← All templates

Jira task template

SOC2 Type II Audit Prep — Annual Compliance

Complete audit preparation from scoping through report delivery. Every control a real compliance team tracks.

Issues created:
187
Structure:
1 epic · 32 tasks · 154 subtasks
Roles:
compliance_lead, security_engineer, vendor_manager, ciso, legal, it_admin, hr_director, devops, eng_lead

The full task tree this template creates

Copy it, paste it into the SuperTemplates editor, and Smart Replace turns every marker into a typed Jira field.

[#epic] SOC2 Type II Audit Prep — Annual Compliance !Highest @compliance_lead
  [#task] Audit Scoping & Engagement !Highest @compliance_lead [Due + 0d]
    [#subtask] Define in-scope systems and services @security_engineer !High [Due + 1d]
    [#subtask] Map data flows between in-scope systems @security_engineer !High [Due + 2d]
    [#subtask] Document third-party integrations in scope @vendor_manager !High [Due + 2d]
    [#subtask] Select Trust Service Criteria with leadership @ciso !High [Due + 3d]
    [#subtask] Define audit period start and end dates @compliance_lead !Highest [Due + 1d]
  [#task] External Auditor Engagement !Highest @compliance_lead [Due + 5d]
    [#subtask] Request proposals from qualified audit firms @compliance_lead !High [Due + 3d]
    [#subtask] Evaluate auditor qualifications and references @ciso !Medium [Due + 4d]
    [#subtask] Negotiate and execute engagement letter @legal !High [Due + 7d]
  [#task] Readiness Assessment !High @compliance_lead [Due + 10d]
    [#subtask] Gap analysis against SOC2 criteria @compliance_lead !High [Due + 8d]
    [#subtask] Review prior year findings and remediation @compliance_lead !High [Due + 9d]
    [#subtask] Assess current control maturity levels @security_engineer !Medium [Due + 10d]
    [#subtask] Build prioritized risk register @compliance_lead !High [Due + 11d]
  [#task] Audit Project Setup !High @compliance_lead [Due + 7d]
    [#subtask] Create shared evidence repository @it_admin !Medium [Due + 5d]
    [#subtask] Assign control owners across departments @compliance_lead !Highest [Due + 6d]
    [#subtask] Distribute evidence request list to owners @compliance_lead !High [Due + 8d]
    [#subtask] Schedule kickoff with all stakeholders @compliance_lead !High [Due + 7d]
  [#task] Information Security Policy Review !High @ciso [Due + 14d]
    [#subtask] Update Information Security Policy @ciso !High [Due + 15d]
    [#subtask] Review Acceptable Use Policy @ciso !Medium [Due + 16d]
    [#subtask] Update Data Classification Policy @compliance_lead !High [Due + 17d]
    [#subtask] Review Code of Conduct and Ethics Policy @hr_director !Medium [Due + 16d]
    [#subtask] Update Incident Response Policy @security_engineer !High [Due + 18d]
    [#subtask] Review Business Continuity Policy @ciso !Medium [Due + 19d]
  [#task] Risk Management Framework (CC3) !High @compliance_lead [Due + 21d]
    [#subtask] Update enterprise risk assessment @compliance_lead !High [Due + 19d]
    [#subtask] Document risk appetite and tolerance levels @ciso !Medium [Due + 20d]
    [#subtask] Identify and assess fraud risk scenarios @compliance_lead !High [Due + 21d]
    [#subtask] Review risk mitigation strategies and owners @compliance_lead !High [Due + 22d]
  [#task] Communication & Information Controls (CC2) !Medium @compliance_lead [Due + 25d]
    [#subtask] Verify internal security communication channels @compliance_lead !Medium [Due + 23d]
    [#subtask] Review external communication procedures @legal !Medium [Due + 24d]
    [#subtask] Document whistleblower and reporting mechanisms @hr_director !Medium [Due + 25d]
    [#subtask] Verify board and management oversight reporting @ciso !Medium [Due + 26d]
  [#task] User Access Management (CC6) !Highest @it_admin [Due + 21d]
    [#subtask] Audit user access lists for all in-scope systems @it_admin !Highest [Due + 22d]
    [#subtask] Verify RBAC configuration across systems @it_admin !High [Due + 23d]
    [#subtask] Remove terminated user accounts @it_admin !Highest [Due + 22d]
    [#subtask] Validate access provisioning workflow @it_admin !High [Due + 24d]
    [#subtask] Document access de-provisioning SLA @it_admin !High [Due + 25d]
    [#subtask] Review privileged access accounts @security_engineer !Highest [Due + 23d]
