SOC 2 Type 1 Automated Backup Log Collection
-
Where I'm working is currently SOC 2 Type 1 compliant, this is great and it means that we can work on a lot of different things for a variety of customers.
In the SOC 2 Type 1 control, is a weekly tasks to prove that backups are being performed (successfully).
At the moment, I'm pulling logs from my NFS target (synology) as a CSV and uploading that into OneTrust Tugboat - Evidence task, this absolutely sucks...
- It takes time away from other items
- If I miss the window, then we're "Out of Compliance"
- I'd imagine it's reasonable to automate with webhooks
Is anyone else doing something similar and exporting the backup logs directly from XO/XOA into a SOC 2 environment for reporting and if so how?
Hello! It looks like you're interested in this conversation, but you don't have an account yet.
Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.
With your input, this post could be even better 💗
Register Login