Related Posts
UHY is looking to hire across all positions both audit and tax for our office in Melville, Long Island. We the largest book of business in UHY and have grown significantly over the past few years. There is tremendous opportunity for growth and the office is more than just a job. We regularly have golf outings, wine tastings, bbqs at the partners houses and many other events with our team. Anyone who is interested send me a message and I will set up a time to connect and discuss our opportunities UHY Advisors
Celebrate responsibly y’all

AMC to the moon baby
Additional Posts in Cyber Security Bowl
Tell me it’s not true.

Any thoughts on the CISM certification?
New to Fishbowl?
unlock all discussions on Fishbowl.



This is a standard question that I have come across when working with new security teams. The SOC teams tend to be treated as an afterthought. This undermines visibility for the entire company. Here is my take from a high level down to SOC 2 Controls -
Every org should have a defined risk mitigation plan. I would align NIST's CSF 2.0 framework as part of organizational risk management planning.
Each domain should have a defined risk mitigation plan. For example, cloud teams who focus on IaaS/PaaS can use NIST 800-53 based frameworks for compliance monitoring. However, domains like IAM may use NIST 800-63 series for compliance and risk management planning.
SOC Teams - Direction should/may come from upper layers indicating what kind of security posture is needed, how it will be measured, and (hopefully) map it back to upper management's compliance planning and objectives. For SOC teams, understanding controls based upon the industry (e.g., Healthcare vs Finance) may impact the selection of tools. CIS 8 lists various controls which provides comprehensive risk management support.
Visit the 'guardian' of SOC 1/2/3 standards and review their current standards. This is where 'reasoning' models are really helpful. Try this exercise, it is called 'Flipped Interaction' when using an AI Agent. Use an AI agent by indicating that you have to come up with a SOC framework, here are the inputs (current controls and management objectives), and for the AI agent to keep asking you questions until you have a satisfactory answer.
I hope that this is helpful.