A tailored course, built for your situation
Become the go to SOC 2 practitioner at CGI
Position yourself as the internal expert on SOC 2 assessments and lead engagements with confidence
Who this is for
Senior technical practitioner transitioning from active architecture role, maintaining influence through advisory and compliance leadership
Who this is not for
Junior auditors, entry-level compliance staff, or practitioners outside of enterprise IT services
What you walk away with
- Lead internal SOC 2 scoping sessions with authority
- Map technical controls to Trust Services Criteria without external consultants
- Produce evidence packages that pass reviewer scrutiny on first submission
- Mentor junior staff on control implementation and testing
- Be proactively consulted on new client requirements involving SOC 2
The 12 modules (with all 144 chapters)
- What SOC 2 proves today
- Types I and II differences
- Trust Services Criteria breakdown
- Common missteps in scoping
- Auditor expectations now
- Client demand drivers
- Reporting package components
- Management assertion structure
- System description essentials
- Control design vs operation
- Evidence types by criteria
- First steps for practitioners
- Identifying in scope systems
- Network perimeter definition
- Third party dependencies
- Cloud service considerations
- User access boundaries
- Data flow mapping
- In scope personnel
- Legacy system handling
- Change management scope
- Shared responsibility models
- Documentation standards
- Finalizing scope statement
- Mapping access controls
- Logging and monitoring alignment
- Change approval workflows
- Backup verification design
- Encryption in transit mapping
- Data retention compliance
- Vendor risk integration
- Incident response linkage
- BCDR plan alignment
- Physical security controls
- Configuration management
- Control ownership assignment
- Acceptable use policy drafting
- Password policy standards
- Remote access rules
- Data handling classifications
- Incident response planning
- Vendor due diligence policy
- Backup retention schedule
- Change control procedure
- Physical access rules
- Encryption standards
- Audit logging policy
- Policy review cycle
- Sample size guidelines
- Access log collection
- Change ticket review
- User provisioning proof
- Role-based access demo
- Pen test documentation
- Vulnerability scan results
- Backup success reports
- Incident logs
- Policy acknowledgment records
- Training completion proof
- Automated evidence tools
- Auditor selection criteria
- Pre audit briefing
- Request list handling
- Evidence submission format
- Follow up responses
- Deficiency remediation
- Management letter items
- Audit timeline expectations
- In person walkthroughs
- Remote audit logistics
- Report review process
- Final sign off steps
- System overview drafting
- Infrastructure components
- Software and platforms
- Data flows
- Third party services
- Security controls summary
- Availability mechanisms
- Processing integrity notes
- Confidentiality safeguards
- Privacy commitments
- Change history
- Version control
- Testing frequency rules
- Sample selection method
- Walkthrough technique
- Documentation review
- Observation methods
- Re performance testing
- Automated control checks
- Exception handling
- Remediation tracking
- Testing evidence packaging
- Reviewer feedback loop
- Continuous monitoring setup
- Exception identification
- Risk assessment of gaps
- Remediation planning
- Compensating controls
- Management override logs
- Documentation accuracy
- Timeline for fixes
- Auditor notification
- Interim evidence
- Status tracking
- Follow up testing
- Closure verification
- Executive update rhythm
- Technical team briefings
- Legal department sync
- Client communication rules
- Status reporting format
- Escalation protocol
- Training rollout plan
- Change impact notices
- Audit progress updates
- Remediation tracking visibility
- Post audit review meeting
- Lessons learned session
- Training new staff
- Playbook creation
- Control ownership model
- Knowledge transfer sessions
- Internal audit prep
- Cross team collaboration
- Succession planning
- Tool standardization
- Policy maintenance
- Change control integration
- Compliance calendar
- Annual review cycle
- Annual planning cycle
- Scope refresh triggers
- Team readiness check
- Auditor retention
- Internal prep schedule
- Evidence collection start
- Draft review cycle
- Management sign off
- Report distribution
- Client Q&A readiness
- Lessons learned capture
- Next cycle improvements
How this maps to your situation
- When starting a new SOC 2 engagement
- When responding to auditor requests
- When onboarding new team members
- When updating system descriptions
Before vs. after
What's included with your purchase
- 12 modules with 12 chapters each (144 chapters)
- Downloadable templates and worked examples for every module
- Hand-built implementation playbook delivered alongside course access
- 30-day money-back guarantee
Delivery and format
- Course and learning environment access provisioned within 24 hours of purchase
- Hand-built implementation playbook delivered alongside course access
Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access.
Time investment: Approximately 3-4 hours per module, designed for completion over 6-8 weeks with flexibility to pause and resume.
How this compares to the alternatives
Unlike generic compliance courses, this focuses exclusively on SOC 2 execution in enterprise IT services firms, with templates and examples tailored for organizations like CGI. No other course combines technical depth with practical lifecycle ownership.
Frequently asked
Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.