Add SOC 2 operations checklist
This commit is contained in:
parent
77529d26a8
commit
25a1981909
@ -11,4 +11,9 @@ export class ComplianceController {
|
|||||||
async soc2Readiness(@CurrentUser() userId: string) {
|
async soc2Readiness(@CurrentUser() userId: string) {
|
||||||
return this.complianceService.getSoc2Readiness(userId);
|
return this.complianceService.getSoc2Readiness(userId);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
@Get("soc2/operations")
|
||||||
|
async soc2Operations() {
|
||||||
|
return this.complianceService.getSoc2Operations();
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@ -28,6 +28,21 @@ export interface Soc2ReadinessReport {
|
|||||||
note: string;
|
note: string;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
export interface Soc2OperationsReport {
|
||||||
|
framework: "SOC 2";
|
||||||
|
certificationStatus: "not_certified";
|
||||||
|
generatedAt: string;
|
||||||
|
externalOperations: Array<{
|
||||||
|
id: string;
|
||||||
|
area: string;
|
||||||
|
owner: string;
|
||||||
|
status: "external_required";
|
||||||
|
requiredEvidence: string[];
|
||||||
|
systemSupport: string[];
|
||||||
|
}>;
|
||||||
|
note: string;
|
||||||
|
}
|
||||||
|
|
||||||
@Injectable()
|
@Injectable()
|
||||||
export class ComplianceService {
|
export class ComplianceService {
|
||||||
constructor(private readonly prisma: PrismaService) {}
|
constructor(private readonly prisma: PrismaService) {}
|
||||||
@ -122,4 +137,76 @@ export class ComplianceService {
|
|||||||
note: "This endpoint reports application control evidence only. It does not represent SOC 2 certification or audit opinion.",
|
note: "This endpoint reports application control evidence only. It does not represent SOC 2 certification or audit opinion.",
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
|
|
||||||
|
getSoc2Operations(): Soc2OperationsReport {
|
||||||
|
return {
|
||||||
|
framework: "SOC 2",
|
||||||
|
certificationStatus: "not_certified",
|
||||||
|
generatedAt: new Date().toISOString(),
|
||||||
|
externalOperations: [
|
||||||
|
{
|
||||||
|
id: "SOC2-AUDITOR",
|
||||||
|
area: "Independent examination",
|
||||||
|
owner: "Executive sponsor / auditor",
|
||||||
|
status: "external_required",
|
||||||
|
requiredEvidence: [
|
||||||
|
"Signed engagement letter with a CPA firm",
|
||||||
|
"Defined Type I or Type II examination scope",
|
||||||
|
"Auditor request list and evidence retention plan",
|
||||||
|
],
|
||||||
|
systemSupport: ["GET /api/compliance/soc2/readiness exposes runtime control evidence."],
|
||||||
|
},
|
||||||
|
{
|
||||||
|
id: "SOC2-POLICIES",
|
||||||
|
area: "Security policies",
|
||||||
|
owner: "Security / management",
|
||||||
|
status: "external_required",
|
||||||
|
requiredEvidence: [
|
||||||
|
"Approved access control policy",
|
||||||
|
"Approved change management policy",
|
||||||
|
"Approved incident response policy",
|
||||||
|
"Approved vendor risk policy",
|
||||||
|
],
|
||||||
|
systemSupport: ["Audit logs, export logs, session records, and abuse events provide technical evidence."],
|
||||||
|
},
|
||||||
|
{
|
||||||
|
id: "SOC2-ACCESS-REVIEWS",
|
||||||
|
area: "Access reviews",
|
||||||
|
owner: "Operations",
|
||||||
|
status: "external_required",
|
||||||
|
requiredEvidence: [
|
||||||
|
"Quarterly access review checklist",
|
||||||
|
"Reviewer sign-off records",
|
||||||
|
"Remediation tickets for excessive access",
|
||||||
|
],
|
||||||
|
systemSupport: ["User/session/audit data can support review evidence, but approvals occur outside the runtime."],
|
||||||
|
},
|
||||||
|
{
|
||||||
|
id: "SOC2-VENDOR-RISK",
|
||||||
|
area: "Vendor risk",
|
||||||
|
owner: "Operations / legal",
|
||||||
|
status: "external_required",
|
||||||
|
requiredEvidence: [
|
||||||
|
"Subprocessor inventory",
|
||||||
|
"Vendor security reviews for infrastructure, email, payments, bank data, and tax providers",
|
||||||
|
"Executed DPAs where required",
|
||||||
|
],
|
||||||
|
systemSupport: ["Provider integration metadata identifies Stripe, Plaid, Teller, Google, SMTP, and export storage dependencies."],
|
||||||
|
},
|
||||||
|
{
|
||||||
|
id: "SOC2-TRAINING-DRILLS",
|
||||||
|
area: "Training and incident drills",
|
||||||
|
owner: "People / security",
|
||||||
|
status: "external_required",
|
||||||
|
requiredEvidence: [
|
||||||
|
"Employee security training records",
|
||||||
|
"Onboarding/offboarding records",
|
||||||
|
"Incident response tabletop or drill report",
|
||||||
|
],
|
||||||
|
systemSupport: ["Application audit records can support incident reconstruction after an event."],
|
||||||
|
},
|
||||||
|
],
|
||||||
|
note: "These operations cannot be completed by code alone. The application can expose evidence, but certification requires external policies, retained records, and an auditor.",
|
||||||
|
};
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
Loading…
x
Reference in New Issue
Block a user