Updating the System Description

Update your System Description before the forthcoming audit; this checklist includes AICPA guidance issued in October 2022

Written By Micah

To ensure that auditors and end-users of your organization's product/solution have the most accurate understanding of your organization's current security compliance program, a SOC 2 System Description (Section III of the SOC 2 report) needs to be updated about a month or so prior to each forthcoming audit.

Remember that your organization's System Description needs to be as concise. The AICPA specifically recommends ‘no puffery,’ so keep it factual! Anything included in a System Description is fair game for an audit.

A video demonstration of how to utilize the System Description template can be found here.

System Description Update Checklist:

  1. Update the templated language in the Principle Service Commitments and System Requirements section to align with the Strike Graph template language.

  2. Add the role or team responsible for incident management in the People section.

  3. Ensure the most up-to-date versions of the Data Flow Diagram, Network Diagram, and Organizational Chart are showcased.

  4. Add/update the Incidents in the Last 12 Months section.

    If there has been a (significant) security incident during audit period, you may choose to disclose this to your readers at a very high level. Provide the nature of the incident, the timing, the extent of the effect of the incident, and how it was resolved.

    You will want to describe any incidents that resulted in:

    • A significant failure of one or more of your controls that impacted a customer.

    • An incident that impacted your service commitments or system requirements that was required to be disclosed due to cybersecurity laws or regulations.

    • Any incident that had a material impact on your financial position or was required to be disclosed on your financial statements resulted in a closure of a business unit or withdrawal of a product.

    If there have been no incidents during the audit period, paste in this language:

    There have been no significant incidents related to a control failure or that impacted service commitments or system requirements, were required to be disclosed, or had a material impact requiring disclosure.

5. Add/update the System Changes During the Period section.

Update this section if there have been any of the following major changes during the monitoring period that are relevant to service commitments and system requirements.

Either add this sentence:

There were no changes that are likely to affect report users’ understanding of how the [SYSTEM NAME] is used to provide the service during the period from [Start date] to [End date].

OR describe any significant change to:

  • The services provided.

  • Significant changes to IT and security personnel.

  • Significant changes to system processes, IT architecture and applications, and the processes and systems used by sub service organizations.

  • Changes to legal and regulatory requirements that could affect system requirements.

  • Changes to the org structure (i.e., a change in the legal entity) that resulted in a change to internal controls over the system.

6. Revise or update the Complementary User Entity Controls section to look like the following:

User entities are responsible for:

  • Example: Ensuring that access to the client portal is restricted to authorized users and access rights are commensurate with their job responsibilities.

  • Example: Ensuring that usernames and passwords for the client portal are not shared and kept confidential.

  • Further bullet points that begin with, "Ensuring that…"