Video: Audit Readiness Simulation: Plan, Prep & Prove | Duration: 3256s | Summary: Audit Readiness Simulation: Plan, Prep & Prove | Chapters: Welcome and Introduction (7.52s), Audience Poll (87.92s), Audit Readiness Fundamentals (146.52s), Vanta Platform Demo (443.955s), Framework Navigation (531.365s), Policy Management (702.845s), Control Verification Methods (1251.015s), Documents and Tests (1477.575s), Vulnerability Management (1743.145s), SLA Configuration (2208.65s), Personnel Management (2294.84s), Task Tracking Management (2417.145s), Platform Integrations (2506.145s), Audit Wrap-up (2558.095s)
Transcript for "Audit Readiness Simulation: Plan, Prep & Prove":
Okay. Good morning, everyone, and welcome to the Vanta audit readiness walk through. My name is Kareem Mathias. I am the GRC program education manager here at Vanta. Today, we're gonna walk through how to prepare your company for your first audit. Whether you're going through your first audit or you've been through audits before and wanna get some tips and tricks from us at Vanta, Sit back, relax, and we're gonna talk through some of the audit best practices here. Gonna give a few more minutes for everyone to join and then get into it around 10:02. So looking forward to talking to you. For those that are already here, could you just drop a good morning, good afternoon, chat, wherever you're dialing from? Tell me a little bit about your name and where you're from so I know who I'm talking to. In California. Nice to meet you. Hi. Elena from Saint Petersburg, Florida. Wish I was there, but, you know, I'm from Philadelphia, so it's nice here too. Oh, good morning from Minnesota. Portugal. Okay. This is a wide ranging audience. I'm glad you guys are joining me from all over. So quick question for those of you that are here. On a scale of one to 10, how comfortable are you with audits audits inventing the whole audit process so I know where I should focus a lot of our attention today? Oh, greetings from Egypt. Yes. This is going to be recorded. So in addition to getting a recording of this call, we also would love to direct you guys to our Vanta Academy and then our help center that has a lot of material that really reinforces the fundamentals of audit. There is an audit 101102103 series of articles, actually written by yours truly, that will be able to get you up to speed on everything audit related in Vanta. Okay. Threes, threes, and fours. Alright. So I'll really take it nice and slow. So let's get into it. Okay. So first, we're gonna go through our audit readiness checklist and some of the fundamentals on audit, and then we're gonna go into the program here. Advantage, we have another deck I wanna show you. So let me share my screen there. K. K. Well, let me get into. Okay. So audit readiness simulation, getting fully prepared for your audit. First, whenever we're talking about audits, I really wanna boil down what is a security audit. A security audit is a formal review of your security program by an independent party. What that means is it's not assessing you on things where you don't really know what the questions will be. It's more so like an open book exam or an exam where you already have the answers to all the questions. An auditor checks whether your controls, your evidence, and documentation meets the standards for frameworks like SOC two or ISO 27,001 that you're already working to conform to. So what that means is is if you're doing everything that you're supposed to be doing and you're checking your documentation, you're mapping your controls, your people are getting your documentation in and meeting their deadlines, so you have nothing to worry about. An audit is just a verification of that process happening. And the reason why audits matter is because they prove to customers, partners, procurement teams especially, that your company maintains an effective information technology program. This includes maintaining confidentiality, integrity, and availability. And a lot of that is just, can I depend on you to be the resource that I'm either paying for or I'm giving my data to as a customer or that I'm partnering with? Audits are a shorthand way of saying yes. Yes. You can. And think of it like this. I've worked in third party risk management before, and many times when we're looking for a security tool or a vendor, I'll go to their trust center and say, have they done a SOC two? Have they done ISO 27,001? And you could have two identical vendors or even one vendor that's a little better. But if they don't have that security documentation where I can see it, it makes me second guess, oh, are they safe? Could they get hacked? Did they take security seriously? And that can be the difference between starting a vendor relationship and not really being able to close that. So for many companies, especially growing companies, an audit report is what turns security work into sales ready proof. It's an asset to have that sort of documentation. We, at Vanta, support you in that process by centralizing your audit work in one place, organizing evidence, giving auditors access, tracking audit progress, and storing the final report. I do wanna make a quick note though. The