← All templates

Jira task template

SOC2 Type II Audit Prep — Annual Compliance

Complete audit preparation from scoping through report delivery. Every control a real compliance team tracks.

Issues created:
187
Structure:
1 epic · 32 tasks · 154 subtasks
Roles:
compliance_lead, security_engineer, vendor_manager, ciso, legal, it_admin, hr_director, devops, eng_lead

The full task tree this template creates

Copy it, paste it into the SuperTemplates editor, and Smart Replace turns every marker into a typed Jira field.

[#epic] SOC2 Type II Audit Prep — Annual Compliance !Highest @compliance_lead
  [#task] Audit Scoping & Engagement !Highest @compliance_lead [Due + 0d]
    [#subtask] Define in-scope systems and services @security_engineer !High [Due + 1d]
    [#subtask] Map data flows between in-scope systems @security_engineer !High [Due + 2d]
    [#subtask] Document third-party integrations in scope @vendor_manager !High [Due + 2d]
    [#subtask] Select Trust Service Criteria with leadership @ciso !High [Due + 3d]
    [#subtask] Define audit period start and end dates @compliance_lead !Highest [Due + 1d]
  [#task] External Auditor Engagement !Highest @compliance_lead [Due + 5d]
    [#subtask] Request proposals from qualified audit firms @compliance_lead !High [Due + 3d]
    [#subtask] Evaluate auditor qualifications and references @ciso !Medium [Due + 4d]
    [#subtask] Negotiate and execute engagement letter @legal !High [Due + 7d]
  [#task] Readiness Assessment !High @compliance_lead [Due + 10d]
    [#subtask] Gap analysis against SOC2 criteria @compliance_lead !High [Due + 8d]
    [#subtask] Review prior year findings and remediation @compliance_lead !High [Due + 9d]
    [#subtask] Assess current control maturity levels @security_engineer !Medium [Due + 10d]
    [#subtask] Build prioritized risk register @compliance_lead !High [Due + 11d]
  [#task] Audit Project Setup !High @compliance_lead [Due + 7d]
    [#subtask] Create shared evidence repository @it_admin !Medium [Due + 5d]
    [#subtask] Assign control owners across departments @compliance_lead !Highest [Due + 6d]
    [#subtask] Distribute evidence request list to owners @compliance_lead !High [Due + 8d]
    [#subtask] Schedule kickoff with all stakeholders @compliance_lead !High [Due + 7d]
  [#task] Information Security Policy Review !High @ciso [Due + 14d]
    [#subtask] Update Information Security Policy @ciso !High [Due + 15d]
    [#subtask] Review Acceptable Use Policy @ciso !Medium [Due + 16d]
    [#subtask] Update Data Classification Policy @compliance_lead !High [Due + 17d]
    [#subtask] Review Code of Conduct and Ethics Policy @hr_director !Medium [Due + 16d]
    [#subtask] Update Incident Response Policy @security_engineer !High [Due + 18d]
    [#subtask] Review Business Continuity Policy @ciso !Medium [Due + 19d]
  [#task] Risk Management Framework (CC3) !High @compliance_lead [Due + 21d]
    [#subtask] Update enterprise risk assessment @compliance_lead !High [Due + 19d]
    [#subtask] Document risk appetite and tolerance levels @ciso !Medium [Due + 20d]
    [#subtask] Identify and assess fraud risk scenarios @compliance_lead !High [Due + 21d]
    [#subtask] Review risk mitigation strategies and owners @compliance_lead !High [Due + 22d]
  [#task] Communication & Information Controls (CC2) !Medium @compliance_lead [Due + 25d]
    [#subtask] Verify internal security communication channels @compliance_lead !Medium [Due + 23d]
    [#subtask] Review external communication procedures @legal !Medium [Due + 24d]
    [#subtask] Document whistleblower and reporting mechanisms @hr_director !Medium [Due + 25d]
    [#subtask] Verify board and management oversight reporting @ciso !Medium [Due + 26d]
  [#task] User Access Management (CC6) !Highest @it_admin [Due + 21d]
    [#subtask] Audit user access lists for all in-scope systems @it_admin !Highest [Due + 22d]
    [#subtask] Verify RBAC configuration across systems @it_admin !High [Due + 23d]
    [#subtask] Remove terminated user accounts @it_admin !Highest [Due + 22d]
