Skip to main content

Overview

CaseBender provides comprehensive SOC2 Type II support, mapping platform capabilities to Trust Service Criteria and automating evidence collection for audit readiness. SOC2 Type II evaluates the operating effectiveness of controls over a period of time (typically 6-12 months), making continuous evidence collection essential.

Trust Service Criteria Coverage

Security (Common Criteria)

ControlDescriptionCaseBender Implementation
CC1.1-CC1.5Control EnvironmentOrganization management, team structure, role definitions
CC2.1-CC2.3Communication & InformationNotification service, audit trail, dashboard reporting
CC3.1-CC3.4Risk AssessmentVulnerability management, risk scoring, threat detection
CC4.1-CC4.2Monitoring ActivitiesUEBA, security monitoring, compliance dashboards
CC5.1-CC5.3Control ActivitiesRBAC, MFA, encryption, input validation
CC6.1-CC6.8Logical & Physical AccessAuthentication, authorization, PAM, API security
CC7.1-CC7.5System OperationsAudit logging, incident response, change management
CC8.1Change ManagementVersion control, deployment pipelines, approval workflows
CC9.1-CC9.2Risk MitigationSLA management, business continuity, disaster recovery

Availability

ControlDescriptionCaseBender Implementation
A1.1Capacity ManagementResource monitoring, auto-scaling support, health checks
A1.2Recovery ProceduresBackup management, disaster recovery, data retention
A1.3Recovery TestingBackup verification, failover testing documentation

Confidentiality

ControlDescriptionCaseBender Implementation
C1.1Confidential InformationData classification, TLP system, access controls
C1.2Disposal of Confidential InfoData retention policies, secure deletion, legal hold

Evidence Collection

Automated Collectors

CaseBender includes automated evidence collectors that gather compliance artifacts without manual effort:
  • Access Control Evidence: User lists, role assignments, permission matrices, MFA enrollment status
  • Audit Log Evidence: Authentication events, authorization decisions, data access logs, configuration changes
  • Change Management Evidence: Deployment history, code review records, approval workflows
  • Encryption Evidence: Encryption configuration, key rotation history, TLS certificate status
  • Monitoring Evidence: Alert history, incident response records, UEBA anomaly reports

Collection Schedule

Evidence TypeFrequencyRetention
Access reviewsQuarterly3 years
Audit log samplesMonthly3 years
Configuration snapshotsMonthly3 years
Vulnerability scansWeekly3 years
Penetration test resultsAnnually3 years
Training recordsQuarterly3 years

Evidence Review Workflow

  1. Collection: Automated collectors gather evidence on schedule
  2. Review: Compliance team reviews collected evidence for completeness
  3. Approval: Evidence is approved and tagged with the relevant control
  4. Storage: Approved evidence is stored with tamper-evident integrity protection
  5. Retrieval: Evidence is readily available for auditor review

Audit Period Management

Audit Periods

  • Define audit periods with start and end dates
  • Track evidence collection progress per period
  • Monitor control effectiveness across the audit window
  • Generate period-specific compliance reports

Gap Analysis

CaseBender identifies gaps in your SOC2 compliance:
  • Controls without sufficient evidence
  • Controls with outdated evidence
  • Controls that have not been tested within the required timeframe
  • New controls introduced by TSC updates that need implementation

Attestation Management

  • Track attestation status per control
  • Record control owner attestations
  • Manage exception and remediation workflows
  • Generate attestation reports for auditors

Reporting

Audit Reports

Generate comprehensive reports for your auditors:
  • Control Matrix: Complete mapping of TSC controls to CaseBender implementations
  • Evidence Package: Bundled evidence artifacts organized by control
  • Gap Report: Outstanding gaps with remediation plans and timelines
  • Testing Results: Control test results with pass/fail status and evidence

Continuous Monitoring

Between formal audits, CaseBender provides continuous compliance monitoring:
  • Real-time compliance score tracking
  • Alert on control degradation
  • Automated evidence collection ensures no gaps accumulate
  • Dashboard showing audit readiness at any point in time