SOC 2 readiness for Mindpath
Gap assessment, policies and technical controls to pass a SOC 2 Type I audit. A case study by James O'Connor, Penetration Tester & Security Consultant.
Challenge
Mindpath, a mental health app, was asked for a SOC 2 report by every large prospect but had no policies, no formal access reviews and no vendor management.
Solution
I ran a gap assessment against the Trust Services Criteria, wrote pragmatic policies, implemented technical controls with the engineering team and prepared evidence for the auditor.