    [#subtask] Validate access provisioning workflow @it_admin !High [Due + 24d]
    [#subtask] Document access de-provisioning SLA @it_admin !High [Due + 25d]
    [#subtask] Review privileged access accounts @security_engineer !Highest [Due + 23d]
    [#subtask] Verify least-privilege enforcement @security_engineer !High [Due + 26d]
  [#task] Authentication Controls !High @security_engineer [Due + 28d]
    [#subtask] Verify MFA on all in-scope systems @security_engineer !Highest [Due + 26d]
    [#subtask] Review password policy configuration @it_admin !High [Due + 27d]
    [#subtask] Audit SSO provider settings @it_admin !High [Due + 28d]
    [#subtask] Review service account credential rotation @devops !High [Due + 29d]
    [#subtask] Verify session timeout and lockout policies @security_engineer !Medium [Due + 28d]
  [#task] Physical Access Controls !Medium @it_admin [Due + 30d]
    [#subtask] Review data center physical access logs @it_admin !Medium [Due + 28d]
    [#subtask] Verify badge access system configuration @it_admin !Medium [Due + 29d]
    [#subtask] Audit visitor access procedures @it_admin !Low [Due + 30d]
    [#subtask] Review environmental controls (HVAC, fire, flood) @it_admin !Medium [Due + 31d]
  [#task] Network Security Controls !High @security_engineer [Due + 35d]
    [#subtask] Review firewall rules and configurations @devops !High [Due + 33d]
    [#subtask] Verify network segmentation between environments @devops !High [Due + 34d]
    [#subtask] Audit VPN access configuration and logs @security_engineer !High [Due + 35d]
    [#subtask] Review IDS/IPS system configuration @security_engineer !High [Due + 36d]
    [#subtask] Verify WAF rules and configuration @devops !High [Due + 35d]
  [#task] Encryption Controls !High @security_engineer [Due + 38d]
    [#subtask] Verify encryption at rest for all databases @devops !Highest [Due + 36d]
    [#subtask] Verify TLS configuration for data in transit @devops !High [Due + 37d]
    [#subtask] Audit encryption key management procedures @security_engineer !High [Due + 38d]
    [#subtask] Review certificate management and expiry tracking @devops !Medium [Due + 39d]
  [#task] Cloud Infrastructure Security !High @devops [Due + 40d]
    [#subtask] Review cloud IAM policies and roles @devops !High [Due + 38d]
    [#subtask] Audit security groups and network ACLs @devops !High [Due + 39d]
    [#subtask] Verify cloud audit logging enabled @devops !High [Due + 40d]
    [#subtask] Review cloud storage bucket permissions @devops !Highest [Due + 38d]
    [#subtask] Validate infrastructure-as-code security scanning @devops !Medium [Due + 41d]
  [#task] Secure Development Lifecycle (CC8) !High @eng_lead [Due + 42d]
    [#subtask] Review SDLC policy documentation @eng_lead !High [Due + 40d]
    [#subtask] Verify mandatory code review process @eng_lead !High [Due + 41d]
    [#subtask] Audit branch protection rules @devops !High [Due + 41d]
    [#subtask] Review SAST tool configuration and results @security_engineer !High [Due + 42d]
    [#subtask] Verify dependency vulnerability scanning @devops !High [Due + 42d]
    [#subtask] Review secure coding training records @eng_lead !Medium [Due + 43d]
  [#task] Change Management Controls !Highest @eng_lead [Due + 46d]
    [#subtask] Review change approval workflow documentation @eng_lead !High [Due + 44d]
    [#subtask] Audit sample change tickets for proper approval @compliance_lead !Highest [Due + 45d]
    [#subtask] Verify separation of duties (dev vs deploy) @devops !High [Due + 45d]
    [#subtask] Review emergency change procedures @eng_lead !High [Due + 46d]
    [#subtask] Validate rollback procedures and testing @devops !Medium [Due + 47d]
  [#task] Release & Deployment Controls !High @devops [Due + 49d]
    [#subtask] Review CI/CD pipeline security controls @devops !High [Due + 47d]
    [#subtask] Verify production deployment approval gates @devops !High [Due + 48d]
    [#subtask] Audit deployment logs for unauthorized changes @security_engineer !High [Due + 49d]
    [#subtask] Review environment separation (dev/staging/prod) @devops !High [Due + 48d]
