SOC 2 Type 1 Automated Backup Log Collection
-
Where I'm working is currently SOC 2 Type 1 compliant, this is great and it means that we can work on a lot of different things for a variety of customers.
In the SOC 2 Type 1 control, is a weekly tasks to prove that backups are being performed (successfully).
At the moment, I'm pulling logs from my NFS target (synology) as a CSV and uploading that into OneTrust Tugboat - Evidence task, this absolutely sucks...
- It takes time away from other items
- If I miss the window, then we're "Out of Compliance"
- I'd imagine it's reasonable to automate with webhooks
Is anyone else doing something similar and exporting the backup logs directly from XO/XOA into a SOC 2 environment for reporting and if so how?