<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>SOC 2 Certification Archives - Zasio</title>
	<atom:link href="https://zasio.com/tag/soc-2-certification/feed/" rel="self" type="application/rss+xml" />
	<link>https://zasio.com/tag/soc-2-certification/</link>
	<description>Digital Records Management Software</description>
	<lastBuildDate>Fri, 05 Apr 2024 21:53:05 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0</generator>

<image>
	<url>https://zasio.com/wp-content/uploads/2023/05/cropped-zasiopurplefavicon-32x32.png</url>
	<title>SOC 2 Certification Archives - Zasio</title>
	<link>https://zasio.com/tag/soc-2-certification/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Standby, RIM/IG Professionals: SOC 2 Applies to You, Too!</title>
		<link>https://zasio.com/soc-2-certification-rim-information-governance-zasio/</link>
					<comments>https://zasio.com/soc-2-certification-rim-information-governance-zasio/#respond</comments>
		
		<dc:creator><![CDATA[Zasio]]></dc:creator>
		<pubDate>Wed, 22 Feb 2023 20:28:55 +0000</pubDate>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[IG]]></category>
		<category><![CDATA[information governance]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[records management]]></category>
		<category><![CDATA[RIM]]></category>
		<category><![CDATA[SOC 2 Certification]]></category>
		<category><![CDATA[Zasio]]></category>
		<guid isPermaLink="false">https://wordpress-140425-3498808.cloudwaysapps.com/?p=345</guid>

					<description><![CDATA[<p>Records management and information governance professionals are all too aware data breaches are on the rise. Clients know, too—and they are looking for organizations that fight back. Obtaining SOC 2 certification is one way to show your organization takes data security seriously. RIM and IG professionals play a central role in data security, and RIM/IG’s cross-organizational nature is the ideal launch pad for your organization’s information security and protection initiatives, including SOC 2 certification. What is SOC 2 Certification? SOC 2 is a voluntary certification offered by the Association of International Certified Professional Accountants and provides standards centered on the five pillars of the trust services criteria (“TSC”)[1]: Security Availability Processing Integrity Confidentiality Privacy The standards aren’t rigid rules; rather, they comprise a data security program framework. Organizations seeking SOC 2 certification often implement internal controls customized to their business processes in relation to the TSC. Ultimately, organizations seeking certification must be able to pass an audit conducted by an AICPA-affiliated certified accountant. The audit process includes showing evidence the organization’s program satisfies the TSC. RIM/IG Meets Data Security Compliance It’s no secret data security and RIM/IG programs go together like peanut butter and jelly. A sound RIM/IG program aims [&#8230;]</p>
<p>The post <a href="https://zasio.com/soc-2-certification-rim-information-governance-zasio/" data-wpel-link="internal">Standby, RIM/IG Professionals: SOC 2 Applies to You, Too!</a> appeared first on <a href="https://zasio.com" data-wpel-link="internal">Zasio</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Records management and information governance professionals are all too aware data breaches are on the rise. Clients know, too—and they are looking for organizations that fight back. Obtaining SOC 2 certification is one way to show your organization takes data security seriously. RIM and IG professionals play a central role in data security, and RIM/IG’s cross-organizational nature is the ideal launch pad for your organization’s information security and protection initiatives, including SOC 2 certification.</p>
<p><strong>What is SOC 2 Certification?</strong></p>
<p>SOC 2 is a voluntary certification offered by the Association of International Certified Professional Accountants and provides standards centered on the five pillars of the trust services criteria (“TSC”)<a href="https://www.zasio.com/soc-2-certification-rim-information-governance-zasio/#_ftn1" name="_ftnref1" data-wpel-link="internal">[1]</a>:</p>
<ol>
<li>Security</li>
<li>Availability</li>
<li>Processing Integrity</li>
<li>Confidentiality</li>
<li>Privacy</li>
</ol>
