Compliance, Audit & SOC 2 for Data Centers
This course covers compliance and audit operations for colocation and hyperscale data centers, centered on the AICPA Trust Services Criteria used in SOC 2 examinations — Security (the mandatory Common Criteria CC1-CC9), and the optional Availability, Confidentiality, Processing Integrity, and Privacy categories — alongside ISO/IEC 27001:2022 and its 93 Annex A controls across organizational, people, physical, and technological themes. Students assemble audit evidence packages for physical access control, change management, and incident response controls; draft a Statement of Applicability excluding inapplicable Annex A controls with documented justification; and walk through a mock SOC 2 Type II evidence request from an external auditor. The course distinguishes Type I (point-in-time) from Type II (period-of-time, operating-effectiveness) examinations and covers the evidence retention practices data-center operations staff must sustain year-round, not only at audit time.
What you'll be able to do
- Classify a control activity under the correct SOC 2 Trust Services Criteria category (Security, Availability, Confidentiality, Processing Integrity, or Privacy).
- Assemble a physical access control audit evidence package covering badge provisioning, deprovisioning, and periodic access review.
- Draft a Statement of Applicability excluding inapplicable ISO/IEC 27001:2022 Annex A controls with documented justification.
- Distinguish SOC 2 Type I and Type II examination scope and evidence requirements for a given control.
- Respond to a mock external auditor evidence request within a defined turnaround window.
- Document a change-management record demonstrating segregation of duties and approval evidence for a data-center infrastructure change.
- Identify a control gap during a mock internal audit walkthrough and draft a corrective action plan.
- Map a customer compliance question (e.g., data residency, sub-processor list) to the correct internal control owner and evidence source.
- Interpret a SOC 2 Type II report's exceptions section and assess customer-facing risk implications.
- Maintain a continuous compliance evidence calendar tracking recurring control activities across a 12-month audit period.
Train the team that runs the factory.
The Institute travels with every SAVRN campus.