System Description Basics

Learn about the intended audience of this document and what should be included

Written By Micah

Where can I find the System Description Template?

The System Description template can be found in our article here, along with template-specific guidance.

A video demonstration of how to utilize the System Description template can be found here.

What is a System Description?

The System Description is a required component of the SOC 2 report. It is management's narrative of the product or service in scope and the security practices in place to secure it. Many auditors will refer to it as "Section 3", as it comprises the third part of your organization’s SOC 2 report. The SOC 2 report itself is considered a 'limited distribution' document; it is best practice to obtain an NDA from outside parties before sharing it with them.

Who is the audience for the System Description?

Prior to and during the audit, your auditors will read your System Description to gain an understanding of your service and security practices. Near the end of your audit, they will ask for a final version and integrate it into the final SOC 2 report package they deliver to you.

Your direct customers (whoever purchases the product/system you describe) may require that you furnish them with your current SOC 2 report. They will read the System description section to gain an understanding of your security practices.

Generally, when you provide your SOC 2 report to a current customer or prospect, the part of the report that that customer/prospect actually reads is the System Description. Therefore, it is important that the content of the narrative is polished and accurate, as it will eventually be customer facing.

What is included in the System Description?

Anything written within the System Description is fair game to be audited, so no need to use flowery language and embellishments. The vast majority of the content of your System Description restates the design of your organization’s controls, so the information included may seem somewhat redundant.

The primary sections of the System Description include:

  • Company Overview and Overview of the Services Provided

    • This includes a brief company history and a high-level description of the services provided

    • This section is typically completed by an individual or team with deep knowledge of the service. Marketing is sometimes involved.

  • The Components of the System Used to Provide the Services

    • What is described in this section comprises the 'System'.

    • This is also referred to as the System Boundaries.

    • It outlines the scope of the services being provided, with specific emphasis on the infrastructure, software, people, and data relevant to the service.

    • It includes a description of any Trust Services Criteria or Services that are NOT in Scope.

    • It also includes a description of the subservice providers or the 3rd party providers that are used to support the service. This section will also describe the trust services criteria of their security environment that you rely upon, to paint a complete picture of your security practices.

  • Relevant Aspects of the...

    • Control Environment - This section goes into a bit more detail on almost every control that is in scope for the SOC 2. This is often the longest section of the System Description.

    • Risk Assessment Process - describes the organization's risk management process.

    • Information and Communication - describes how information is communicated within the organization as well is to and from outside stakeholders.

    • Monitoring - describes the activities that Management undertakes to monitor the security landscape of the organization.

  • Changes of the System During the Period

    • This section will capture any major infrastructure or process changes since the last SOC 2 report was issued, including any security incidents that occurred.

  • Complementary User Entity Controls

    • This is a list of the controls you expect your customer to have in place in order for your service to operate securely or as intended. We have more information on CUECs in a separate article here. We also have a blog that gives more information on them here.

Can I remove sections from the System Description?

Unless our guidance language specifically says that you can remove a given section (for example, the Criteria Not Applicable applicable section), then you should fill out all sections outlined in our template. The AICPA and your auditor demand that certain sections be addressed within the System Description, so you can run into trouble during audit by cutting out sections.

Questions?

Reach out through our chat feature for real-time Customer Success support 8 am - 5 pm PT Monday through Friday.