auditors that you are working with have your own system to actually to conduct actually to conduct testing of controls and making the work papers and storing the evidence. That's not what we do here at Vanta. We more so coordinate your program so that they can source it from this place all in one. So they'll be pulling the information from Vanta to their own systems to be able to do the testing. Vanta is a centralization of that on your end. So you should take away that an audit is in the checkbox. It's how your company proves to its customers, partners, and procurement team that you're secure. You take security seriously, and you have an up an effective security program. As far as resources, at the end of this, you'll get a recording of the slides within twenty four hours. We have many other trainings at Vanta including integrations, policy workshop, risk vulnerabilities. We definitely encourage you to attend as many live trainings as you need to help make sure you have an effective program here at Vanta. If you have feedback, please share. And if you need support in the application, go to the question icon and utilize that. We definitely wanna make sure that you're served as well as possible, and so we try to front load you with as many resources as we can. So in a second, we're gonna go into the Vanta platform so we can talk through all of this, and I can walk you through. But before we do that, does anyone have any questions? Okay. Seeing no questions, I do wanna take a moment to also introduce my colleague, Jaques Hotto. He is the program manager for down market education here at Vanta. He'll also be answering questions here in the chat if they come up and be able to provide you with a wealth of information. So hello from DeQuest, from all of us, and let's get into Vanta. K. K. Let me know if you can see my screen, everybody, then we can keep it going. So what you see here is a frameworks page here in Vanta. And I like to start off here because the frameworks is often the starting point for your audit. In a sense, each audit is trying to comply with the controls that are outlined in the specific framework. And often when you're buying Vanta getting set up, you're getting set up with a framework in mind that you wanna conform to. And that could be SOC two. That can be ISO 27,001. And so a lot of what I like to do is go into the framework stage, and then maybe clicking into SOC two or ISO 27,001 and then taking a look at the controls. And so each control has a list of sub controls that are supported by evidence, have owners, control sets, etcetera. And we're gonna get more into this as we go throughout the section, but I just want you to think about how you're going from the framework to the requirement categories, to the control environment, and how each of those supports the level above. You have the framework that's supported by the control categories that's supported by the sub controls in there that you provide evidence for that has a control owner. And all of that together is what your auditor is assessing to make sure you're following it effectively. Oh, taking a minute here. Just want you to get a good look at that. So now let's go to the audit section just to give you a quick overview of what that looks like here in Vanta. This is the audit section here, and here you can see active audits that are currently underway. You can also see completed audits. This is an environment that's relatively new, so we don't have any completed audits yet. However, you can also sort by the audit firm, the frameworks that have been in scope for audits, the audit status, and audit type. At Vanta here, we support internal and external audits, and we like to give you that sort of support so that you're able to both do internal audits and testing before you're doing your external to make sure everything is where it needs to be. And then have a seamless connection with your external auditors so that you can so that you can pass your audits smoothly. Next, I wanna show you the policy section because that's the first stop after frameworks where okay. You have your framework, you have your SOC two, you know you want to create and develop those. But from frameworks, then we need to make our policies because that's what we're really gonna be assessed on. So taking a look at the policy page, there's a lot of good information here that I wanna make sure you're aware of. You can sort things by their status, what needs approval from you, what needs approval in general, what needs reassignment. Going back to all. This view here gives you the ability to see, okay, what do I need to renew, or what do I need to update by my audit deadline? Say, for example, your audit is coming up by July 1, and you need to have everything okay, fully approved, fully locked in like this access control policy right here. So then you can notice these are new by dates. You can filter on the status like I showed you before. And then you start to you can start to see, okay. Well, I'm being audited on SOC two on July 1. So I only really care about things that are in scope for that. So I'm a filter there and see, okay. So my code of conduct policy needs to be approved or