Skip to main content

VPN

What we mean by “VPN” and how to satisfy the related evidence

Cayla Marshall avatar
Written by Cayla Marshall
Updated over 2 years ago

What is a VPN and how does it impact my audit?

A VPN (virtual private network) is an encrypted connection over the Internet from a device to a network. The encrypted connection helps ensure that sensitive data is safely transmitted. It prevents unauthorized people from eavesdropping on the traffic and allows the user to conduct work remotely.

For SOC 2, there is no requirement to utilize a VPN, so if you don't already have one in place don't worry about implementing one specifically for SOC 2 compliance.

Do I need a VPN if I don’t use one already?

Not necessarily. Consider this from a risk perspective. Is the data that your staff is accessing sensitive or confidential? Have you applied sufficient controls to address the risk? Would implementing VPN access reduce the risk further?

If you don’t currently use a VPN, and don’t plan to implement one, then you should take care to remove references to a VPN within your control descriptions and deactivate any VPN-related evidence items.

Did this answer your question?