Compliance, Audit & SOC 2 for Data Centers

Advanced · SDB
96Total hours
40Lecture
56Hands-on lab
SDB 2801Prerequisite
Credential
56 lab hours 40 lecture hours

This course covers compliance and audit operations for colocation and hyperscale data centers, centered on the AICPA Trust Services Criteria used in SOC 2 examinations — Security (the mandatory Common Criteria CC1-CC9), and the optional Availability, Confidentiality, Processing Integrity, and Privacy categories — alongside ISO/IEC 27001:2022 and its 93 Annex A controls across organizational, people, physical, and technological themes. Students assemble audit evidence packages for physical access control, change management, and incident response controls; draft a Statement of Applicability excluding inapplicable Annex A controls with documented justification; and walk through a mock SOC 2 Type II evidence request from an external auditor. The course distinguishes Type I (point-in-time) from Type II (period-of-time, operating-effectiveness) examinations and covers the evidence retention practices data-center operations staff must sustain year-round, not only at audit time.

What you'll be able to do

  1. Classify a control activity under the correct SOC 2 Trust Services Criteria category (Security, Availability, Confidentiality, Processing Integrity, or Privacy).
  2. Assemble a physical access control audit evidence package covering badge provisioning, deprovisioning, and periodic access review.
  3. Draft a Statement of Applicability excluding inapplicable ISO/IEC 27001:2022 Annex A controls with documented justification.
  4. Distinguish SOC 2 Type I and Type II examination scope and evidence requirements for a given control.
  5. Respond to a mock external auditor evidence request within a defined turnaround window.
  6. Document a change-management record demonstrating segregation of duties and approval evidence for a data-center infrastructure change.
  7. Identify a control gap during a mock internal audit walkthrough and draft a corrective action plan.
  8. Map a customer compliance question (e.g., data residency, sub-processor list) to the correct internal control owner and evidence source.
  9. Interpret a SOC 2 Type II report's exceptions section and assess customer-facing risk implications.
  10. Maintain a continuous compliance evidence calendar tracking recurring control activities across a 12-month audit period.

Train the team that runs the factory.

The Institute travels with every SAVRN campus.

Engage SAVRN → Open the catalog