SSAE18, SOC 1, SOC 2 - What Do I Need?

SSAE18, SOC 1, SOC 2 - What Do I Need?

SSAE18, SOC 1, SOC 2 - What Do I Need?
Wednesday, August 21, 2019
2:30 pm – 4:30 pm Eastern



Each of our regulators say this in a similar way, we must understand the security controls of a third party “to the same extent” as we understand our own internal controls. This is challenging, as some of our vendors share few details about controls. Our industry currently relies heavily on the new SSAE18 Audit Report and the Service Organization Control (SOC)2 reports provided by vendors. What are the differences between these two reports, and which should we be requesting? And once we obtain them, how do we understand the security controls to the “same extent” as our own?

We will explore the different types of SOC reports provided by vendors and highlight the best items that should be requested from vendors. Each of these reports serves a different purpose and will provide different value to your institution. In addition to what reports to ask for, we will explore them in detail to highlight what to look for and how to fill in the gaps to ensure your understanding security to the “same extent”.

Topics Covered:

  • Third Party Management best practices
  • Fourth Party Management assistance
  • Updated Regulatory Expectations
  • Existing Regulatory Review
  • SSAE16 vs SSAE18 standard changes
  • SOC1, SOC2, SOC3 Audits
  • SOC Reports Type 1 and Type 2
  • Other items useful in vendor reviews
  • Detailed due diligence and contract questions

Who Should Attend?   

Information Security Officer, IT Manager, Risk Officer, Internal Auditor, CFO, and Executives looking to understand the risk around Vendor Management.

Speaker:

Jon Waldman

Jon Waldman is a co-founder and Senior Information Security Consultant for SBS CyberSecurity, LLC, a premier cybersecurity consulting and audit firm dedicated to making a positive impact on the banking and financial services industry. He maintains his CISA and CRISC certifications and received his Bachelor of Science in Computer Information Systems and his Master of Science in Information Assurance with an emphasis in Banking and Finance Security from Dakota State University.

Over the last ten years Jon has helped hundreds of financial institutions across the country create and implement comprehensive, valuable, and manageable Information Security Programs. He also conducts webinars and certification programs for the SBS Institute.

Attendance verification for CE credits provided upon request.

Webinar Sponsored by Total Training Solutions

If you are having issues with registering online, please contact CBAO's Education & Training Coordinator, Lianne Simeone, (614) 610-1877.

Registration Options

Live Plus Five – Attend the live event and receive five business days of unlimited access to the OnDemand Playback and links to presenter materials and supplementary handouts.

OnDemand Recording – Receive unlimited access to the OnDemand Playback for 6 months and links to presenter materials and supplementary handouts. This option does not include live session attendance.

CD-ROM – Receive the webinar recording on a CD-ROM 7-10 business days after the Live event or your registration date (whichever is the latter). Receive unlimited access to the OnDemand Playback for 6 months and links to presenter materials and supplementary handouts. This option does not include live session attendance.

Live Plus Six – Attend the live event and receive six months of unlimited access to the OnDemand Playback and links to presenter materials and supplementary handouts.

Premier Package – Includes all three base options. Live attendance, OnDemand Playback for six months, and the CD-ROM.


When
8/21/2019
Registration is closed.