},16,"Social Media",50,"social-media",{"id":35,"doc_module":9,"doc_module_name":10,"category_name":36,"show_sort_weight":37,"slug":38},17,"Forms",40,"forms",{"id":40,"doc_module":9,"doc_module_name":10,"category_name":41,"show_sort_weight":42,"slug":43},18,"Letters",30,"letters",{"id":45,"doc_module":9,"doc_module_name":10,"category_name":46,"show_sort_weight":47,"slug":48},21,"Paper Templates",5,"papers-templates",{"id":50,"doc_module":9,"doc_module_name":10,"category_name":51,"show_sort_weight":4,"slug":52},158,"General","general-158",{"code":4,"msg":54,"data":55},"ok",{"site_id":56,"language":57,"slug":58,"title":59,"keywords":60,"description":61,"schema_data":62,"social_meta":119,"head_meta":121,"extra_data":123,"updated_unix":125},105,"en","january2022-soc-2-checklist-february-to-april-mastermind","January+2022 - SOC 2 Checklist - February to April Mastermind","","SOC 2 checklist materials structured by monthly Mastermind themes, guiding organization-wide readiness across governance, communications, risk management, and monitoring. January focuses on executive buy-in, confirming technical and security owners, defining scope and timelines, and ensuring adequate time and resources. February emphasizes policy and procedure communication, documentation collection, gap analysis, and information security policy ownership. March adds risk assessment, asset inventory, risk registers, mitigation plans, and scanning. April covers audits, reviews, monitoring tools, training, access removal, and reporting actions.",{"@graph":63,"@context":118},[64,80,101],{"@type":65,"itemListElement":66},"BreadcrumbList",[67,71,74,77],{"item":68,"name":69,"@type":70,"position":9},"https://docshare.wps.com","Home","ListItem",{"item":72,"name":10,"@type":70,"position":73},"https://docshare.wps.com/template/",2,{"item":75,"name":36,"@type":70,"position":76},"https://docshare.wps.com/template/forms/",3,{"item":78,"name":59,"@type":70,"position":79},"https://docshare.wps.com/template/january2022-soc-2-checklist-february-to-april-mastermind/191363/",4,{"url":78,"name":59,"@type":81,"image":82,"author":87,"headline":59,"publisher":90,"fileFormat":93,"inLanguage":57,"description":61,"dateModified":94,"datePublished":95,"encodingFormat":93,"isAccessibleForFree":96,"interactionStatistic":97},"DigitalDocument",{"url":83,"@type":84,"width":85,"height":86},"https://docshare.wps.com/thumbnails/january2022-soc-2-checklist-february-to-april-mastermind/191363.png","ImageObject",442,249,{"name":88,"@type":89},"Aurora","Person",{"url":68,"name":91,"@type":92},"DocShare","Organization","application/pdf","2026-09-29","2026-09-03",true,{"@type":98,"interactionType":99,"userInteractionCount":79},"InteractionCounter",{"@type":100},"ViewAction",{"@type":102,"mainEntity":103},"FAQPage",[104,110,114],{"name":105,"@type":106,"acceptedAnswer":107},"What does January Mastermind focus on for SOC 2 readiness?","Question",{"text":108,"@type":109},"January centers on organization and management: establishing a leadership structure, confirming technical and security ownership, defining scope and timelines, and ensuring resources for security and compliance.","Answer",{"name":111,"@type":106,"acceptedAnswer":112},"How does February Mastermind support SOC 2 communication requirements?",{"text":113,"@type":109},"February emphasizes written policies and procedures and a maintained communication process, including gathering and updating documentation, reviewing the information security policy, and assigning policy sections to stakeholders for edits.",{"name":115,"@type":106,"acceptedAnswer":116},"What key activities are included in March Mastermind risk management?",{"text":117,"@type":109},"March requires revising the information security policy, creating an asset inventory and risk register, conducting a formal risk assessment, developing a risk mitigation plan with controls, and implementing vulnerability scanning and penetration testing.","https://schema.org",{"og:url":78,"og:type":120,"og:title":59,"og:site_name":91,"og:description":61},"article",{"robots":122,"canonical":78},"index,follow",{"doc_id":124,"site_id":56},191363,1790180161,{"code":4,"msg":5,"data":127},{"doc_id":124,"user_id":128,"nickname":88,"user_avatar":129,"doc_module":9,"category_id":35,"category_name":36,"doc_title":59,"doc_description":61,"doc_content":130,"file_id":131,"file_url":132,"file_type":133,"file_size":134,"view_count":79,"is_deleted":4,"is_public":9,"is_downloadable":9,"audit_status":9,"page_count":135,"language":136,"language_code":57,"site_id":56,"html_lang":57,"table_of_contents":137,"faqs":138,"seo_title":139,"seo_description":61,"update_tm":140,"read_time":141},4810365810221,"https://ap-avatar.wpscdn.com/davatar_155a257f0dc6eb9ab79c44ca47cae57d","| In Plain English | January Mastermind |\n| --- | --- |\n| Organization and Management examines the leadership structure of your company to determine if there is a defined chain of command to ensure that every employee has a clear area of responsibility such that no critical task can \"fall through the cracks . \" | ❏ Buy-in