<p>The standards aren’t rigid rules; rather, they comprise a data security program framework. Organizations seeking SOC 2 certification often implement internal controls customized to their business processes in relation to the TSC. Ultimately, organizations seeking certification must be able to pass an audit conducted by an AICPA-affiliated certified accountant. The audit process includes showing evidence the organization’s program satisfies the TSC.</p>
<p><strong>RIM/IG Meets Data Security Compliance</strong></p>
<p>It’s no secret data security and RIM/IG programs go together like peanut butter and jelly. A sound RIM/IG program aims to protect data, information, and records, ensuring their accessibility, availability, and integrity. It also ensures data, information, and records are defensibly disposed of when no longer needed. An organization can significantly mitigate its risks when it is managing only the information it needs.</p>
<p><strong><em>Vendor Management</em></strong></p>
<p>A primary consideration for RIM/IG professionals evaluating vendors is whether data will be protected. This importance is heightened when personal or proprietary data is involved. Vendor vetting considers a list of factors, which typically center around the TSC. Vendors with SOC 2 immediately check boxes, and they often receive priority consideration. Certification immediately demonstrates the vendor’s commitment to the protection of your organization’s data.</p>
<p><strong><em>SOC 2 Within Your Organization</em></strong></p>
<p>If your organization manages customer data, it may already have considered or achieved a SOC 2 certification. The TSC likely bring about warm fuzzies for RIM/IG professionals—they can bring to mind the beloved and familiar GARP principles including the principles of “Integrity” and “Availability.”<a href="https://www.zasio.com/soc-2-certification-rim-information-governance-zasio/#_ftn2" name="_ftnref2" data-wpel-link="internal">[2]</a> Other GARP principles also align with TSC, including “Protection”, which provides that protection should be provided to “assets that are private, confidential, privileged.”<a href="https://www.zasio.com/soc-2-certification-rim-information-governance-zasio/#_ftn3" name="_ftnref3" data-wpel-link="internal">[3]</a></p>
<p><u>Confidentiality &amp; Privacy Criteria</u></p>
<p>Under the TSC, “Confidentiality” is defined to include information that is “protected to meet the entity’s objectives”; if your organization deals with confidential customer data, this is a key standard. “Privacy” as a standard involves personal information that “is collected, used to meet the entity’s objectives.” The privacy sub-criteria elaborates that the “entity limits the use, retention, and disposal of personal information to support the achievement of its objectives related to privacy.” These elements can be easily included in a RIM/IG program.</p>
<p><strong><em>Under the IG/RIM Umbrella</em></strong></p>
<p>Whether your organization is preparing for SOC 2 certification or another data security-related certification, or simply wants to ensure the TSC principles are accounted for, your team members can leverage several RIM/IG program components to demonstrate it has the necessary processes, policies, and procedures in place.</p>
<p><u>Records/Data Inventory</u></p>
<p>This isn’t a new refrain, but it often bears repeating: You can’t protect information if you don’t know what you have. Organizations are always wise to keep a handle on their records and information by starting and maintaining a comprehensive data inventory. This is often accomplished through an information collection process. Important details should be gathered including location, format, data owner, and privacy or confidentiality classifications. A robust and regularly updated inventory helps organizations manage their information in a number of ways, even beyond protection: It can help support regular defensible disposition, accessibility for litigation and business needs, and greater privacy initiatives.</p>
<p><u>RIM/IG Policies</u></p>
<p>A well-drafted records and information management policy, along with corresponding procedures, tends to parallel many of the TSC principles; in particular, they reflect the principles touching on access, retention, and disposal. They can also impact business processes relating to data storage, processing, transfer, and archiving, as well as eDiscovery.</p>
