{"id":51348,"date":"2023-04-03T09:24:48","date_gmt":"2023-04-03T13:24:48","guid":{"rendered":"https:\/\/live-jc-marketing-site.pantheonsite.io\/?p=51348"},"modified":"2024-11-14T19:08:40","modified_gmt":"2024-11-15T00:08:40","slug":"soc-2-admin-and-control-owner-responsibilities-and-tips-for-passing-an-audit","status":"publish","type":"post","link":"https:\/\/jumpcloud.com\/blog\/soc-2-admin-and-control-owner-responsibilities-and-tips-for-passing-an-audit","title":{"rendered":"Compliance Planning: SOC 2 Admin and Control Owner Responsibilities \u2014 and Tips for Passing an Audit"},"content":{"rendered":"\n

As a compliance manager or IT admin that\u2019s in charge of managing SOC 2 audits, it\u2019s common to find yourself taking on the sole responsibility of your entire organization\u2019s controls in an attempt to ensure consistency and compliance. However, this often creates unnecessary challenges when audits begin and is almost impossible to keep up with on top of your other day-to-day duties. <\/p>\n\n\n\n

To avoid this, a major part of both of these roles needs to be focused on delegating responsibilities while building relationships and awareness with the assigned control owners. If your organization is struggling with a disconnect here, taking a step back and reassessing your SOC 2 audit framework<\/a> is a good place to start; but ultimately, getting this balance and partnership established is one of the most effective ways to pass SOC 2 audits consistently.<\/p>\n\n\n\n

So now that you are preparing for the inevitable SOC 2 audit, there are certain activities you can do to get ahead of these common challenges. Taking initiative and using a proactive approach will not only help you pass future SOC audits with flying colors, but it will also decrease your organization\u2019s overhead and the amount of day-of stress that your team faces. A proactive approach regarding SOC 2 audits involves planning, delegation\/ownership, internal audits, and control owner preparation.<\/p>\n\n\n\n

This approach begins at the top of your organization and trickles down \u2014 management needs to set clear expectations for the entire team and assign control owners in order to avoid taking on all of the SOC responsibilities<\/a> across the entire organization. From there, control owners need to fully embody their role and take complete ownership over their controls which involves internal auditing, consistency, rationalization, evidence storage, and communication.<\/p>\n\n\n\n\n

\n
\n \"JumpCloud\"\n <\/div>\n
\n

\n The IT Manager\u2019s Guide to Data Compliance Hygiene <\/p>\n

\n How to ace your audit <\/p>\n <\/div>\n

\n Get the Guide <\/a>\n <\/div>\n<\/div>\n\n\n\n\n

Be Proactive, Not Reactive<\/h2>\n\n\n\n

By assigning controls to various key people across your organization, you can delegate different levels of responsibility to each. This is not only a relief to the compliance manager, but it also means that a closer eye can be kept on each control when they\u2019re split between multiple people who can spend more time internally auditing them.<\/p>\n\n\n\n

Being proactive rather than reactive will save your organization massive amounts of time and stress later on down the line by preventing failed audits and employee burnout. The best ways to be proactive as a member of management or the compliance manager are to assign controls to others and ensure that they\u2019re set up in a way that allows them to take full ownership, build a positive and bidirectional relationship with each control leader, and schedule regular meetings with control leaders to discuss any issues that arise.<\/p>\n\n\n\n

It can be difficult to get buy-in from assigned control leaders, as they already have full plates with their day-to-day responsibilities. During regular organizational planning, it\u2019s important to prioritize initiatives and communicate to your team that SOC 2 compliance is high priority. On top of that, you may also need to help control owners adjust their priorities to take SOC into consideration and avoid overwhelming them with too many tasks.<\/p>\n\n\n\n

Once priorities are set company-wide and workloads are as balanced as possible, relationship building and regular check-ins will prove to be essential to ensure complete ownership is taken over each control. It\u2019s important to work with each control leader to make further workload adjustments, identify areas of control improvement, remind them of annual compliance commitments, and locate where their control evidence resides.<\/p>\n\n\n\n

Undertake an Internal SOC 2 Audit<\/h2>\n\n\n\n

Completing an internal audit is a great way to prepare yourself and your team for an external SOC 2 audit. Processes get easier after you\u2019ve run through them at least once, and an internal audit gives your team a chance to close any gaps and make changes to controls before you\u2019re all put on-the-spot.<\/p>\n\n\n\n