remediated or whatever by July 1. So let me start to send that notification out there who's the approver. I can see that here. The approver is Ahmed here. So let me start to send that notification and start to spread that information. And you really wanna make good use of that so you're not reacting to what the auditor is asking for in real time. You're more so being proactive and able to get your policy squared away before the audit starts. So take a second there. Are there any questions about the policy section? Alright. All good. I do wanna go into a policy and just highlight one thing. So as your inside policies remember, there's different versions of policies that are created over time. As you remediate and make updates, you'll be able to see past versions of policies. Let me show you that actually. I don't filter on that. Let's go to all. So as you can see, this policy has been in the environment for a while, since May 2024, May 2025. As you renew policies and update, you'll be able to see past versions there. Additionally, each policy has mapped elements like controls and frameworks and things that are linked to it. And that is how the frameworks that you're working on get linked to a policy as you map controls. These controls get added to a policy that you're working on, and they then relate to the framework that you're working on. What you really wanna do as you're writing your policies and you're linking your controls is make sure that there is a set make sure that there's a strong link between that the policy that you're writing, the control that you're linking to it, and then the actual framework that you're trying to follow. If those threes are in if those three things are in tandem, then you're in good shape. One thing that we like to recommend is using our Vanta agent. If there's ever any doubt, you can find that agent up here in the top right hand corner. And then you can ask the questions like, I am preparing for my I'll cut to audit. I am preparing for my SOC two audit. Do I have a code of conduct policy? Is are the controls properly mapped in that policy to meet to? And in answering that question, it can search your environment and make sure that you're conforming to what you need to do. K. Notice that the AI agent was able to highlight, yes, we have a code of conduct policy inventive, but there are a few steps that remain. It's currently in draft state awaiting approval, like we mentioned on the highlight on the overall policy section. Policy is currently mapped to the course dot two requirements for this document. Content requirements, your current policy draft includes reporting violation section that establishes a process. This is important. So we need to approve the policy, roll out acceptance, make sure we have evidence. So those little things are so helpful. Oh, okay. Yes. I can go back and go over mapping the controls. Certainly. Certainly. I just wanted to show you this real quick. So if you ever in doubt, the AI agent's a great resource to be able to answer your questions in here. But going back to mapping controls, I wanna show you how to get to that from the policy section. So you click policies. Next, you can click a control. You can see the policy versions, mapped elements, audits, and comments. You go to mapped elements. And here you'll see all the controls that are currently mapped to your policy. And then from here, you can click map control, and we can map additional policies to the control sorry. Additional controls to this policy based either on our AI suggestion or you can use a search here to search for things that you think might be relevant. So this one is a scope of information security management systems. Say if you wanna make sure cloud related things are added into that. Okay. Not cloud. Say if you wanna search for infrastructure. Alright. Reminds, say if you wanna filter by framework, make sure that this policy makes SOC two as well. You can filter there. You can add that in. Good question. Good question. As far as mapping controls for each policy, when you come in to Vanta and you add new policies, you can either add new policies from your policy library and you our policy library, rather. You can add them in that way. You can create new policies from scratch, or you can import policies from your existing environment either by uploading or by adding them from Google Drive, Confluence, or SharePoint. We do have auto mapping with our AI function. So it's not that you're responsible for mapping controls manually. We do have a function that does that for you. However, they're not automatic based on framework per se. It's more so the tool and request can, express it, so I'm not really articulating it well. But, essentially, you write your policy, and then our tool is able to look at the policy and link what controls make the most sense. But then depending on the framework that you're subscribed to and the framework that you're trying to follow, the controls will be linked to that framework and then linked to the policy. But then we encourage you to double check to make sure everything is linked together smoothly. Alright. Good. And I see you have a question, from a friend in Egypt. If