<p>Relatedly, an organization’s record retention schedule policy can help demonstrate the organization has controls in place around limited retention and disposal of records. The TSC expressly mentions data retention and disposal, so this is a key effort—and another area in which RIM/IG professionals can significantly contribute.</p>
<p><u>Governance</u></p>
<p>TSC, and the certification process, can even impact and help shape the work of an IG steering committee. The committee is typically composed of stakeholder professionals and experts from the organization, and, according to the Information Governance Body of Knowledge (IBOK),  includes members from privacy and security. Although the TSCs don’t explicitly require governance, they do highlight governance as a good way to demonstrate controls.</p>
<p><strong>Conclusion</strong></p>
<p>Pearl Zhu, in her book <em>12 CIO Personas</em>, said the purpose of “Information Management is to make sure the right information is shared with the right persons at the right time in the right place.” With that single sentence, Zhu highlighted the multidisciplinary nature of records and information management. She also perfectly connected RIM/IG to information security. Risks surrounding data breaches cannot be understated, and breaches cost organizations more each year. Therefore, it is increasingly important RIM/IG professionals are attuned to data security.</p>
<p>There are many parallels between the TSC framework and RIM/IG objectives, resulting in many opportunities to integrate TSC principles into policies. Evidence of successful implementation into, and enforcement of, relevant internal controls will never be a bad thing.</p>
<p>Ultimately, every organization can benefit from the TSC framework and regardless of whether an organization seeks formal certification, the development of formal TSC framework controls and procedures customized to the organization’s processes goes a long way in protecting your organization’s data while also providing guarantees to prospective business partners. And when evaluating vendors, don’t underestimate the guarantees provided by that official SOC 2 seal.</p>
<p><em> </em><em>Zasio prioritizes the protection of its customer data and is proud to display our SOC 2 certification badge. Ask us how we can help build data security into your RIM/IG program.</em></p>
<p><a href="https://www.zasio.com/soc-2-certification-rim-information-governance-zasio/#_ftnref1" name="_ftn1" data-wpel-link="internal">[1]</a> 2017 Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy, AICPA (2022), https://www.aicpa.org/resources/download/2017-trust-services-criteria-with-revised-points-of-focus-2022.</p>
<p><a href="https://www.zasio.com/soc-2-certification-rim-information-governance-zasio/#_ftnref2" name="_ftn2" data-wpel-link="internal">[2]</a> The Principles®, ARMA (2017), https://www.arma.org/page/principles.</p>
<p><a href="https://www.zasio.com/soc-2-certification-rim-information-governance-zasio/#_ftnref3" name="_ftn3" data-wpel-link="internal">[3]</a> Id.</p>
<p><em>Disclaimer: The purpose of this post is to provide general education on Information Governance topics. The statements are informational only and do not constitute legal advice. If you have specific questions regarding the application of the law to your business activities, you should seek the advice of your legal counsel.</em></p>
<p><a class="a2a_button_facebook" href="https://www.addtoany.com/add_to/facebook?linkurl=https%3A%2F%2Fzasio.com%2Fsoc-2-certification-rim-information-governance-zasio%2F&amp;linkname=Standby%2C%20RIM%2FIG%20Professionals%3A%20SOC%202%20Applies%20to%20You%2C%20Too%21" title="Facebook" rel="nofollow noopener external noreferrer" target="_blank" data-wpel-link="external"></a><a class="a2a_button_x" href="https://www.addtoany.com/add_to/x?linkurl=https%3A%2F%2Fzasio.com%2Fsoc-2-certification-rim-information-governance-zasio%2F&amp;linkname=Standby%2C%20RIM%2FIG%20Professionals%3A%20SOC%202%20Applies%20to%20You%2C%20Too%21" title="X" rel="nofollow noopener external noreferrer" target="_blank" data-wpel-link="external"></a><a