diff --git a/src/compliance/compliance.controller.ts b/src/compliance/compliance.controller.ts index 10b933a..f20699f 100644 --- a/src/compliance/compliance.controller.ts +++ b/src/compliance/compliance.controller.ts @@ -11,4 +11,9 @@ export class ComplianceController { async soc2Readiness(@CurrentUser() userId: string) { return this.complianceService.getSoc2Readiness(userId); } + + @Get("soc2/operations") + async soc2Operations() { + return this.complianceService.getSoc2Operations(); + } } diff --git a/src/compliance/compliance.service.ts b/src/compliance/compliance.service.ts index 448ac52..77f674e 100644 --- a/src/compliance/compliance.service.ts +++ b/src/compliance/compliance.service.ts @@ -28,6 +28,21 @@ export interface Soc2ReadinessReport { note: string; } +export interface Soc2OperationsReport { + framework: "SOC 2"; + certificationStatus: "not_certified"; + generatedAt: string; + externalOperations: Array<{ + id: string; + area: string; + owner: string; + status: "external_required"; + requiredEvidence: string[]; + systemSupport: string[]; + }>; + note: string; +} + @Injectable() export class ComplianceService { constructor(private readonly prisma: PrismaService) {} @@ -122,4 +137,76 @@ export class ComplianceService { note: "This endpoint reports application control evidence only. It does not represent SOC 2 certification or audit opinion.", }; } + + getSoc2Operations(): Soc2OperationsReport { + return { + framework: "SOC 2", + certificationStatus: "not_certified", + generatedAt: new Date().toISOString(), + externalOperations: [ + { + id: "SOC2-AUDITOR", + area: "Independent examination", + owner: "Executive sponsor / auditor", + status: "external_required", + requiredEvidence: [ + "Signed engagement letter with a CPA firm", + "Defined Type I or Type II examination scope", + "Auditor request list and evidence retention plan", + ], + systemSupport: ["GET /api/compliance/soc2/readiness exposes runtime control evidence."], + }, + { + id: "SOC2-POLICIES", + area: "Security policies", + owner: "Security / management", + status: "external_required", + requiredEvidence: [ + "Approved access control policy", + "Approved change management policy", + "Approved incident response policy", + "Approved vendor risk policy", + ], + systemSupport: ["Audit logs, export logs, session records, and abuse events provide technical evidence."], + }, + { + id: "SOC2-ACCESS-REVIEWS", + area: "Access reviews", + owner: "Operations", + status: "external_required", + requiredEvidence: [ + "Quarterly access review checklist", + "Reviewer sign-off records", + "Remediation tickets for excessive access", + ], + systemSupport: ["User/session/audit data can support review evidence, but approvals occur outside the runtime."], + }, + { + id: "SOC2-VENDOR-RISK", + area: "Vendor risk", + owner: "Operations / legal", + status: "external_required", + requiredEvidence: [ + "Subprocessor inventory", + "Vendor security reviews for infrastructure, email, payments, bank data, and tax providers", + "Executed DPAs where required", + ], + systemSupport: ["Provider integration metadata identifies Stripe, Plaid, Teller, Google, SMTP, and export storage dependencies."], + }, + { + id: "SOC2-TRAINING-DRILLS", + area: "Training and incident drills", + owner: "People / security", + status: "external_required", + requiredEvidence: [ + "Employee security training records", + "Onboarding/offboarding records", + "Incident response tabletop or drill report", + ], + systemSupport: ["Application audit records can support incident reconstruction after an event."], + }, + ], + note: "These operations cannot be completed by code alone. The application can expose evidence, but certification requires external policies, retained records, and an auditor.", + }; + } }