we're seeing this, does it mean we are ready for audit? Well, there's a lot involved with being ready for audit in the policy section. If everything is approved, that's a good sign, but there are many more steps to that. So can I send a screenshot? I don't think I'm able to send see screenshots that you'll have if you send them to me here, but I can reach out to you after the call to walk through it if necessary. Oh, okay. Okay. The quest can help you with that. Perfect. Perfect. Okay. But in addition to policies, next, we have to go to documents because those are what help prove controls. Okay. Does it take a while? I'm ported about two hours ago, but nothing in AI has potential for mapping. Oh, yeah. Let me show you again. So, again, if you have your policy in Vanta here, mapped elements, map control, you'll get these auto suggestion ones. So try to do that. Try to go through policy map control and see the suggestion ones, and click the ones that you think make the most sense. So that auto suggestion one is it'll be able to help you get your controls linked up. I see. Okay. Let me come back to that. Definitely want to make sure I cover everything now. This is the control section. Here, you can see all of the controls that are linked with your subscription here. You can filter these on framework as well. These are all filtered to SOC two. You can also filter on owner, as in what's assigned to you versus needs reassignment. You can filter on domain, as in are they administrative controls, asset management. You can filter on source. Are they coming from Vanta, custom framework code to really match the specific control from the SOC two or whichever that you're trying to comply to. And then you can also filter on status. You'll also notice that each control has something called test here. Test and documents are the two ways that a control is verified in Vanta. We verify your controls by a combination of integrations where when you integrate your environment with Vanta, you can look sorry. When you integrate your environment with Vanta, we're able to see if that integrated connection is operating effectively. And if that integration is linked to a control, then we can also see that the control is operating effectively. So here, this is a document. Someone uploaded a cybersecurity insurance policy document, and that shows, oh, okay. There is cybersecurity insurance. We have evidence of that. It's verified, uploaded, done. This control is good to go. Need to assign someone to it, but the evidence is there. Let's see if we have another one. I'm gonna unfilter and just show you the whole thing. This one's another one where you have job scheduling access. Let's see. You have a test here. A test is, again, a verification of the integration, and a document is something that is uploaded by the user. Just wanna show you the whole line here. We are in the artificial and autonomous technology domain. This seems to have an owner assigned. However, you have mapped elements of test and documents here, and you can see that it's linked to the access control policy, and it's also linked to a SOCS ITGC framework. So this whole thing is showing the entire chain of what's linking this control to what policy, to what framework, and then what tests and documents approving it. And verifying all of these within the scope, whatever framework you're getting audited or that we'll have audited is super important for that. Hey. Thank you, Jacqueline, for answering that question. Next, I wanna show you guys the documents and test section. So the document section is a list of all the documents that are maintained in your environment. As you go through audit cycles and review cycles, you'll have to upload documents again to reverify that they are exactly what they need to be. As you can see here, we can we have the owner, status, renew by, and framework. When the overall status is overdue, that means, oh, okay. We need to remediate this. We need to upload an updated version of the document. We need to make sure we're still following this process. We need to make sure that the proof that was good last year or last quarter still meets the needs of the work of the control. So clicking into here. We also wanna make no other view cycles, and those are customizable. At Vanta, we recommend renewal or recurrence based on the needs of your environment. We have everything from every two years, annually, biannually, quarterly, and so on. With setting those renewals, you'll have to make sure that they're assigned to the proper person that's able to do those renewals and make sure that they are properly notified to do so. Just a quick note, you wanna make sure that you're matching the document renewal periods to how often your org needs to update these files. Again, we have monthly, quarterly, annually, and so on. And make sure that they're at least quarterly so that you're never really taken by surprise during an audit. K. Next to documents. Once again, I want you to take a look at the document section. You can filter here by what's owned by you, which ones need a new document for various reasons, which things are in draft. You can use this in combination with test to be your