A few benefits of conducting an internal audit are finding out where control evidence resides for later use, ensuring there are no inconsistencies between controls, and encouraging control owners to focus on processes rather than ambiguous control language.<\/p>\n\n\n\n

An important thing to remember is that with SOC, you can always change controls to keep up with your organization\u2019s changing reality. Nothing is set in stone, and controls should be monitored and adjusted as the organization\u2019s processes and commitments change and expand over time.<\/p>\n\n\n\n

Tips for Control Owners and Admin<\/h2>\n\n\n\n

As a control owner, preparation for a SOC 2 audit is key to remaining sane when it comes time for the actual thing.<\/p>\n\n\n\n

Have a Method to Your Madness<\/h3>\n\n\n\n

Be able to explain to an auditor why you chose the controls and processes that you did \u2014 these are what you\u2019re held accountable for and they need to be logical. Consider leveraging other defined standards such as PCI<\/a> or GDPR<\/a> to help you explain the \u2018why\u2019 behind your choice of best practices, protocols, processes, etc. Though you won\u2019t be held responsible for adhering to any external standards, using them to back your argument up will prove valuable.<\/p>\n\n\n\n

Impose Consistent Controls<\/h3>\n\n\n\n

Controls don\u2019t count if they aren\u2019t being used \u2014 any controls you choose to use need to be active. Automation is key for keeping consistency within your controls without having to reinvent the wheel \u2014 a great example of this is zero-touch onboarding<\/a>. Automation is great for repetitive, standardized tasks such as onboarding, offboarding, and any other regular tasks you deal with. If you can\u2019t automate, this is where checklists and documentation proving that you followed the checklist become indispensable.<\/p>\n\n\n\n

On top of that, test cases are picked at random during a SOC 2 audit, so consistency will make collecting evidence much easier.<\/p>\n\n\n\n

Leave a Trail<\/h3>\n\n\n\n

Leaving a documented trail of evidence proves that you\u2019re adhering to the processes you outlined. Examples of this can be in the form of checklists with signatures, categorized helpdesk tickets, Slack channels, and email threads. Any time a change happens to a mission-critical system, ensure that it\u2019s documented in the same place in the same format to achieve consistency.<\/p>\n\n\n\n

Document Processes and Exceptions<\/h3>\n\n\n\n

As part of your paper trail, establishing and defining your processes and exceptions will serve you well during a SOC 2 audit. When putting out a new control, there will always be exceptions that need to be documented \u2014 it\u2019s very rare that you\u2019re able to have 100% coverage across a single control 100% of the time. However, keep exceptions as minimal as possible \u2014 monitor processes over time and remove exceptions whenever you can to reduce system vulnerability.<\/p>\n\n\n\n

In terms of change management, it\u2019s important for employees and auditors to be able to reference documentation that details what the change was, why it happened, how it was handled, and who was involved.<\/p>\n\n\n\n

Communicate Regularly and Clearly<\/h3>\n\n\n\n

As a control owner, it\u2019s important to have regular communication with the audit and compliance managers. Loop them in when any new software or systems that involve sensitive data are implemented to ensure the rollout is smooth and adheres to best practices. Clear communication between all parties better guarantees consistency in evidence formatting, confirms control responsibility and ownership, and allows any overlap between control owners across teams to be distinctly laid out in front of all stakeholders to ensure clarity and compliance.<\/p>\n\n\n\n

This communication tells management, control owners, and external auditors who the point-person is for each control so they know who to contact for evidence or more insight into a topic.<\/p>\n\n\n\n

Understand That it Gets Easier Over Time<\/h3>\n\n\n\n

Audits are a lot of work, but the more audits you go through, the more streamlined the process becomes. If multiple audits are performed in the same period, it\u2019s likely that some evidence will cover both of them adequately.<\/p>\n\n\n\n

Ex. JumpCloud completed a SOC 2 Type 2<\/a> and accounting\/finance audit in succession, and everything in the accounting and finance audit had already been covered in the evidence from the SOC 2 audit. This meant all we had to do was some copying and pasting rather than starting from scratch and taking more time away from other important tasks.<\/p>\n\n\n\n

