<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SOC-2 Subservice Organization - CSP? in Tech Talk</title>
    <link>https://community.isc2.org/t5/Tech-Talk/SOC-2-Subservice-Organization-CSP/m-p/32930#M2367</link>
    <description>&lt;P&gt;So, as I am preparing a service description for a SOC-2 audit (the first).&amp;nbsp; I have a question.&amp;nbsp; Is a cloud service provider considered a subservice organization?&amp;nbsp; I have seen a few things that indicate it is, while I personally feel it is a vendor, like Dell or IBM for servers, Microsoft or Red Hat for an operating system, etc.&amp;nbsp; Any guidance from experience?&lt;/P&gt;</description>
    <pubDate>Thu, 20 Feb 2020 17:55:45 GMT</pubDate>
    <dc:creator>mgorman</dc:creator>
    <dc:date>2020-02-20T17:55:45Z</dc:date>
    <item>
      <title>SOC-2 Subservice Organization - CSP?</title>
      <link>https://community.isc2.org/t5/Tech-Talk/SOC-2-Subservice-Organization-CSP/m-p/32930#M2367</link>
      <description>&lt;P&gt;So, as I am preparing a service description for a SOC-2 audit (the first).&amp;nbsp; I have a question.&amp;nbsp; Is a cloud service provider considered a subservice organization?&amp;nbsp; I have seen a few things that indicate it is, while I personally feel it is a vendor, like Dell or IBM for servers, Microsoft or Red Hat for an operating system, etc.&amp;nbsp; Any guidance from experience?&lt;/P&gt;</description>
      <pubDate>Thu, 20 Feb 2020 17:55:45 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/SOC-2-Subservice-Organization-CSP/m-p/32930#M2367</guid>
      <dc:creator>mgorman</dc:creator>
      <dc:date>2020-02-20T17:55:45Z</dc:date>
    </item>
    <item>
      <title>Re: SOC-2 Subservice Organization - CSP?</title>
      <link>https://community.isc2.org/t5/Tech-Talk/SOC-2-Subservice-Organization-CSP/m-p/32934#M2368</link>
      <description>Good question. There is no silver bullet answer to this and there is judgment and different interpretations of the standards. I will provide you my stance as an auditor that performs SOC 2 audits.&lt;BR /&gt;&lt;BR /&gt;The key to determining if a CSP is a SOC 2 subservice provider, is if you are relying on the vendor to perform a control and without the control, you would not be meeting a specific SOC 2 requirement. For instance, if you are using a CSP such as AWS and Azure to host the services you provide to customers, they would be a subservice provider, since you cannot meet the requirement for physical security without relying on AWS and Azure. However, if you are using a CSP for tracking changes and software development, this vendor would not be a subservice provider since you are not relying on them for specific controls.&lt;BR /&gt;&lt;BR /&gt;Keep in mind, regardless of whether or not you determine if the vendor is a subservice provider, you are still responsible for monitoring key vendors. In this instance, you should have a vendor management program where key vendors are monitored on a regular basis, subservice orgs and non-subservice orgs.</description>
      <pubDate>Thu, 20 Feb 2020 18:32:30 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/SOC-2-Subservice-Organization-CSP/m-p/32934#M2368</guid>
      <dc:creator>Troy_Fine</dc:creator>
      <dc:date>2020-02-20T18:32:30Z</dc:date>
    </item>
  </channel>
</rss>