main point of emphasis when working through your audits and preparing for your audits. Next is the test section. So, again, a test is the verification of your integrations as they are linked to controls in Vanta. So you'll be able to see what tests are passing in this dashboard here. And as we can see, a 117 of a 169 are passing, and this is a combination of automated tests and documents. And then this gives you a nice short list here of what needs your attention. You can see what's overdue, what needs remediation with no SLA assigned, and what's due soon. And I'll get into the SLA portion in just a little bit. But we have the same basic outline here where you can filter on framework, control, integration, so you can bundle by, well, what things in my a AWS environment need to be remediated or updated so that I'm meeting my controls? You can get very granular with the test filtering here so that you can really outline everything you you need to do ahead of your audit. And I want you to take a second and think about that. So you can get granular with what controls you're looking for. You can do so in a document section and a test section so that before your audit, you can sort of do inventory yourself to see what are my frameworks that are in scope, and how are my integrations doing, and do I have anything overdue for AWS specifically? Do I need to talk to our cloud security team and ask them to upload the documentation or to update the environment because this server isn't doing what it needs to do or this network segment's not secured the way it should be? Really use this as a way to give yourself a map of how to prepare yourself for the audit. On a note want to highlight the agent again. Maybe we can see if we can get some help on this. So let's say we're on this page, and I have a test that is overdue. It is AWS. How can I Great question? I'll get to your observation window in just a second. Once this updates, we can get to that. Okay. So this give you outline of what's going on. To remediate this, you need to ensure that each of your failing e c two instances and auto scan groups has a CloudWatch alarm configured to a CPU utilization metric. This outlines what resources are failing and gives you the remediation steps. So this is great because it can arm you with some information that you can use to go to your cloud security team, your infrastructure team, and say, hey. We're we have an audit coming up. We really need to make sure our cloud environment that's in scope is meeting all the requirements that we need. Here are what I think is going here's what I think is going wrong based on my observation of the our environment of Vanta. Can you tell me if this is the case and what needs to be remediated, and when can you get this done by? And that sort of shorthand information is fantastic for giving people the ability to remediate things ahead of the audit. Let's see. You have a question. Our observation window is October, November, December, and report scheduled for January 27. What should we expect during the observation window? So when you say observation window, do you mean that your testing will be from October to December? Okay. So so that just means that October is a cutoff date for when your environment needs to be ready. And then during that window is when they'll be doing testing. And so during that window, they'll be observing your policies, observing your controls, making sure everything is operating effectively. And see since it's a three month testing window, that makes me think it's not a point in time test, but an actual operating effectively test. So that means you wanna make sure that everything, not only it's operating effectively leading up to the audit, but that people understand that it needs to sort of be continuous. As in, okay, they're gonna be looking at our environment over this period of time. Let's make sure that not only are we fixing issues, but we're also making sure that they won't come up again. And we're doing a full remediation. So this period now in the summer is a prime time to do that either internal audit testing or do that inventory that I'm mentioning now where you're walking through. Okay. Let's see how my controls are in scope for SOC two, and I see one out of three tests is complete. Okay. What's going on there? I see oh, I need to update this and it's unassigned. I need to update this and it's unassigned. This is a time where you can start to talk to people to assign these out to have meetings and make a plan to be remediated by, say, a late September So that all that work is done by October, November, December. And so during that time, you're responding to request list. You're answering follow-up questions. You're working on remediation plans if they come up during the audit window, and you can just focus on that. Hopefully, that answered your question. Okay. Next, I want to go to vulnerabilities. So vulnerabilities are part of the integration that I mentioned back in the test section. And with these integrations, you actually have SLAs that you need to have their mediated by based on what you determine is your risk appetite for your organization. So auditors want to see that you're