Benefits of Preparing for a SOC 2 Audit<\/h2>\n\n\n\n

Whether you\u2019re part of the management team, a compliance expert, an audit manager, or a control owner, preparing for a SOC 2 audit is more than worth it in the end. Putting in the work up front is ideal so you\u2019re not scrambling to explain yourself or providing evidence that\u2019s inconsistent or nowhere to be found in the middle of an unexpected audit.<\/p>\n\n\n\n

If you were to fail an audit due to retroactively trying to take the steps outlined here, customers will quickly lose faith in you, resulting in negative publicity and a poor brand image. On top of that, employee burnout is much more likely to happen during an audit when preparations were slim to none and your team is now stressed and disorganized.<\/p>\n\n\n\n

SOC 2 Compliance: As Painless As Enforce, Prove, Repeat<\/em>.<\/h2>\n\n\n\n

Whether you want to learn more about SOC 2 compliance or you\u2019re ready to start working toward achieving it, JumpCloud\u2019s IT Compliance Quickstart Guide<\/a> was designed to get IT professionals the resources they need to prepare for an audit or shore up their IT security baseline.<\/p>\n","protected":false},"excerpt":{"rendered":"

SOC 2 compliance is a heavy lift for compliance managers and IT admins \u2014 delegate controls responsibly and avoid stretching your team members too thin.<\/p>\n","protected":false},"author":143,"featured_media":51352,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_oasis_is_in_workflow":0,"_oasis_original":0,"_oasis_task_priority":"","inline_featured_image":false,"footnotes":""},"categories":[23],"tags":[],"collection":[2775],"platform":[],"funnel_stage":[3015],"coauthors":[2533],"acf":[],"yoast_head":"\nSOC 2 Admin, Control Owner Responsibilities, Audit Passing Tips<\/title>\n<meta name=\"description\" content=\"SOC 2 compliance is a heavy lift for compliance managers and IT admins \u2014 delegate controls responsibly and avoid stretching your team members too thin.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/jumpcloud.com\/blog\/soc-2-admin-and-control-owner-responsibilities-and-tips-for-passing-an-audit\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Compliance Planning: SOC 2 Admin and Control Owner Responsibilities \u2014 and Tips for Passing an Audit\" \/>\n<meta property=\"og:description\" content=\"SOC 2 compliance is a heavy lift for compliance managers and IT admins \u2014 delegate controls responsibly and avoid stretching your team members too thin.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/jumpcloud.com\/blog\/soc-2-admin-and-control-owner-responsibilities-and-tips-for-passing-an-audit\" \/>\n<meta property=\"og:site_name\" content=\"JumpCloud\" \/>\n<meta property=\"article:author\" content=\"matt.renstrom\" \/>\n<meta property=\"article:published_time\" content=\"2023-04-03T13:24:48+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-11-15T00:08:40+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/jumpcloud.com\/wp-content\/uploads\/2021\/06\/Person-being-stretched-too-thin.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1900\" \/>\n\t<meta property=\"og:image:height\" content=\"1140\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Brenna Lee\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Brenna Lee\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"9 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/jumpcloud.com\/blog\/soc-2-admin-and-control-owner-responsibilities-and-tips-for-passing-an-audit#article\",\"isPartOf\":{\"@id\":\"https:\/\/jumpcloud.com\/blog\/soc-2-admin-and-control-owner-responsibilities-and-tips-for-passing-an-audit\"},\"author\":{\"name\":\"Brenna Lee\",\"@id\":\"https:\/\/jumpcloud.com\/#\/schema\/person\/359d7999806d5e67935965c2dd3d28e7\"},\"headline\":\"Compliance Planning: SOC 2 Admin and Control Owner Responsibilities \u2014 and Tips for Passing an