from executives (CEO, CTO, COO)\u003Cbr>❏ Confirm technical owners\u003Cbr>❏ Confirm security officer ❏ Confirm business process owners ❏ Set expectations with scope and\u003Cbr>timelines for upcoming projects ❏ Determine which systems and processes are in scope ❏ Hold kickoff meeting with internal\u003Cbr>stakeholders to plan for the year ahead\u003Cbr>❏ Ensure adequate time/resources available for security and compliance |\n| Key Checks |  |\n| ❏ Visible structure and accountability from executive level ❏ Employee code of conduct\u003Cbr>❏ Job/role descriptions and performance review structure ❏ Onboarding / offboarding checklists\u003Cbr>❏ Job role and security training |  |\n\n| In Plain English | February Mastermind |\n| --- | --- |\n| Communications means that you have written policies and procedures that cover major areas of risk and that you have a confirmed, well-maintained process for communicating those policies and procedures to employees, vendors, and customers. | ❏ Gather/Review/Update existing change management and SDLC documentation\u003Cbr>❏ Gather existing technical system documentation and diagrams ❏ Gather existing HR forms and hiring\u003Cbr>procedures\u003Cbr>❏ Gather existing policies and procedures\u003Cbr>❏ Each stakeholder performs “quick and dirty” gap analysis\u003Cbr>❏ Review Information Security Policy\u003Cbr>❏ Assign Information Security Policy sections to stakeholders for edits |\n| Key Checks |  |\n| ❏ Network and Data Flow diagram\u003Cbr>❏ Updated Org Chart with security responsibilities ❏ Information Security Policy and Acknowledgement ❏ Documented client security responsibilities ❏ Documented security commitments ❏ Established lines of communication |  |\n\n| In Plain English | March Mastermind |\n| --- | --- |\n| Risk Management refers to the academic exercise of making sure you know all your organization's key technical and operational vulnerabilities, associated risks are well documented and addressed through controls, and reviewed on a regular basis. | ❏ Revise Information Security Policy ❏ Develop assessment process for\u003Cbr>onboarding new technology vendors ❏ Request and review SOC 2 reports\u003Cbr>for key service providers ❏ Develop system, data, and\u003Cbr>workstation asset inventory ❏ Conduct a formalized risk\u003Cbr>assessment\u003Cbr>❏ Develop risk mitigation plan and identify additional controls ❏ Establish a vulnerability scanning process for key systems ❏ Engage with a penetration testing\u003Cbr>firm |\n| Key Checks |  |\n| ❏ Create a risk management policy ❏ Create an asset list with relevant data ❏ Create and complete a risk register ❏ Conduct the risk assessment ❏ Update control documentation |  |\n\n| In Plain English | April Mastermind |\n| --- | --- |\n| Monitoring refers to the internal audits, reviews, and reports you regularly undertake to ensure that your internal controls are doing their jobs--especially when it comes to your information technology. | ❏ Develop checklists, process, and document storage routine for all processes surrounding new/ex hires\u003Cbr>❏ Confirm background checks for all new hires\u003Cbr>❏ Develop an employee handbook and code of conduct\u003Cbr>❏ Review an acceptable use policy\u003Cbr>❏ Review security awareness and job training material\u003Cbr>❏ Update an org chart that clearly\u003Cbr>shows security responsibilities ❏ Integrate security awareness training ❏ Ensure access is removed for all\u003Cbr>termed employees |\n| Key Checks |  |\n| ❏ Create (and perform) an internal audit process ❏ Review all key monitoring tools and configurations ❏ Perform External Penetration Testing\u003Cbr>❏ Report to board of directors and/or executive team ❏ Perform preventative and corrective actions as needed |  |","cbCainzz7Zxc5afu","https://ap.wps.com/l/cbCainzz7Zxc5afu","pdf",894658,22,"English","# January Mastermind\n## Key Checks\n# February Mastermind\n## Key Checks\n# March Mastermind\n## Key Checks\n# April Mastermind\n## Key Checks","[{\"question\":\"What does January Mastermind focus on for SOC 2 readiness?\",\"answer\":\"January centers on organization and management: establishing a leadership structure, confirming technical and security ownership, defining scope and timelines, and ensuring resources for security and compliance.\"},{\"question\":\"How does February Mastermind support SOC 2 communication requirements?\",\"answer\":\"February emphasizes written policies and procedures and a maintained communication process, including gathering and updating documentation, reviewing the information security policy, and assigning policy sections to stakeholders for edits.\"},{\"question\":\"What key activities are included in March Mastermind risk management?\",\"answer\":\"March requires revising the information security policy, creating an asset inventory and risk register, conducting a formal risk assessment, developing a risk mitigation plan with controls, and implementing vulnerability scanning and penetration testing.\"}]","January+2022 - SOC 2 Checklist - February to April Mastermind | PDF",1788408227,8]