not only maintaining your controls, but you're also meeting your SLAs. So if you have an outage or a control not working effectively, you're fixing those within the windows that you attest to. And so you can use this section to filter by that SLA status to say, okay. Well, it's overdue and what's due soon. And you say, okay. This one, I have one critical vulnerability status here, And then for this EKS instance, 762 vulnerabilities. This is due in twenty eight days. This is going to be a major problem. This tells you, I need to get my cloud security team together today and really start to work on remitting these vulnerabilities? Can they do a scan to see what's going on? Can I look and maybe use my Vanta agent to give me a quick summary of what's going on so that I can take that and give them some quick tips, not tips, but more so diagnose with problem? So let's see if we can do that here. It's still on. Hello. I have to re an issue with one assets by oh, in twenty eight days. This EKS instance has interval abilities. What should tell my internal team to sure. So now it's reading your SLAs, searching the help center, listing issues. And just wanna note, our Vanta Adrian is trained on a combination of your help of our help center and then also has access to all the information that you put in this instance. So it's able to give you tailored solutions. So here, to ensure your internal team is prepared to remediate this vulnerability within twenty day window, you should focus on following strategy, prioritize the severity, high, medium, low, remediation strategy, rotate node groups, adopt minimum space images, triage activation. So the reason this sort of thing is so important is because it gives you the ability to not only go to your teams and say, fix this, but more so say, here is what is wrong that's clearly needs to be remediated, and here's what I think we need to do specifically. And that gives them more to go off of and hopefully can even prioritize or help you be prioritized because you're pointing to specific issues with specific fixes in mind. K. Next, I wanna show you how to modify those SLAs or make sure that they're set effectively in the first place. So to do that, you can either go to view settings here or go back, settings, and assets, vulnerability SLAs. And what you wanna do is make sure these SLAs are set to the remediation window that you find appropriate for your organization, and you can set these SLAs based on the the criticality of the different levels. Obviously, critical is quick, fifteen days. High is a little longer. Medium's a little longer, and so on. So as you're setting up your Vanta environment, you're doing your integrations, you're having these onboard, You wanna make sure you're setting these SLAs to remediate vulnerabilities within this window. Your auditor will be able to see the history of this as well, so you'll be able to see if you're getting better with your SLA remediations, you're meeting your deadlines, you're you're conforming with what you say you're gonna do with remediation and track that over time. You also wanna make sure that you're monitoring access to these assets to make sure that the person assigned to work on these assets is a person that should be assigned to do it. And that gets us to the next section, which is personnel. Personnel will be your central hub for working with people in Vanta. And you can do that through a few different ways. So in Vanta, you'll have service accounts, you'll have people, you'll have groups, And each person will be you'll be able to assign them to a group. You can assign them tasks. You can assign them things to do and track here their progress on that. So, again, if you're going through your control section, your document section, your policy section, you see people need to approve policies, people need to upload documents, they need to complete tests or remediate integrations, so test or verify. This is a section where you can start to see who is in charge of what and start to send those notifications. And you can send updates and notifications in a few ways. You can select people individually and maybe say, send a reminder. I'm gonna see if I can find myself and do that. So I'm not so I'm not bugging anybody that doesn't need to be. Send a reminder, and you can do that there. And it's sending a reminder. You can also send a reminder to everybody in bulk. I don't recommend to do this unless it's super necessary, but you can do send a reminder. You can modify groups. You can all four. Also note, you can track what tasks you have to do in the my work section of Vanta, and that'll let you know what things are do for you, what's assigned to you, what needs your approval, etcetera, etcetera. But back to the personnel section. Again, it's super important to filter by status and audit window. So you can see that what's due for this audit period, this is the past Wednesday example we're using, what's due for this period and what people have task or assignments due during that time. So this will be a big help to be able to track everything down to say, hey. We have this audit coming up in three weeks, and I still need you to remediate that cloud