Audit\",\"datePublished\":\"2023-04-03T13:24:48+00:00\",\"dateModified\":\"2024-11-15T00:08:40+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/jumpcloud.com\/blog\/soc-2-admin-and-control-owner-responsibilities-and-tips-for-passing-an-audit\"},\"wordCount\":1542,\"publisher\":{\"@id\":\"https:\/\/jumpcloud.com\/#organization\"},\"image\":{\"@id\":\"https:\/\/jumpcloud.com\/blog\/soc-2-admin-and-control-owner-responsibilities-and-tips-for-passing-an-audit#primaryimage\"},\"thumbnailUrl\":\"https:\/\/jumpcloud.com\/wp-content\/uploads\/2021\/06\/Person-being-stretched-too-thin.jpg\",\"articleSection\":[\"Best Practices\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/jumpcloud.com\/blog\/soc-2-admin-and-control-owner-responsibilities-and-tips-for-passing-an-audit\",\"url\":\"https:\/\/jumpcloud.com\/blog\/soc-2-admin-and-control-owner-responsibilities-and-tips-for-passing-an-audit\",\"name\":\"SOC 2 Admin, Control Owner Responsibilities, Audit Passing Tips\",\"isPartOf\":{\"@id\":\"https:\/\/jumpcloud.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/jumpcloud.com\/blog\/soc-2-admin-and-control-owner-responsibilities-and-tips-for-passing-an-audit#primaryimage\"},\"image\":{\"@id\":\"https:\/\/jumpcloud.com\/blog\/soc-2-admin-and-control-owner-responsibilities-and-tips-for-passing-an-audit#primaryimage\"},\"thumbnailUrl\":\"https:\/\/jumpcloud.com\/wp-content\/uploads\/2021\/06\/Person-being-stretched-too-thin.jpg\",\"datePublished\":\"2023-04-03T13:24:48+00:00\",\"dateModified\":\"2024-11-15T00:08:40+00:00\",\"description\":\"SOC 2 compliance is a heavy lift for compliance managers and IT admins \u2014 delegate controls responsibly and avoid stretching your team members too thin.\",\"breadcrumb\":{\"@id\":\"https:\/\/jumpcloud.com\/blog\/soc-2-admin-and-control-owner-responsibilities-and-tips-for-passing-an-audit#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/jumpcloud.com\/blog\/soc-2-admin-and-control-owner-responsibilities-and-tips-for-passing-an-audit\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/jumpcloud.com\/blog\/soc-2-admin-and-control-owner-responsibilities-and-tips-for-passing-an-audit#primaryimage\",\"url\":\"https:\/\/jumpcloud.com\/wp-content\/uploads\/2021\/06\/Person-being-stretched-too-thin.jpg\",\"contentUrl\":\"https:\/\/jumpcloud.com\/wp-content\/uploads\/2021\/06\/Person-being-stretched-too-thin.jpg\",\"width\":1900,\"height\":1140,\"caption\":\"broken lego man\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/jumpcloud.com\/blog\/soc-2-admin-and-control-owner-responsibilities-and-tips-for-passing-an-audit#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/jumpcloud.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Compliance Planning: SOC 2 Admin and Control Owner Responsibilities \u2014 and Tips for Passing an Audit\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/jumpcloud.com\/#website\",\"url\":\"https:\/\/jumpcloud.com\/\",\"name\":\"JumpCloud\",\"description\":\"Daily insights on directory services, IAM, LDAP, identity security, SSO, system management (Mac, Windows, Linux), networking, and the cloud.\",\"publisher\":{\"@id\":\"https:\/\/jumpcloud.com\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/jumpcloud.com\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/jumpcloud.com\/#organization\",\"name\":\"JumpCloud\",\"url\":\"https:\/\/jumpcloud.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/jumpcloud.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/jumpcloud.com\/wp-content\/uploads\/2021\/01\/jc-logo-brand-2021.png\",\"contentUrl\":\"https:\/\/jumpcloud.com\/wp-content\/uploads\/2021\/01\/jc-logo-brand-2021.png\",\"width\":598,\"height\":101,\"caption\":\"JumpCloud\"},\"image\":{\"@id\":\"https:\/\/jumpcloud.com\/#\/schema\/logo\/image\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\/\/jumpcloud.com\/#\/schema\/person\/359d7999806d5e67935965c2dd3d28e7\",\"name\":\"Brenna Lee\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/jumpcloud.com\/#\/schema\/person\/image\/a512f44ee3cc1a59010e879f81d8b53c\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/967dd7256974fbbeb3db3f2549c2da47?