SSAE 18 SOC
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
‎10-22-2021 12:13 AM
Hi
We need "SSAE 18 SOC" papers for an audit process, I have found two documents into the community site about it: ServiceNow Platform SOC 1 Type 2 Bridge Letter 03-31 2021.pdf ServiceNow Platform SOC 1 Type 2 Report 03-31 2021.pdf but for the second paper (The bridge letter) only is covering until june 2021 and we need from july 21 to december 21 period Could you provide us it? I have attached the from the community site link https://community.servicenow.com/community?id=community_article&sys_id=887ceea1dbd0dbc01dcaf3231f961940
Thanks in advance
- Labels:
-
Compliance Management
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
‎10-22-2021 03:06 AM
The Service Organizational Control (SOC) framework is an attestation that ServiceNow meets the required standard regarding having controls in place to protect the confidentiality, integrity and availability of our customers’ data in the cloud.
- - SOC 1 focuses on the effectiveness of internal controls that affect the financial reports of customers
- - SOC 2 evaluates controls that are relevant to availability, integrity, security, confidentiality, or privacy.
ServiceNow is audited by a third party and has maintained its SSAE 18 SOC 1 Type 2 attestation since 2011 (SSAE 18 superseded SSAE 16 in 2017). SSAE 18 is aligned with international standard ISAE3402 and replaced the now-deprecated SAS70.
ServiceNow’s SOC 1 report covering the period October 1 (of the prior calendar year) to September 30 (current calendar year) is available via ServiceNow CORE by the end of each calendar year (December).
The SOC 1 report covering the period April 1 to March 31 is available via ServiceNow CORE by the end of each calendar Q2 (June).
ServiceNow has also undertaken an annual SOC 2 Type 2 attestation since 2013, relevant to security, availability and confidentiality controls listed in the AICPA Trust Services Criteria (TSC).
ServiceNow’s SOC 2 report covers the period October 1 (of the prior calendar year) to September 30 (current calendar year) and is available via ServiceNow CORE by the end of each calendar year (December).
A Bridge Letter is provided between audit periods so that the company is covered for the entire year.
ServiceNow’s SOC 1 bridge letter covering the period October 1 (current calendar year) to December 31 (current calendar year) is available on ServiceNow CORE by the end of each calendar Q1 of next year
The SOC 1 bridge letter covering the period April 1 to June 30 is available via ServiceNow CORE by the end of each calendar Q3.
ServiceNow’s SOC 2 bridge letter covers the period October 1 (current calendar year) to December 31 (current calendar year) and is available on ServiceNow CORE by the end of each calendar Q1 of next year.
Please mark answer as Correct if it solved your question,
Seb
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
‎03-22-2022 05:50 AM
I have a CORE account but cannot locate the reports - are you able to tell me where I can find them?
David