environment. This EKS instance is still kicking 700 errors. I gave you the information in Vanta. Can you update it? You can send an email or you can use, once again, this. Send the email for you so it's clear, oh, it's coming from Vanta. That person has stuff to do. You can also go inside your settings and set automatic reminders and notifications here. And this is send reminders to personnel on a recurring digest for their incomplete security task, and you can do that every weekday. You can also do it weekly. You can email reminders, and we also have a Slack integration. Okay. Before I move on, I wanna go into the auditor section. But before I do that, I just wanna know. Are there any questions? Is there anything you need me to go back over before I dive into the audit section? I wanna make sure I cover that in detail before we move on. Okay. Yeah. It should be a Teams integration. You can actually see all of your integrations in this integration section. And I'm pretty sure we have Office three six five, and that comes with all the different Microsoft capabilities. Let me see. There's another instance that might have that. So going here, integrations. As you can see, we have many, many, many integrations. We have Datadog, DocuSign, Google Workspace, HubSpot, Jira, Notion. So more than likely, we'll have integrations. You might wanna talk to your CSM to make sure that everything you need is integrated, but, yeah, we have a lot of integrations. We try to make it so the ease and VANT is as seamless as possible. So no problem. So going to the audit section, I actually wanna do something first before we're even here. Because if your auditor is not added in Vanta and then you're not able to get an email from us, they won't be notified that you added them to an audit. So here's what I wanna do. I wanna go to settings, go to user permissions, and go to auditors. And I do wanna make a quick note. You don't click this button up here to add user. That just adds a new user to your environment. You specifically wanna do an add auditor. And that's because we have different audit firms here, and you can search the existing ones here. However, you might be using KPMG. You might be using You might be using Protiviti or someone. And you're using, say, the St. Louis office or the Miami office, and so that specific person is not added into your Vanta instance. So you need to invite them to Vanta. You can name the audit firm. You can say what the firm domain is, contact information, contact email, and then you send that invitation. Soon that it's done, once they're invited, accept that invitation. Actually, I wanna show you what that means. After you audit that in Vanta, they will receive an email to take our self led training about auditing on Vanta. They actually get training from us on how to handle the audit environment here in Vanta, and their responsibilities as an auditor. So going back to the audit section, we wanna start a new audit. And we do that by clicking this add audit button here. And add a new audit, add an audit for your framework, and invite your auditor when you're ready to share your Vanta data. Auditors will be able to view your controls and related evidence, including tests, documents, and policies associated with the audit framework from a dedicated audit portal. Manage your default audit review and compliance settings. And let's click here to see what that looks like. So this is what what do we want auditors to see? And you can edit your audit visibility to show. Can they see your control history? Or you don't want them to see the history, you want them to see only what they should see right now. You want the default audit view to be full, as in they have access to expanded pop population attributes supporting a more automated efficient audit process, or you can have it more controlled or more granular limit, things to need to know. You can decide what is appropriate for your organization, but wanna make sure you know how to get there. So gonna go from the audit section. You can go to settings, compliance, audit visibility, and you can update those settings. So going back to audit so we can create our audit. I know we're running short on time. You do that. Add audit. Definitely take time to read all of this information when you're doing so, but, okay, go in here. Segment. We wanna add SOC two. That's what we're doing. This is our environment, SOC two for TigerLabs. We wanna do a SOC two type two, and this tells you that the TSC is let me click that. You select to find which areas will be assessed and reported on, and this audit security is always required. So this is what are all the subsections in SOC two that are in scope for the audit that are coming up. So you can select your scope. And this is different for different frameworks, but this is what's happening for SOC two. You can name it. So today is the twenty fourth, so let's name six twenty four. External or internal. If it's an internal audit, you don't actually select the audit firm. You more so assign a user within your environment to be the person that comes in and does the audit. But for this example, we're gonna do external. You can select the audit firm. Let's