    [#subtask] Verify least-privilege enforcement @security_engineer !High [Due + 26d]
  [#task] Authentication Controls !High @security_engineer [Due + 28d]
    [#subtask] Verify MFA on all in-scope systems @security_engineer !Highest [Due + 26d]
    [#subtask] Review password policy configuration @it_admin !High [Due + 27d]
    [#subtask] Audit SSO provider settings @it_admin !High [Due + 28d]
    [#subtask] Review service account credential rotation @devops !High [Due + 29d]
    [#subtask] Verify session timeout and lockout policies @security_engineer !Medium [Due + 28d]
  [#task] Physical Access Controls !Medium @it_admin [Due + 30d]
    [#subtask] Review data center physical access logs @it_admin !Medium [Due + 28d]
    [#subtask] Verify badge access system configuration @it_admin !Medium [Due + 29d]
    [#subtask] Audit visitor access procedures @it_admin !Low [Due + 30d]
    [#subtask] Review environmental controls (HVAC, fire, flood) @it_admin !Medium [Due + 31d]
  [#task] Network Security Controls !High @security_engineer [Due + 35d]
    [#subtask] Review firewall rules and configurations @devops !High [Due + 33d]
    [#subtask] Verify network segmentation between environments @devops !High [Due + 34d]
    [#subtask] Audit VPN access configuration and logs @security_engineer !High [Due + 35d]
    [#subtask] Review IDS/IPS system configuration @security_engineer !High [Due + 36d]
    [#subtask] Verify WAF rules and configuration @devops !High [Due + 35d]
  [#task] Encryption Controls !High @security_engineer [Due + 38d]
    [#subtask] Verify encryption at rest for all databases @devops !Highest [Due + 36d]
    [#subtask] Verify TLS configuration for data in transit @devops !High [Due + 37d]
    [#subtask] Audit encryption key management procedures @security_engineer !High [Due + 38d]
    [#subtask] Review certificate management and expiry tracking @devops !Medium [Due + 39d]
  [#task] Cloud Infrastructure Security !High @devops [Due + 40d]
    [#subtask] Review cloud IAM policies and roles @devops !High [Due + 38d]
    [#subtask] Audit security groups and network ACLs @devops !High [Due + 39d]
    [#subtask] Verify cloud audit logging enabled @devops !High [Due + 40d]
    [#subtask] Review cloud storage bucket permissions @devops !Highest [Due + 38d]
    [#subtask] Validate infrastructure-as-code security scanning @devops !Medium [Due + 41d]
  [#task] Secure Development Lifecycle (CC8) !High @eng_lead [Due + 42d]
    [#subtask] Review SDLC policy documentation @eng_lead !High [Due + 40d]
    [#subtask] Verify mandatory code review process @eng_lead !High [Due + 41d]
    [#subtask] Audit branch protection rules @devops !High [Due + 41d]
    [#subtask] Review SAST tool configuration and results @security_engineer !High [Due + 42d]
    [#subtask] Verify dependency vulnerability scanning @devops !High [Due + 42d]
    [#subtask] Review secure coding training records @eng_lead !Medium [Due + 43d]
  [#task] Change Management Controls !Highest @eng_lead [Due + 46d]
    [#subtask] Review change approval workflow documentation @eng_lead !High [Due + 44d]
    [#subtask] Audit sample change tickets for proper approval @compliance_lead !Highest [Due + 45d]
    [#subtask] Verify separation of duties (dev vs deploy) @devops !High [Due + 45d]
    [#subtask] Review emergency change procedures @eng_lead !High [Due + 46d]
    [#subtask] Validate rollback procedures and testing @devops !Medium [Due + 47d]
  [#task] Release & Deployment Controls !High @devops [Due + 49d]
    [#subtask] Review CI/CD pipeline security controls @devops !High [Due + 47d]
    [#subtask] Verify production deployment approval gates @devops !High [Due + 48d]
    [#subtask] Audit deployment logs for unauthorized changes @security_engineer !High [Due + 49d]
    [#subtask] Review environment separation (dev/staging/prod) @devops !High [Due + 48d]
  [#task] Logging & Monitoring (CC7) !Highest @devops [Due + 49d]
    [#subtask] Verify centralized log aggregation system @devops !High [Due + 47d]
    [#subtask] Review log retention policy compliance @compliance_lead !High [Due + 48d]
    [#subtask] Audit alerting rules for security events @security_engineer !High [Due + 49d]
    [#subtask] Verify application-level audit logging @eng_lead !High [Due + 50d]
    [#subtask] Review monitoring dashboards for system health @devops !Medium [Due + 49d]
