What should I do in my first 90 days as a compliance lead?
As a compliance lead, your first 90 days should focus on comprehensive discovery. Understand the current state of controls, identify existing documentation for SOC 2 and ISO 27001, and engage key stakeholders. Prioritise assessing the organisation's context, risk landscape, and control maturity to establish a baseline for future compliance efforts and build a strategic roadmap.
Begin by conducting a thorough review of existing documentation, including policies, procedures, and previous audit reports relevant to SOC 2 Trust Services Criteria and ISO 27001 Annex A controls. Engage with department heads, IT operations, and legal teams to understand current operational practices, control implementation, and data flows. This initial phase is critical for mapping existing controls against both frameworks' requirements and identifying areas where documentation or implementation may be nascent or absent. Focus on understanding the organisation's scope for both frameworks, particularly the Information Security Management System (ISMS) scope for ISO 27001 and the system/service scope for SOC 2.
Following the initial assessment, perform a detailed gap analysis comparing the current state against the specific requirements of SOC 2 (e.g., Common Criteria, Availability, Confidentiality) and ISO 27001 (Clauses 4-10, Annex A). Develop a prioritised remediation roadmap, distinguishing between quick wins and longer-term strategic initiatives. Establish clear communication channels with leadership and control owners, setting expectations and defining roles for ongoing compliance activities. This period is also crucial for initiating or refining the organisation's risk assessment process, a foundational element for both frameworks, ensuring risks are identified, analysed, and treated appropriately.
Sources
- AICPA, Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy (SOC 2), Common Criteria (CC1.1, CC2.1, CC3.1)
- ISO/IEC 27001:2022, Information security, cybersecurity and privacy protection — Information security management systems — Requirements, Clause 4 (Context of the organisation), Clause 6 (Planning), Clause 9 (Performance evaluation)