Why policies matter
SOC 2 does not hand you a rulebook. You state how your company handles security, and the auditor checks that you do what you stated. A policy that promises more than you do creates a finding. A policy that describes reality passes.
The policies most audits expect
- Information security: the overall program and who is responsible.
- Access control: how access is granted, reviewed and removed.
- Acceptable use: what employees may do with company systems and data.
- Change management: how changes to your product are reviewed and released.
- Incident response: what happens when something goes wrong.
- Business continuity and disaster recovery: how you keep operating and restore data.
- Risk management: how risks are identified and reviewed.
- Vendor management: how vendors are assessed and monitored.
- Data classification and retention: what data you hold, how it is labeled and how long it is kept.
- HR security: onboarding, training, conduct and offboarding.
- Asset management: how devices and systems are tracked.
- Vulnerability management: how weaknesses are found and fixed, and how quickly.
Your auditor and your scope determine the exact list.
How to make them match reality
- Start from templates, then read every sentence and ask whether it is true today.
- Replace specific promises you can't keep. If the template says access is removed within one day and you take three, change the policy or the practice.
- Name roles, not people, as owners.
- Keep them short enough that employees will read them.
Approval and acceptance
Each policy needs an approver, an approval date and a review at least once a year. Every employee needs to accept the relevant policies, and new hires need to do so as part of onboarding. Both leave records the auditor will ask to see.
Policies are not procedures
A policy says what must happen. A procedure says how it is done here, step by step. You need both. See how to write an SOP.
We write and roll out the policies, then make sure practice matches them. See SOC 2 readiness and audit management.