class="a2a_button_linkedin" href="https://www.addtoany.com/add_to/linkedin?linkurl=https%3A%2F%2Fzasio.com%2Fsoc-2-certification-rim-information-governance-zasio%2F&amp;linkname=Standby%2C%20RIM%2FIG%20Professionals%3A%20SOC%202%20Applies%20to%20You%2C%20Too%21" title="LinkedIn" rel="nofollow noopener external noreferrer" target="_blank" data-wpel-link="external"></a><a class="a2a_dd addtoany_share_save addtoany_share" href="https://www.addtoany.com/share#url=https%3A%2F%2Fzasio.com%2Fsoc-2-certification-rim-information-governance-zasio%2F&#038;title=Standby%2C%20RIM%2FIG%20Professionals%3A%20SOC%202%20Applies%20to%20You%2C%20Too%21" data-a2a-url="https://zasio.com/soc-2-certification-rim-information-governance-zasio/" data-a2a-title="Standby, RIM/IG Professionals: SOC 2 Applies to You, Too!" data-wpel-link="external" rel="external noopener noreferrer"></a></p><p>The post <a href="https://zasio.com/soc-2-certification-rim-information-governance-zasio/" data-wpel-link="internal">Standby, RIM/IG Professionals: SOC 2 Applies to You, Too!</a> appeared first on <a href="https://zasio.com" data-wpel-link="internal">Zasio</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://zasio.com/soc-2-certification-rim-information-governance-zasio/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Zasio Successfully Achieves SOC 2, Type 2 Certification</title>
		<link>https://zasio.com/soc-2-certification/</link>
					<comments>https://zasio.com/soc-2-certification/#respond</comments>
		
		<dc:creator><![CDATA[Zasio]]></dc:creator>
		<pubDate>Fri, 18 Mar 2022 19:47:05 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Enterprise document management]]></category>
		<category><![CDATA[information governance]]></category>
		<category><![CDATA[Information Governance software]]></category>
		<category><![CDATA[records management software]]></category>
		<category><![CDATA[records retention software]]></category>
		<category><![CDATA[SOC 2 Certification]]></category>
		<category><![CDATA[Versatile Software as a Service System]]></category>
		<guid isPermaLink="false">https://wordpress-140425-3498808.cloudwaysapps.com/?p=459</guid>

					<description><![CDATA[<p>BOISE, IDAHO — Zasio Enterprises, Inc., a global leader in business-to-business information governance and records management solutions, is pleased to announce that it has successfully completed the Service Organization Control (SOC) 2 Type 2 audit with respect to Zasio’s Versatile Software as a Service System. Zasio utilizes the Versatile System to provide its suite of records and information management SaaS solutions to customers. With an unqualified opinion for Versatile controls relative to security, Zasio’s SOC 2, Type 2 attestation report demonstrates the company’s commitment to security in delivering its SaaS solutions to customers around the globe. To comply with SOC2, Zasio had to demonstrate that it had established rigorous policies and procedures in accordance with the Trusted Services Criteria of security. “Zasio has made information governance security a top priority throughout our organization,” said Kevin Zasio, the company’s founder and president. “Achieving SOC 2 certification is another step in that goal.” The official audit report provides a thorough review of Zasio’s internal controls, policies, and processes for security. It also reviews Zasio’s processes relating to risk management and vendor due diligence, as well as Zasio’s entire IT infrastructure, software development lifecycle, change management, logical security, network security, physical and environmental [&#8230;]</p>
<p>The post <a href="https://zasio.com/soc-2-certification/" data-wpel-link="internal">Zasio Successfully Achieves SOC 2, Type 2 Certification</a> appeared first on <a href="https://zasio.com" data-wpel-link="internal">Zasio</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>BOISE, IDAHO — Zasio Enterprises, Inc., a global leader in business-to-business information governance and records management solutions, is pleased to announce that it has successfully completed the Service Organization Control (SOC) 2 Type 2 audit with respect to Zasio’s Versatile Software as a Service System.</p>
