System Description Template
How to use the Strike Graph System Description template and what to do if an additional Trust Services Criteria is in scope
Written By Micah
As described in the System Description Basics article, the System Description (aka "Section III") is a required element of the SOC 2 Report. It is management's narrative of the product/service in scope and the security practices that are in place to secure it.
A video demonstration of how to utilize the System Description template can be found here.
If you are only pursuing the Security Trust Services Criteria, use the template below:
If you are also pursuing the Privacy Trust Services Criteria, use the template below.
If you are including the Availability, Confidentiality, or Processing Integrity Trust Services Criteria with your SOC 2, add the following to your System Description:
Reference the additional TSCs within the last sentence of the “Principle Service Commitments and System Requirements” section, such as:
This report is based on the Trust Services Criteria based on the guidance from AICPA and is limited in scope to the following Trust Principles:
Security
Availability
Confidentiality
Processing Integrity
Cut and paste the relevant report section(s) immediately after the last ‘control’ section. In our template, this is after the ‘System Monitoring’ subsection:
Tips on using Strike Graph System Description Template(s)
Anything written within the System Description is fair game to be audited, so make sure to perform a detailed review of the document and tailor it to accurately reflect your organization's practices.
Black text should remain in the document.
Red text is guidance, and should be deleted after used.
Purple text signifies example responses; they offer language that is sufficient, but all text should be closely reviewed and revised to mirror what is in place within your organization.
In addition to typed text, graphics/charts may be added to the System Description (i.e. Data Flow Diagram, Network Diagram, Organizational Chart).
For a SOC 2 Type 1, the following sections of the System Description template will be omitted:
“Incidents in the Last 12 Months”
“System Changes During the Audit Period”
Your auditor may prefer to move things around within your System Description. This is fine, as the structure is subjective.