  [#task] Logging & Monitoring (CC7) !Highest @devops [Due + 49d]
    [#subtask] Verify centralized log aggregation system @devops !High [Due + 47d]
    [#subtask] Review log retention policy compliance @compliance_lead !High [Due + 48d]
    [#subtask] Audit alerting rules for security events @security_engineer !High [Due + 49d]
    [#subtask] Verify application-level audit logging @eng_lead !High [Due + 50d]
    [#subtask] Review monitoring dashboards for system health @devops !Medium [Due + 49d]
    [#subtask] Test log tamper-protection mechanisms @security_engineer !High [Due + 51d]
  [#task] Vulnerability Management !Highest @security_engineer [Due + 53d]
    [#subtask] Review vulnerability scanning tools and schedule @security_engineer !High [Due + 50d]
    [#subtask] Audit vulnerability remediation SLAs @security_engineer !High [Due + 51d]
    [#subtask] Verify critical patching within SLA @devops !Highest [Due + 52d]
    [#subtask] Review penetration test reports and remediation @security_engineer !High [Due + 53d]
    [#subtask] Document risk acceptances with justification @ciso !Medium [Due + 54d]
  [#task] Incident Response Procedures !Highest @security_engineer [Due + 56d]
    [#subtask] Review incident response plan documentation @security_engineer !High [Due + 53d]
    [#subtask] Verify incident classification and severity matrix @security_engineer !High [Due + 54d]
    [#subtask] Audit IR team roles and escalation contacts @compliance_lead !High [Due + 55d]
    [#subtask] Review incident communication templates @compliance_lead !Medium [Due + 55d]
    [#subtask] Conduct tabletop incident response exercise @security_engineer !High [Due + 56d]
    [#subtask] Review post-incident review process @security_engineer !Medium [Due + 57d]
  [#task] Employee Lifecycle Security (CC1) !High @hr_director [Due + 35d]
    [#subtask] Review background check policy and records @hr_director !High [Due + 33d]
    [#subtask] Verify employment agreement security clauses @legal !High [Due + 34d]
    [#subtask] Review NDA and confidentiality agreement coverage @legal !High [Due + 35d]
    [#subtask] Audit new hire security training completion @hr_director !High [Due + 36d]
    [#subtask] Verify offboarding checklist and access revocation @hr_director !Highest [Due + 36d]
  [#task] Security Awareness Training !High @compliance_lead [Due + 42d]
    [#subtask] Review annual security awareness training program @compliance_lead !High [Due + 38d]
    [#subtask] Verify training completion rates @hr_director !High [Due + 39d]
    [#subtask] Review phishing simulation results and trends @security_engineer !Medium [Due + 40d]
    [#subtask] Audit role-specific security training records @hr_director !Medium [Due + 41d]
    [#subtask] Document training exceptions and remediation @compliance_lead !Medium [Due + 42d]
  [#task] Vendor Inventory & Classification (CC9) !High @vendor_manager [Due + 42d]
    [#subtask] Update inventory of all third-party vendors @vendor_manager !High [Due + 40d]
    [#subtask] Classify vendors by data access and criticality @vendor_manager !High [Due + 41d]
    [#subtask] Verify vendor SOC2/ISO reports are current @compliance_lead !Highest [Due + 42d]
    [#subtask] Flag vendors without compliance certifications @compliance_lead !High [Due + 43d]
  [#task] Vendor Risk Assessment !High @vendor_manager [Due + 49d]
    [#subtask] Complete risk assessments for critical vendors @vendor_manager !High [Due + 45d]
    [#subtask] Review vendor security questionnaire responses @security_engineer !High [Due + 46d]
    [#subtask] Assess vendor incident notification procedures @compliance_lead !Medium [Due + 47d]
    [#subtask] Document vendor risk acceptance decisions @ciso !Medium [Due + 48d]
  [#task] Vendor Contract Review !High @legal [Due + 52d]
    [#subtask] Review data processing agreements (DPAs) @legal !High [Due + 49d]
    [#subtask] Verify breach notification clauses @legal !High [Due + 50d]
    [#subtask] Audit vendor SLA compliance @vendor_manager !Medium [Due + 51d]