<p>Zasio utilizes the Versatile System to provide its suite of records and information management SaaS solutions to customers. With an unqualified opinion for Versatile controls relative to security, Zasio’s SOC 2, Type 2 attestation report demonstrates the company’s commitment to security in delivering its SaaS solutions to customers around the globe.</p>
<p>To comply with SOC2, Zasio had to demonstrate that it had established rigorous policies and procedures in accordance with the Trusted Services Criteria of security.</p>
<p>“Zasio has made information governance security a top priority throughout our organization,” said Kevin Zasio, the company’s founder and president. “Achieving SOC 2 certification is another step in that goal.”</p>
<p>The official audit report provides a thorough review of Zasio’s internal controls, policies, and processes for security. It also reviews Zasio’s processes relating to risk management and vendor due diligence, as well as Zasio’s entire IT infrastructure, software development lifecycle, change management, logical security, network security, physical and environmental security, and computer operations.</p>
<p>The audit examination was conducted in accordance with attestation standards established by the American Institute of Certified Public Accountants. System Organization Control (SOC2) is a technical auditing process performed by an independent auditor who measures the security of an organization’s unique data processing systems, and determines whether effective safeguards and controls are in place</p>
<p>The audit was conducted by Dansa D’Arata Soucia LLP (“DDS”), a full service CPA firm based out of Buffalo, New York. Over the past decade, DDS has built a team of auditors dedicated to understanding the AICPA’s Trust Service Criteria and how properly applying best practices to comply with this set of criteria results in risk mitigation when it comes to protecting sensitive data.</p>
<p><strong># # #</strong></p>
<p>Founded in 1987, Zasio has more than three decades of experience being at the forefront of records management and information governance. Zasio prides itself in its ability to foster a culture of innovation mixed with long-term thinking, which translates in to offering leading-edge records and information management solutions along with unparalleled support to its customers.</p>
<p>Stay up-to-date on Zasio by following us on <a href="https://www.linkedin.com/company/zasio-enterprises-inc-/mycompany/" data-wpel-link="external" rel="external noopener noreferrer"><strong>linkedIn</strong></a> and by subscribing to our <a href="https://www.zasio.com/news/page/17/" data-wpel-link="internal"><strong>monthly newsletter</strong></a>.</p>
<p><a class="a2a_button_facebook" href="https://www.addtoany.com/add_to/facebook?linkurl=https%3A%2F%2Fzasio.com%2Fsoc-2-certification%2F&amp;linkname=Zasio%20Successfully%20Achieves%20SOC%202%2C%20Type%202%20Certification" title="Facebook" rel="nofollow noopener external noreferrer" target="_blank" data-wpel-link="external"></a><a class="a2a_button_x" href="https://www.addtoany.com/add_to/x?linkurl=https%3A%2F%2Fzasio.com%2Fsoc-2-certification%2F&amp;linkname=Zasio%20Successfully%20Achieves%20SOC%202%2C%20Type%202%20Certification" title="X" rel="nofollow noopener external noreferrer" target="_blank" data-wpel-link="external"></a><a class="a2a_button_linkedin" href="https://www.addtoany.com/add_to/linkedin?linkurl=https%3A%2F%2Fzasio.com%2Fsoc-2-certification%2F&amp;linkname=Zasio%20Successfully%20Achieves%20SOC%202%2C%20Type%202%20Certification" title="LinkedIn" rel="nofollow noopener external noreferrer" target="_blank" data-wpel-link="external"></a><a class="a2a_dd addtoany_share_save addtoany_share" href="https://www.addtoany.com/share#url=https%3A%2F%2Fzasio.com%2Fsoc-2-certification%2F&#038;title=Zasio%20Successfully%20Achieves%20SOC%202%2C%20Type%202%20Certification" data-a2a-url="https://zasio.com/soc-2-certification/" data-a2a-title="Zasio Successfully Achieves SOC 2, Type 2 Certification" data-wpel-link="external" rel="external noopener noreferrer"></a></p><p>The post <a href="https://zasio.com/soc-2-certification/" data-wpel-link="internal">Zasio Successfully Achieves SOC 2, Type 2 Certification</a> appeared first on <a href="https://zasio.com" data-wpel-link="internal">Zasio</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://zasio.com/soc-2-certification/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