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/967dd7256974fbbeb3db3f2549c2da47?s=96&d=mm&r=g\",\"caption\":\"Brenna Lee\"},\"description\":\"Brenna is a Content Writer at JumpCloud that loves learning about and immersing herself in new technologies. Outside of the [remote] office, she loves traveling and exploring the outdoors!\",\"sameAs\":[\"https:\/\/jumpcloud.com\/blog\",\"matt.renstrom\",\"stefano.tomasello@jumpcloud.com\"]}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"SOC 2 Admin, Control Owner Responsibilities, Audit Passing Tips","description":"SOC 2 compliance is a heavy lift for compliance managers and IT admins \u2014 delegate controls responsibly and avoid stretching your team members too thin.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/jumpcloud.com\/blog\/soc-2-admin-and-control-owner-responsibilities-and-tips-for-passing-an-audit","og_locale":"en_US","og_type":"article","og_title":"Compliance Planning: SOC 2 Admin and Control Owner Responsibilities \u2014 and Tips for Passing an Audit","og_description":"SOC 2 compliance is a heavy lift for compliance managers and IT admins \u2014 delegate controls responsibly and avoid stretching your team members too thin.","og_url":"https:\/\/jumpcloud.com\/blog\/soc-2-admin-and-control-owner-responsibilities-and-tips-for-passing-an-audit","og_site_name":"JumpCloud","article_author":"matt.renstrom","article_published_time":"2023-04-03T13:24:48+00:00","article_modified_time":"2024-11-15T00:08:40+00:00","og_image":[{"width":1900,"height":1140,"url":"https:\/\/jumpcloud.com\/wp-content\/uploads\/2021\/06\/Person-being-stretched-too-thin.jpg","type":"image\/jpeg"}],"author":"Brenna Lee","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Brenna Lee","Est. reading time":"9 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/jumpcloud.com\/blog\/soc-2-admin-and-control-owner-responsibilities-and-tips-for-passing-an-audit#article","isPartOf":{"@id":"https:\/\/jumpcloud.com\/blog\/soc-2-admin-and-control-owner-responsibilities-and-tips-for-passing-an-audit"},"author":{"name":"Brenna Lee","@id":"https:\/\/jumpcloud.com\/#\/schema\/person\/359d7999806d5e67935965c2dd3d28e7"},"headline":"Compliance Planning: SOC 2 Admin and Control Owner Responsibilities \u2014 and Tips for Passing an Audit","datePublished":"2023-04-03T13:24:48+00:00","dateModified":"2024-11-15T00:08:40+00:00","mainEntityOfPage":{"@id":"https:\/\/jumpcloud.com\/blog\/soc-2-admin-and-control-owner-responsibilities-and-tips-for-passing-an-audit"},"wordCount":1542,"publisher":{"@id":"https:\/\/jumpcloud.com\/#organization"},"image":{"@id":"https:\/\/jumpcloud.com\/blog\/soc-2-admin-and-control-owner-responsibilities-and-tips-for-passing-an-audit#primaryimage"},"thumbnailUrl":"https:\/\/jumpcloud.com\/wp-content\/uploads\/2021\/06\/Person-being-stretched-too-thin.jpg","articleSection":["Best Practices"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/jumpcloud.com\/blog\/soc-2-admin-and-control-owner-responsibilities-and-tips-for-passing-an-audit","url":"https:\/\/jumpcloud.com\/blog\/soc-2-admin-and-control-owner-responsibilities-and-tips-for-passing-an-audit","name":"SOC 2 Admin, Control Owner Responsibilities, Audit Passing Tips","isPartOf":{"@id":"https:\/\/jumpcloud.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/jumpcloud.com\/blog\/soc-2-admin-and-control-owner-responsibilities-and-tips-for-passing-an-audit#primaryimage"},"image":{"@id":"https:\/\/jumpcloud.com\/blog\/soc-2-admin-and-control-owner-responsibilities-and-tips-for-passing-an-audit#primaryimage"},"thumbnailUrl":"https:\/\/jumpcloud.com\/wp-content\/uploads\/2021\/06\/Person-being-stretched-too-thin.jpg","datePublished":"2023-04-03T13:24:48+00:00","dateModified":"2024-11-15T00:08:40+00:00","description":"SOC 2 compliance is a heavy lift for compliance managers and IT admins \u2014 delegate controls responsibly and avoid stretching your team members too