  [#task] Business Continuity Planning (A1) !High @ciso [Due + 56d]
    [#subtask] Review BCP documentation @ciso !High [Due + 54d]
    [#subtask] Verify RTO for critical systems @devops !High [Due + 55d]
    [#subtask] Verify RPO configuration @devops !High [Due + 55d]
    [#subtask] Conduct BCP tabletop exercise @ciso !High [Due + 56d]
    [#subtask] Document BCP test results and lessons learned @compliance_lead !Medium [Due + 58d]
  [#task] Backup & Disaster Recovery !High @devops [Due + 60d]
    [#subtask] Verify automated backup schedules for all databases @devops !High [Due + 57d]
    [#subtask] Test backup restoration procedure @devops !Highest [Due + 58d]
    [#subtask] Review disaster recovery runbooks @devops !High [Due + 59d]
    [#subtask] Verify cross-region replication @devops !High [Due + 59d]
    [#subtask] Conduct failover test to DR environment @devops !High [Due + 60d]
  [#task] Data Classification & Handling (C1) !High @compliance_lead [Due + 56d]
    [#subtask] Review data classification schema and labels @compliance_lead !High [Due + 54d]
    [#subtask] Audit data handling procedures by classification @compliance_lead !High [Due + 55d]
    [#subtask] Verify data retention and disposal schedules @legal !High [Due + 56d]
    [#subtask] Review DLP tool configuration and alerts @security_engineer !High [Due + 57d]
    [#subtask] Audit data access request and approval process @compliance_lead !Medium [Due + 57d]
  [#task] Privacy Controls (P1) !High @legal [Due + 60d]
    [#subtask] Review privacy policy and notice accuracy @legal !High [Due + 58d]
    [#subtask] Verify consent management mechanisms @eng_lead !High [Due + 59d]
    [#subtask] Audit DSAR process @legal !High [Due + 60d]
    [#subtask] Review PII inventory and data mapping @compliance_lead !High [Due + 60d]
    [#subtask] Verify data anonymization controls @eng_lead !Medium [Due + 61d]
  [#task] Critical Gap Remediation !Highest @compliance_lead [Due + 77d]
    [#subtask] Remediate access control findings @it_admin !Highest [Due + 80d]
    [#subtask] Remediate policy documentation gaps @compliance_lead !High [Due + 82d]
    [#subtask] Remediate monitoring and alerting gaps @devops !High [Due + 84d]
    [#subtask] Implement missing vendor risk assessments @vendor_manager !High [Due + 84d]
    [#subtask] Remediate change management findings @eng_lead !High [Due + 86d]
    [#subtask] Verify all remediation items resolved @compliance_lead !Highest [Due + 90d]
  [#task] Evidence Package Finalization !Highest @compliance_lead [Due + 95d]
    [#subtask] Compile evidence artifacts per control objective @compliance_lead !High [Due + 88d]
    [#subtask] Cross-reference evidence to Trust Service Criteria @compliance_lead !High [Due + 90d]
    [#subtask] Review evidence completeness with control owners @compliance_lead !High [Due + 92d]
    [#subtask] Prepare management assertion letter draft @ciso !High [Due + 93d]
    [#subtask] Quality review of full evidence package @compliance_lead !Highest [Due + 95d]
  [#task] Auditor Fieldwork Support !Highest @compliance_lead [Due + 98d]
    [#subtask] Host auditor kickoff and walkthrough sessions @compliance_lead !High [Due + 98d]
    [#subtask] Respond to auditor evidence requests within SLA @compliance_lead !Highest [Due + 105d]
    [#subtask] Coordinate auditor interviews with control owners @compliance_lead !High [Due + 103d]
    [#subtask] Track and resolve auditor inquiries @compliance_lead !High [Due + 108d]
  [#task] Report Review & Closeout !Highest @ciso [Due + 115d]
    [#subtask] Review draft SOC2 report for accuracy @compliance_lead !Highest [Due + 110d]
    [#subtask] Address reported exceptions with auditor @compliance_lead !High [Due + 112d]
    [#subtask] Obtain management sign-off on final report @ciso !Highest [Due + 114d]
    [#subtask] Distribute SOC2 report to stakeholders @compliance_lead !High [Due + 116d]
    [#subtask] Create remediation plan for any exceptions @compliance_lead !High [Due + 118d]
    [#subtask] Schedule lessons-learned retrospective @compliance_lead !Medium [Due + 120d]

