SECURITY PRACTISES YOU CAN REVIEW
How N.O. IT Strategy Aligns with SOC 2 Principels
I use the SOC 2 Trust Services Criteria as a practical guide for protecting client information, managing access, selecting vendors, responding to incidents and using AI responsibly. This page explains the safeguards and operating practices built into how I work so clients can evaluate them clearly before sharing confidential information.
VENDOR DUE DILIGENCE
SOC 2 Alignment
If your firm is subject to the FTC Safeguards Rule, vendor oversight is part of your information security program. Here is my answer.
Covered firms are expected to evaluate whether service providers can appropriately safeguard customer information, put those expectations into contracts, monitor their work, and periodically reassess the relationship. That includes consultants who may access your systems or handle information on your behalf.
Most solo consultants make you ask for this information one question at a time. I would rather put it in writing before you have to ask.
Transparency Matters
N.O. IT Strategy has not undergone an independent SOC 2 examination. I do not claim to be SOC 2 certified, and this page is not a substitute for an independent CPA’s examination or assurance report.
What I can say is that I use the AICPA Trust Services Criteria as a reference when designing and reviewing the internal controls for my practice. Those criteria address security, availability, processing integrity, confidentiality, and privacy.
This is a self-assessed alignment statement. No independent CPA has tested the design or operating effectiveness of the controls described here.
If your vendor-management policy requires an audited SOC 2 report, I will tell you plainly that I do not have one. I can provide the documentation your firm needs to evaluate the relationship and support its own risk-based exception process. The decision to accept that exception belongs to your firm.
What “SOC 2 aligned” means here; I have mapped relevant internal practices to the Trust Services Criteria. It does not mean that N.O. IT Strategy has received a SOC 2 report, certification, attestation, or independent validation.
TRUST SERVICES CRITERIA
How My Controls Map to SOC 2
Security
Systems used to access or store client information are protected through access controls, multi-factor authentication, endpoint security, patch management, security logging, and ongoing monitoring.
Access is limited to the accounts, systems, and information needed to perform the engagement. Administrative access is separated from ordinary daily use where practical, and security events are reviewed and investigated.
Confidentiality
Client information is used only to perform the agreed engagement and operate the professional relationship.
I do not sell client information. I do not disclose it to outside parties except approved service providers needed to operate, support, or secure my business, when permitted by the engagement agreement, or when required by law.
Confidential information is stored in access-controlled systems and protected during transmission. I will sign a mutual or client-provided nondisclosure agreement when requested.
Detailed security information may be provided under NDA when publishing it openly would create unnecessary risk.
Availability
Client engagement records are maintained in systems designed to protect against device failure, accidental deletion, and loss of a single endpoint.
Version history and backup controls help ensure that the loss or failure of my primary computer does not mean the loss of the engagement record
Processing integrity
N.O. IT Strategy provides assessments, plans, recommendations, and advisory services. I do not process customer transactions on behalf of clients, so this criterion has a narrower application to my services.
Findings and recommendations are tied to documented evidence, interviews, observed conditions, and clearly identified assumptions. Deliverables are reviewed before release, and material revisions are versioned so the client can distinguish the current document from an earlier draft.
I remain responsible for the accuracy and professional judgment reflected in the final deliverable, including when supporting tools are used during its preparation.
Privacy
I collect only the client and engagement information reasonably needed to perform the work, communicate with the client, maintain business records, and meet legal, contractual, insurance, and professional obligations.
Client-provided working files are deleted when they are no longer required, subject to the documented retention schedule and any legal or contractual reason to retain them. Information scheduled for disposal is deleted or destroyed using methods appropriate to its sensitivity.
I do not use client information for unrelated advertising, sell it to data brokers, or build marketing profiles from confidential engagement information.
RESPONSIBLE AI USE
How I Use Artificial Intelligence
I maintain a written standard governing the use of artificial intelligence in my practice.
Client personally identifiable information, protected health information, tax records, credentials, authentication details, and unredacted confidential source documents are not uploaded to general-purpose AI tools.
When AI supports research, organization, or drafting, I minimize the information provided, use approved accounts and available privacy controls, independently verify the result, and remain responsible for the final work. AI does not make final risk decisions, approve findings, or replace my professional judgment.
If your firm has a stricter AI-use policy for service providers, I will review it before the engagement and work within the agreed restrictions.
INCIDENT PREPAREDNESS
How I Respond to Security Incidents
I maintain a written incident response plan addressing detection, containment, evidence preservation, investigation, communication, recovery, and post-incident review.
If a confirmed security incident affects information entrusted to N.O. IT Strategy, I will contact the affected client directly in accordance with the notification terms in our agreement and applicable law.
I will not wait for the client to discover the incident through a third party or public report.
VENDOR-NEUTRAL ADVICE
Independent by Design
I do not sell hardware, software licenses, managed services, or security products. I do not accept vendor commissions for recommending one provider over another.
Recommendations are based on the client’s needs, risks, current environment, financial priorities, and operational requirements. If a vendor relationship or referral arrangement could create a conflict, I will disclose it.
Vendor neutrality does not eliminate the need for professional judgment, but it removes the financial incentive to recommend a product simply because I profit from the sale.
DUE-DILIGENCE DOCUMENTS
What Your Firm Can Request
The following due-diligence materials are available upon request:
- Certificate of insurance
- Form W-9
- Signed nondisclosure agreement
- Security and data-handling summary
- AI-use and AI-handling summary
- Incident response plan summary
- Relevant professional references
- Additional control information appropriate to the proposed engagement
Some documents may require a signed NDA before release because they contain information about internal security controls.
You can request these documents through the Trust Center page, and I will respond within two business days.
GOVERNANCE IN PRACTICE
I Hold My Practice to the Same Standard
I help CPAs, bookkeeping firms, attorneys and other businesses build information security programs, assess risk, oversee service providers, and document safeguards.
Publishing my own controls is not a claim that risk has been eliminated. It is the same governance discipline I would expect you to require from any vendor with access to your systems or information.
If one of your current providers cannot clearly explain how it protects your information, who can access it, how incidents are handled, or what happens when the relationship ends, that is worth a conversation.