Before you log in
- Decide the scope: which product and systems the report will cover, and which criteria. Most first reports cover Security only.
- Name one owner for the project and identify the administrator of each system you will connect.
- Decide whether you are working toward a Type 1, a Type 2 or both. See Type 1 vs Type 2.
Connect your systems
Integrations are how Vanta collects evidence. Connect them in roughly this order:
- Identity provider, such as Google Workspace or Microsoft 365, so Vanta knows who your people are.
- HR system, so it knows who was hired and who left, and when.
- Cloud hosting, where your product runs.
- Code repository, to check how changes are reviewed.
- Task tracker, to link changes and security issues to tickets.
- Device management, or the Vanta agent on every company laptop.
Each connection needs an administrator of that system to approve it with the right level of access.
Sort out your people list
Once the identity provider and HR system are connected, review the list of accounts. Mark which are employees, which are contractors, and which are shared or service accounts that are not people. Left untidy, this produces failing tests that are not real problems.
Set up policies
Start from the templates, then edit each policy to describe what your company actually does. Have leadership approve them and assign them to employees for acceptance. See which SOC 2 policies you need.
Assign employee tasks
Every person needs to accept the policies, complete security awareness training and have a compliant laptop. Background checks apply if your policy requires them. Set a deadline and follow up individually. This is usually the slowest part.
Work through the failing tests
Vanta will now show which automated tests fail. Group them by the system they relate to, assign each group to the person who administers that system, and review progress weekly until the list is clear.
Add what can't be automated
- Your vendor list, with the security reports of the important ones.
- A risk assessment.
- An access review of key systems. See how to run one.
- An incident response exercise.
- Any documents your auditor asks for that Vanta can't collect.
Bring in the auditor
When the tests are passing and documents are in place, give your audit firm access to review. If you haven't chosen one, read what to prepare before engaging a SOC 2 auditor.
Then keep it green
Setup is the start. Through the audit period, someone has to check Vanta every week and deal with whatever has drifted. See what you have to prove during the audit period.
We set up Vanta, clear the failing tests with your team and manage the audit through to the report. See SOC 2 readiness and audit management.