look at what firm comes up. I want to do audit firm. You can select your auditor. I'm a go with Jose Azure. And for advanced settings, you can either import your own request list, and that limits the scope of what will be seen by the auditor, or you can use Vanta's default request list. And this also change to give auditors a full view into your expanded population data. Next, we want to select an audit range, and let's say we wanna start from today. We're being audited from today to June 30. It's a quick turnaround, and we wanna grant access to test evidence. Audits auditors use test evidence to confirm the underlying event test results are accurate. So we review this, make sure all this information is correct, and then we add audit. Okay. And there we go. Let's find, 06/24. Let's see if we can I think we can sort by date, but let's go with 06/24? We can actually open the audit. And now we're actually in the auditor view here in Vanta. And so you'll see what controls are ready for audit, what's not ready for audit, what's not applicable as in not in scope. And this is how your auditor will see Vanta once they're in here looking at your controls. You'll they'll be able to see the risks that come up and audit and highlight that, but we have our wonderful risk live training session that goes more into detail on that. Highly recommend it. You can see vendors. It can see your asset inventory and your vulnerabilities, so you wanna make sure that they are doing well. Everything here is remediated, so your auditor would be able to see that. You can also see personnel, and then you can see controls and frameworks. So seeing that we're auditing for SOC two, you get to see what controls are linked to what frameworks. And here you can see, okay. I'm doing testing. I see evidence status. Two three of these are not ready for audit. And so this is something I highly encourage you to do too. Take the time before your audit to make sure you're looking at this from your auditor's point of view So you're going in there and seeing, oh, shoot. This isn't ready for audit yet. I need to update this. I need to update this. And be a little paranoid in making sure that everything in your environment is updated to what it needs to be ahead of your audit. But seeing that we're running short on time, I wanna make sure that I answer all your questions. So can you mark a control for SOC two as not applicable organization? How do you provide a comment explaining that? That's a good question. That's a good question. Oh, that's something that you would discuss with your auditor ahead of time and confirm the scope that makes sense for you. So an auditor can only audit within the scope that you guys mutually agree to. So that's one thing. As far I know you can disable controls. And, yeah, you can also disable controls in Vanta. But I think that would be a conversation with your auditor to make sure they know the correct scope and to say, oh, well, this organization, this isn't applicable for this organization. They say, for example, for control in SOC two is that you manage your on prem data centers effectively. But you have no on prem data centers. You only use the cloud. Within the SOC two report, they would just say control not applicable, subject or client or customer, what have you, does not have on prem environment, and so we can't assess this. And so it just can't be tested. Okay. Any other questions? Okay. Thank you for request for giving a more detailed answer there. K. Is there anything anyone wants me to go over again while we still have a little bit of time left? Okay. I'll see. Now I wanna thank everyone for spending this time with us. If you're new wait. Okay. Okay. Is there an audit prepared checklist countdown list or just what you went over? Yes. Yes. There is. And I will link you that right now. In our help center, we have an audit one zero one, 102, and one zero three article list that covers everything I talked about in this call, and I'll share that link with you now. I highly encourage you to use our help center as it has a wealth of information about Vanta, from everything from getting started with audits to integrations to documents, testing, everything you could think of. We fill our help center with lessons that we learn from questions that we get from customers like you. So your participation in the help center is greatly appreciated. Yes. Thank you, Joyce, for linking that. Share your feedback at this link here. Hopefully, you found it helpful to spend your time with me. I've I'd like to hope everyone here learned something. So, yeah, thank you for spending time with us. If you're new to Vanta, promise this is much more of a smooth process than it seems. I know it can be very intimidating with all the different tabs, the buttons, the filters, this and that, but take your time. Take it slow. Over time, you'll get to learn everything, and it'll seem second nature. And definitely use a Vanta agent. That's like a nice copilot with you that can answer a lot of your questions and just teach you how Vanta works. So join our community and come back anytime for another session. It was a pleasure to talk to you this morning. Thank you so much.