    [#subtask] Test log tamper-protection mechanisms @security_engineer !High [Due + 51d]
  [#task] Vulnerability Management !Highest @security_engineer [Due + 53d]
    [#subtask] Review vulnerability scanning tools and schedule @security_engineer !High [Due + 50d]
    [#subtask] Audit vulnerability remediation SLAs @security_engineer !High [Due + 51d]
    [#subtask] Verify critical patching within SLA @devops !Highest [Due + 52d]
    [#subtask] Review penetration test reports and remediation @security_engineer !High [Due + 53d]
    [#subtask] Document risk acceptances with justification @ciso !Medium [Due + 54d]
  [#task] Incident Response Procedures !Highest @security_engineer [Due + 56d]
    [#subtask] Review incident response plan documentation @security_engineer !High [Due + 53d]
    [#subtask] Verify incident classification and severity matrix @security_engineer !High [Due + 54d]
    [#subtask] Audit IR team roles and escalation contacts @compliance_lead !High [Due + 55d]
    [#subtask] Review incident communication templates @compliance_lead !Medium [Due + 55d]
    [#subtask] Conduct tabletop incident response exercise @security_engineer !High [Due + 56d]
    [#subtask] Review post-incident review process @security_engineer !Medium [Due + 57d]
  [#task] Employee Lifecycle Security (CC1) !High @hr_director [Due + 35d]
    [#subtask] Review background check policy and records @hr_director !High [Due + 33d]
    [#subtask] Verify employment agreement security clauses @legal !High [Due + 34d]
    [#subtask] Review NDA and confidentiality agreement coverage @legal !High [Due + 35d]
    [#subtask] Audit new hire security training completion @hr_director !High [Due + 36d]
    [#subtask] Verify offboarding checklist and access revocation @hr_director !Highest [Due + 36d]
  [#task] Security Awareness Training !High @compliance_lead [Due + 42d]
    [#subtask] Review annual security awareness training program @compliance_lead !High [Due + 38d]
    [#subtask] Verify training completion rates @hr_director !High [Due + 39d]
    [#subtask] Review phishing simulation results and trends @security_engineer !Medium [Due + 40d]
    [#subtask] Audit role-specific security training records @hr_director !Medium [Due + 41d]
    [#subtask] Document training exceptions and remediation @compliance_lead !Medium [Due + 42d]
  [#task] Vendor Inventory & Classification (CC9) !High @vendor_manager [Due + 42d]
    [#subtask] Update inventory of all third-party vendors @vendor_manager !High [Due + 40d]
    [#subtask] Classify vendors by data access and criticality @vendor_manager !High [Due + 41d]
    [#subtask] Verify vendor SOC2/ISO reports are current @compliance_lead !Highest [Due + 42d]
    [#subtask] Flag vendors without compliance certifications @compliance_lead !High [Due + 43d]
  [#task] Vendor Risk Assessment !High @vendor_manager [Due + 49d]
    [#subtask] Complete risk assessments for critical vendors @vendor_manager !High [Due + 45d]
    [#subtask] Review vendor security questionnaire responses @security_engineer !High [Due + 46d]
    [#subtask] Assess vendor incident notification procedures @compliance_lead !Medium [Due + 47d]
    [#subtask] Document vendor risk acceptance decisions @ciso !Medium [Due + 48d]
  [#task] Vendor Contract Review !High @legal [Due + 52d]
    [#subtask] Review data processing agreements (DPAs) @legal !High [Due + 49d]
    [#subtask] Verify breach notification clauses @legal !High [Due + 50d]
    [#subtask] Audit vendor SLA compliance @vendor_manager !Medium [Due + 51d]
  [#task] Business Continuity Planning (A1) !High @ciso [Due + 56d]
    [#subtask] Review BCP documentation @ciso !High [Due + 54d]
    [#subtask] Verify RTO for critical systems @devops !High [Due + 55d]
    [#subtask] Verify RPO configuration @devops !High [Due + 55d]
    [#subtask] Conduct BCP tabletop exercise @ciso !High [Due + 56d]
    [#subtask] Document BCP test results and lessons learned @compliance_lead !Medium [Due + 58d]
  [#task] Backup & Disaster Recovery !High @devops [Due + 60d]
    [#subtask] Verify automated backup schedules for all databases @devops !High [Due + 57d]
    [#subtask] Test backup restoration procedure @devops !Highest [Due + 58d]
    [#subtask] Review disaster recovery runbooks @devops !High [Due + 59d]
