By the end
What you'll build
- Explain in plain terms what a SOC 2 report is, who is entitled to issue one, and what it does and does not say about the organisation
- Trace how your own routine actions — approvals, tickets, access requests, file shares — become the evidence an examiner samples
- Apply the company's baseline security expectations to daily tasks such as device use, software installation and remote working
- Justify an access request against least privilege, and give up access you no longer need
- Recognise when an everyday situation has become a control failure and route it to the right internal channel without delay
Curriculum
What's inside
7 modules · 41 lessons
- 01
What SOC 2 Actually Is
6 lessons- Attestation, Not Certification: What a SOC 2 Report Says and Does Not Say
- Who Reads a SOC 2 Report and Why They Ask For It
- Type 1 and Type 2: A Point in Time Versus a Period
- The Trust Services Criteria Categories in Plain English
- Scope, System Boundaries and the System Description
- + 1 more lesson
- 02
Controls, Evidence and the Audit Trail
6 lessons- How Your Ordinary Work Becomes Audit Evidence
- Control Owners, Operators and Reviewers: Who Does What
- Sampling: Why One Missed Approval Can Fail a Control
- Timestamps and Tickets: Why "We Always Do It" Is Not Evidence
- Exceptions, Deviations and What a Qualified Opinion Means
- + 1 more lesson
- 03
Your Baseline Security Responsibilities
6 lessons- The Habits Every Person in Scope Is Expected to Keep
- Devices, Screens and the Physical Workspace
- Software You Install and Services You Sign Up For
- Working Away From the Office and on Untrusted Networks
- Joining, Changing Role and Leaving: Your Part in the Handover
- + 1 more lesson
- 04
Access and Least Privilege in Daily Work
6 lessons- Requesting, Justifying and Giving Up Access
- Least Privilege Explained Through Real Requests
- Shared Accounts and Why They Break Accountability
- Access Reviews: What You Are Actually Being Asked to Confirm
- Contractors, Guests and Time-Limited Access
- + 1 more lesson
- 05
Vendors, Change and the Wider System
6 lessons- Before You Send Company Data to an Outside Service
- Why Third Parties Sit Inside Our Control Environment
- Change Management: Why Approval Comes Before Deployment
- Unapproved Tools, Browser Add-Ons and Personal Automation
- Reading a Supplier's Own Assurance Report
- + 1 more lesson
- 06
When Something Goes Wrong
6 lessons- Spotting a Control Failure and Raising It Without Blame
- Event, Incident and Breach: Three Different Consequences
- Who to Tell, How Quickly, and What to Write Down
- Preserving Evidence Instead of Tidying Up
- What Happens After You Report
- + 1 more lesson
- 07
Practice and check
5 lessons- Four words people use interchangeably, and two morematch pairs
- You still have access you should not havesequence order
- Getting the security words rightfill blank
- The colleague, the deadline and the personal drivescenario
- Course quizquiz
The shape of it
How this course works
Short lessons
41 lessons across 7 modules, each small enough to finish in one sitting.
Practice as you go
Every lesson ends with a small space for what you noticed — the doing is the learning.
Progress you can see
Your progress is saved lesson by lesson, ready whenever you come back.
Ready when you are.
Make an account and this course opens up — your progress is saved from the very first lesson.
