SOC 2 System Description Additions (for HIPAA and/or TSCs)
If HIPAA and/or additional Trust Services Criteria are in scope for your SOC 2 report, include the following
Written By Micah
As described in the System Description Basics article, the System Description (also referred to as "Section III") is a required element of the SOC 2 + HIPAA Report. It is management's narrative of the product or service in scope and the security practices in place to secure them.
If pursuing a SOC 2 + HIPAA Report, use the following template:
If including the Availability, Confidentiality, or Processing Integrity Trust Services Criteria within the scope of your SOC 2 report, add the following to your System Description:
Reference the additional TSCs in the last sentence of the “Principle Service Commitments and System Requirements” section, such as:
This report is based on the Trust Services Criteria based on the guidance from AICPA and is limited in scope to the following Trust Principles:
Security
Availability
Confidentiality
Processing Integrity
Cut and paste the relevant report section(s) immediately after the last ‘control’ section. In our template, this is after the ‘System Monitoring’ subsection:
If including the Privacy TSC, refer to the System Description with Privacy template.
Tips on using Strike Graph System Description Template(s)
Anything written within the System Description is fair game to be audited, so make sure to perform a detailed review of the document and tailor it to accurately reflect your organization's practices.
Black text should remain in the document.
Red text is guidance, and should be deleted after used.
Purple text signifies example responses; they offer language that is sufficient, but all text should be closely reviewed and revised to mirror what is in place within your organization.
In addition to typed text, graphics/charts may be added to the System Description (i.e. Data Flow Diagram, Network Diagram, Organizational Chart).
For a SOC 2 Type 1, the following sections of the System Description template will be omitted:
“Incidents in the Last 12 Months”
“System Changes During the Audit Period”
Your auditor may prefer to move things around within your System Description. This is fine, as the structure is subjective.