    [#subtask] Verify cross-region replication @devops !High [Due + 59d]
    [#subtask] Conduct failover test to DR environment @devops !High [Due + 60d]
  [#task] Data Classification & Handling (C1) !High @compliance_lead [Due + 56d]
    [#subtask] Review data classification schema and labels @compliance_lead !High [Due + 54d]
    [#subtask] Audit data handling procedures by classification @compliance_lead !High [Due + 55d]
    [#subtask] Verify data retention and disposal schedules @legal !High [Due + 56d]
    [#subtask] Review DLP tool configuration and alerts @security_engineer !High [Due + 57d]
    [#subtask] Audit data access request and approval process @compliance_lead !Medium [Due + 57d]
  [#task] Privacy Controls (P1) !High @legal [Due + 60d]
    [#subtask] Review privacy policy and notice accuracy @legal !High [Due + 58d]
    [#subtask] Verify consent management mechanisms @eng_lead !High [Due + 59d]
    [#subtask] Audit DSAR process @legal !High [Due + 60d]
    [#subtask] Review PII inventory and data mapping @compliance_lead !High [Due + 60d]
    [#subtask] Verify data anonymization controls @eng_lead !Medium [Due + 61d]
  [#task] Critical Gap Remediation !Highest @compliance_lead [Due + 77d]
    [#subtask] Remediate access control findings @it_admin !Highest [Due + 80d]
    [#subtask] Remediate policy documentation gaps @compliance_lead !High [Due + 82d]
    [#subtask] Remediate monitoring and alerting gaps @devops !High [Due + 84d]
    [#subtask] Implement missing vendor risk assessments @vendor_manager !High [Due + 84d]
    [#subtask] Remediate change management findings @eng_lead !High [Due + 86d]
    [#subtask] Verify all remediation items resolved @compliance_lead !Highest [Due + 90d]
  [#task] Evidence Package Finalization !Highest @compliance_lead [Due + 95d]
    [#subtask] Compile evidence artifacts per control objective @compliance_lead !High [Due + 88d]
    [#subtask] Cross-reference evidence to Trust Service Criteria @compliance_lead !High [Due + 90d]
    [#subtask] Review evidence completeness with control owners @compliance_lead !High [Due + 92d]
    [#subtask] Prepare management assertion letter draft @ciso !High [Due + 93d]
    [#subtask] Quality review of full evidence package @compliance_lead !Highest [Due + 95d]
  [#task] Auditor Fieldwork Support !Highest @compliance_lead [Due + 98d]
    [#subtask] Host auditor kickoff and walkthrough sessions @compliance_lead !High [Due + 98d]
    [#subtask] Respond to auditor evidence requests within SLA @compliance_lead !Highest [Due + 105d]
    [#subtask] Coordinate auditor interviews with control owners @compliance_lead !High [Due + 103d]
    [#subtask] Track and resolve auditor inquiries @compliance_lead !High [Due + 108d]
  [#task] Report Review & Closeout !Highest @ciso [Due + 115d]
    [#subtask] Review draft SOC2 report for accuracy @compliance_lead !Highest [Due + 110d]
    [#subtask] Address reported exceptions with auditor @compliance_lead !High [Due + 112d]
    [#subtask] Obtain management sign-off on final report @ciso !Highest [Due + 114d]
    [#subtask] Distribute SOC2 report to stakeholders @compliance_lead !High [Due + 116d]
    [#subtask] Create remediation plan for any exceptions @compliance_lead !High [Due + 118d]
    [#subtask] Schedule lessons-learned retrospective @compliance_lead !Medium [Due + 120d]

How to use this template in Jira

  1. Install SuperTemplates from the Atlassian Marketplace (free 14-day trial) and open the editor in any Jira project.
  2. Copy the tree above, paste it into the editor, and run Smart Replace — assignees, priorities, and date offsets resolve against your live Jira data.
  3. Preview the whole batch and create everything in Jira in one click. Nothing is created until you confirm.

Related templates

  • Incident Response — SEV1 Production Outage Structured incident response from detection through post-mortem. Every task a real on-call engineer performs during a production incident.
  • Monthly Patch Deployment ITIL-aligned patch management cycle with testing, approval, and phased production deployment. Every task a real IT ops engineer performs.
  • ITIL Change Management Standard change request workflow from submission through CAB approval, implementation, and post-implementation review. Every task maps to real ITIL processes.