thin.","breadcrumb":{"@id":"https:\/\/jumpcloud.com\/blog\/soc-2-admin-and-control-owner-responsibilities-and-tips-for-passing-an-audit#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/jumpcloud.com\/blog\/soc-2-admin-and-control-owner-responsibilities-and-tips-for-passing-an-audit"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/jumpcloud.com\/blog\/soc-2-admin-and-control-owner-responsibilities-and-tips-for-passing-an-audit#primaryimage","url":"https:\/\/jumpcloud.com\/wp-content\/uploads\/2021\/06\/Person-being-stretched-too-thin.jpg","contentUrl":"https:\/\/jumpcloud.com\/wp-content\/uploads\/2021\/06\/Person-being-stretched-too-thin.jpg","width":1900,"height":1140,"caption":"broken lego man"},{"@type":"BreadcrumbList","@id":"https:\/\/jumpcloud.com\/blog\/soc-2-admin-and-control-owner-responsibilities-and-tips-for-passing-an-audit#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/jumpcloud.com\/"},{"@type":"ListItem","position":2,"name":"Compliance Planning: SOC 2 Admin and Control Owner Responsibilities \u2014 and Tips for Passing an Audit"}]},{"@type":"WebSite","@id":"https:\/\/jumpcloud.com\/#website","url":"https:\/\/jumpcloud.com\/","name":"JumpCloud","description":"Daily insights on directory services, IAM, LDAP, identity security, SSO, system management (Mac, Windows, Linux), networking, and the cloud.","publisher":{"@id":"https:\/\/jumpcloud.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/jumpcloud.com\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/jumpcloud.com\/#organization","name":"JumpCloud","url":"https:\/\/jumpcloud.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/jumpcloud.com\/#\/schema\/logo\/image\/","url":"https:\/\/jumpcloud.com\/wp-content\/uploads\/2021\/01\/jc-logo-brand-2021.png","contentUrl":"https:\/\/jumpcloud.com\/wp-content\/uploads\/2021\/01\/jc-logo-brand-2021.png","width":598,"height":101,"caption":"JumpCloud"},"image":{"@id":"https:\/\/jumpcloud.com\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/jumpcloud.com\/#\/schema\/person\/359d7999806d5e67935965c2dd3d28e7","name":"Brenna Lee","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/jumpcloud.com\/#\/schema\/person\/image\/a512f44ee3cc1a59010e879f81d8b53c","url":"https:\/\/secure.gravatar.com\/avatar\/967dd7256974fbbeb3db3f2549c2da47?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/967dd7256974fbbeb3db3f2549c2da47?s=96&d=mm&r=g","caption":"Brenna Lee"},"description":"Brenna is a Content Writer at JumpCloud that loves learning about and immersing herself in new technologies. Outside of the [remote] office, she loves traveling and exploring the outdoors!","sameAs":["https:\/\/jumpcloud.com\/blog","matt.renstrom","stefano.tomasello@jumpcloud.com"]}]}},"_links":{"self":[{"href":"https:\/\/jumpcloud.com\/wp-json\/wp\/v2\/posts\/51348"}],"collection":[{"href":"https:\/\/jumpcloud.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/jumpcloud.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/jumpcloud.com\/wp-json\/wp\/v2\/users\/143"}],"replies":[{"embeddable":true,"href":"https:\/\/jumpcloud.com\/wp-json\/wp\/v2\/comments?post=51348"}],"version-history":[{"count":3,"href":"https:\/\/jumpcloud.com\/wp-json\/wp\/v2\/posts\/51348\/revisions"}],"predecessor-version":[{"id":117582,"href":"https:\/\/jumpcloud.com\/wp-json\/wp\/v2\/posts\/51348\/revisions\/117582"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/jumpcloud.com\/wp-json\/wp\/v2\/media\/51352"}],"wp:attachment":[{"href":"https:\/\/jumpcloud.com\/wp-json\/wp\/v2\/media?parent=51348"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/jumpcloud.com\/wp-json\/wp\/v2\/categories?post=51348"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/jumpcloud.com\/wp-json\/wp\/v2\/tags?post=51348"},{"taxonomy":"collection","embeddable":true,"href":"https:\/\/jumpcloud.com\/wp-json\/wp\/v2\/collection?post=51348"},{"taxonomy":"platform","embeddable":true,"href":"https:\/\/jumpcloud.com\/wp-json\/wp\/v2\/platform?post=51348"},{"taxonomy":"funnel_stage","embeddable":true,"href":"https:\/\/jumpcloud.com\/wp-json\/wp\/v2\/funnel_stage?post=51348"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/jumpcloud.com\/wp-json\/wp\/v2\/coauthors?post=51348"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}