

SOC 2 + HITRUST
SOC 2 + HITRUST Compliance Experts
The NDB Alliance of Firms offers the following services relating to SOC 2 + HITRUST audits:
Readiness Assessment
-
Conduct comprehensive assessments of an organization's policies, procedures, systems, and controls to evaluate their compliance with HIPAA regulations.
-
Identify gaps and areas of non-compliance and provide recommendations for remediation.
SOC 2 + HITRUST Gap Analysis
-
Perform a detailed analysis of the organization's existing security controls and practices to identify gaps and deficiencies against SOC 2 and HITRUST CSF requirements.
-
Provide a comprehensive report outlining the identified gaps and recommendations for addressing them.
Control Implementation Guidance
-
Assist in the design and implementation of security controls and practices to meet the requirements of SOC 2 and HITRUST CSF.
-
Provide guidance on establishing policies, procedures, and technical controls aligned with the specific criteria of both frameworks.
Documentation Review and Development
-
Review and assess the organization's documentation, including policies, procedures, and control narratives, to ensure they meet the requirements of SOC 2 and HITRUST CSF.
-
Assist in developing or updating the necessary documentation to demonstrate compliance.
Security Control Testing
-
Conduct testing of the organization's security controls to validate their effectiveness and compliance with SOC 2 and HITRUST CSF requirements.
-
Perform control testing procedures, including sample-based testing, interviews, and document reviews, to assess the implementation and operating effectiveness of controls.
Remediation Support
-
Provide guidance and support in addressing identified gaps and deficiencies.
-
Assist in developing and implementing remediation plans to bring security controls into compliance with SOC 2 and HITRUST CSF requirements.
Readiness Review for HITRUST CSF Certification
-
Conduct a comprehensive assessment to determine the organization's readiness for HITRUST CSF certification.
-
Identify areas requiring improvement and provide guidance on meeting the certification requirements.
SOC 2 + HITRUST Audit
-
Conduct an independent audit of the organization's security controls and practices to assess compliance with SOC 2 and HITRUST CSF requirements.
-
Perform testing, review documentation, and issue a final audit report documenting the organization's level of compliance.
Ongoing Compliance Monitoring
-
Provide ongoing support and monitoring to help the organization maintain compliance with SOC 2 and HITRUST CSF requirements.
-
Assist in establishing processes for continuous monitoring, self-assessment, and improvement of security controls and practices.
HITRUST CSF Certification
-
Provide support throughout the HITRUST CSF certification process, including guidance on self-assessment, audit preparation, and working with a HITRUST-authorized external assessor.
-
Assist in the preparation of required documentation, such as the System Security Plan (SSP) and the Corrective Action Plan (CAP).