Why the phases run in this order

A Type I report describes controls as they were designed on a single day. A Type II report says they operated across a window — commonly three to twelve months. That one difference sets the whole sequence. Little here is paperwork you can produce on demand; most of it is evidence that accumulates while a clock runs, so the order decides whether the evidence counts at all.

So scoping comes first, and the subtask that looks like admin — Define audit period start and end dates, day one — is the one everything else hangs off. It decides which access review, which change ticket, which restore test is in period. Auditor engagement lands next, at +5d, because the engagement letter fixes the Trust Service Criteria you are measured against, and a gap analysis run before that is analysis against a guess.

The middle of the plan — roughly +14d through +60d — is two dozen control reviews that do not depend on each other. Access, encryption, network, HR lifecycle, vendors, continuity, privacy. They run in parallel across departments. Access management sits at +21d rather than later because CC6 findings take the longest to fix and remediation does not open until +77d, after every review has closed. Then evidence package at +95d, fieldwork at +98d, closeout through +120d. Fieldwork after the package, never during: an auditor arriving to an unassembled repository spends your response SLA on retrieval.

Who owns which gate

  • Compliance lead — the spine. Schedule, evidence request list, the cross-reference from artefact to criterion. Owns the project, not the controls.
  • CISO — judgment. Criteria selection, risk appetite, documented risk acceptances, the management assertion letter, final sign-off. Anything where someone has to accept residual risk in writing.
  • IT admin and security engineer — a real split. Provisioning mechanics on one side; privileged accounts, least privilege and MFA verification on the other.
  • DevOps — infrastructure evidence. Encryption at rest, cloud IAM, audit logging, backup restoration, failover.
  • Engineering lead — SDLC and change approval, the two areas auditors sample hardest.
  • HR, legal, vendor manager — CC1 employee lifecycle, DPAs and breach notification clauses, CC9 vendor inventory.

Nine roles, nine variables

Every assignment is a @role token, not a person. A token matching no Jira member is saved as a template variable you fill once on apply, so mapping nine roles is nine choices rather than 187 edits. The [Due + Nd] offsets resolve against the anchor date at that same moment, so a plan started in November comes out the same shape as one started in July.

What breaks when you skip a step

  • Skip Remove terminated user accounts before the access audit and a leaver keeps live access inside the window. That is an exception in the report, and you cannot retroactively fix a date that has passed.
  • Verify backup schedules but skip Test backup restoration procedure and you have evidenced design, not operation — the entire point of a Type II.
  • Skip Assign control owners across departments at +6d and the evidence request list goes out two days later addressed to nobody. Every request routes back through the compliance lead, who becomes the bottleneck for 90 days.
  • Skip Audit sample change tickets for proper approval at +45d and you learn during fieldwork that production changes shipped without recorded approval — with no runway left to fix the process before the window closes.
  • Skip the two tabletop exercises and you have plans nobody rehearsed. A rehearsal produces a dated artefact with attendees; a document does not.

Five people versus fifty

Nine roles, and a five-person company has maybe two. One founder-engineer absorbs CISO, compliance lead, security engineer and DevOps; legal is outside counsel; HR is whoever runs payroll. That is fine. Auditors do not score headcount — they ask whether the control operated.

Two things do not collapse. Separation of duties: if the same person writes and deploys, you need a compensating control — mandatory review by another human, an approval gate in the pipeline — documented as one rather than quietly ignored. And Physical Access Controls: with no office and cloud-only infrastructure, that task is inherited from your provider. Delete it and say so. A fabricated badge-log review is worse than an honest exclusion.

At fifty the problem inverts. The nine owners sit in departments that mostly do not report to the compliance lead, so the hard part stops being the work and becomes the follow-up. Two months of parallel reviews with no named owner per subtask is where prep dies.

What this template is not

A project plan shaped like the work, not compliance advice. Your auditor's evidence request list overrides this one, and no task board makes an organisation audit-ready. On certifications, the accurate framing: SuperTemplates.ai runs on Atlassian Forge, and Atlassian holds SOC 2 Type II and ISO 27001 for the Forge platform. SuperTemplates.ai does not hold either certification itself, and applying this template does not make you certified either.

How to use this template in Jira

  1. Install SuperTemplates from the Atlassian Marketplace (free 30-day trial) and open the editor in any Jira project.
  2. Copy the tree above, paste it into the editor, and run Smart Replace — assignees, priorities, and date offsets resolve against your live Jira data.
  3. Preview the whole batch and create everything in Jira in one click. Nothing is created until you confirm.

A 187-issue tree is more than anyone wants to type by hand, which is the whole reason the editor can bulk-create up to 300 Jira issues in one batch from a single paste. Save the tree once and every name, date and priority in it becomes a Jira issue template variable that resolves as the batch is created — so next quarter you re-run the structure instead of re-typing last quarter’s dates.

No credit card required · Starts inside Jira

Related templates

  • Incident Response — SEV1 Production Outage Structured incident response from detection through post-mortem. Every task a real on-call engineer performs during a production incident.
  • Monthly Patch Deployment ITIL-aligned patch management cycle with testing, approval, and phased production deployment. Every task a real IT ops engineer performs.
  • ITIL Change Management Standard change request workflow from submission through CAB approval, implementation, and post-implementation review. Every task maps to real ITIL processes.