← All templates
Jira task template
SOC2 Type II Audit Prep — Annual Compliance
Complete audit preparation from scoping through report delivery. Every control a real compliance team tracks.
- Issues created:
- 187
- Structure:
- 1 epic · 32 tasks · 154 subtasks
- Roles:
- compliance_lead, security_engineer, vendor_manager, ciso, legal, it_admin, hr_director, devops, eng_lead
The full task tree this template creates
Copy it, paste it into the SuperTemplates editor, and Smart Replace turns every marker into a typed Jira field.
[#epic] SOC2 Type II Audit Prep — Annual Compliance !Highest @compliance_lead
[#task] Audit Scoping & Engagement !Highest @compliance_lead [Due + 0d]
[#subtask] Define in-scope systems and services @security_engineer !High [Due + 1d]
[#subtask] Map data flows between in-scope systems @security_engineer !High [Due + 2d]
[#subtask] Document third-party integrations in scope @vendor_manager !High [Due + 2d]
[#subtask] Select Trust Service Criteria with leadership @ciso !High [Due + 3d]
[#subtask] Define audit period start and end dates @compliance_lead !Highest [Due + 1d]
[#task] External Auditor Engagement !Highest @compliance_lead [Due + 5d]
[#subtask] Request proposals from qualified audit firms @compliance_lead !High [Due + 3d]
[#subtask] Evaluate auditor qualifications and references @ciso !Medium [Due + 4d]
[#subtask] Negotiate and execute engagement letter @legal !High [Due + 7d]
[#task] Readiness Assessment !High @compliance_lead [Due + 10d]
[#subtask] Gap analysis against SOC2 criteria @compliance_lead !High [Due + 8d]
[#subtask] Review prior year findings and remediation @compliance_lead !High [Due + 9d]
[#subtask] Assess current control maturity levels @security_engineer !Medium [Due + 10d]
[#subtask] Build prioritized risk register @compliance_lead !High [Due + 11d]
[#task] Audit Project Setup !High @compliance_lead [Due + 7d]
[#subtask] Create shared evidence repository @it_admin !Medium [Due + 5d]
[#subtask] Assign control owners across departments @compliance_lead !Highest [Due + 6d]
[#subtask] Distribute evidence request list to owners @compliance_lead !High [Due + 8d]
[#subtask] Schedule kickoff with all stakeholders @compliance_lead !High [Due + 7d]
[#task] Information Security Policy Review !High @ciso [Due + 14d]
[#subtask] Update Information Security Policy @ciso !High [Due + 15d]
[#subtask] Review Acceptable Use Policy @ciso !Medium [Due + 16d]
[#subtask] Update Data Classification Policy @compliance_lead !High [Due + 17d]
[#subtask] Review Code of Conduct and Ethics Policy @hr_director !Medium [Due + 16d]
[#subtask] Update Incident Response Policy @security_engineer !High [Due + 18d]
[#subtask] Review Business Continuity Policy @ciso !Medium [Due + 19d]
[#task] Risk Management Framework (CC3) !High @compliance_lead [Due + 21d]
[#subtask] Update enterprise risk assessment @compliance_lead !High [Due + 19d]
[#subtask] Document risk appetite and tolerance levels @ciso !Medium [Due + 20d]
[#subtask] Identify and assess fraud risk scenarios @compliance_lead !High [Due + 21d]
[#subtask] Review risk mitigation strategies and owners @compliance_lead !High [Due + 22d]
[#task] Communication & Information Controls (CC2) !Medium @compliance_lead [Due + 25d]
[#subtask] Verify internal security communication channels @compliance_lead !Medium [Due + 23d]
[#subtask] Review external communication procedures @legal !Medium [Due + 24d]
[#subtask] Document whistleblower and reporting mechanisms @hr_director !Medium [Due + 25d]
[#subtask] Verify board and management oversight reporting @ciso !Medium [Due + 26d]
[#task] User Access Management (CC6) !Highest @it_admin [Due + 21d]
[#subtask] Audit user access lists for all in-scope systems @it_admin !Highest [Due + 22d]
[#subtask] Verify RBAC configuration across systems @it_admin !High [Due + 23d]
[#subtask] Remove terminated user accounts @it_admin !Highest [Due + 22d]
[#subtask] Validate access provisioning workflow @it_admin !High [Due + 24d]
[#subtask] Document access de-provisioning SLA @it_admin !High [Due + 25d]
[#subtask] Review privileged access accounts @security_engineer !Highest [Due + 23d]
[#subtask] Verify least-privilege enforcement @security_engineer !High [Due + 26d]
[#task] Authentication Controls !High @security_engineer [Due + 28d]
[#subtask] Verify MFA on all in-scope systems @security_engineer !Highest [Due + 26d]
[#subtask] Review password policy configuration @it_admin !High [Due + 27d]
[#subtask] Audit SSO provider settings @it_admin !High [Due + 28d]
[#subtask] Review service account credential rotation @devops !High [Due + 29d]
[#subtask] Verify session timeout and lockout policies @security_engineer !Medium [Due + 28d]
[#task] Physical Access Controls !Medium @it_admin [Due + 30d]
[#subtask] Review data center physical access logs @it_admin !Medium [Due + 28d]
[#subtask] Verify badge access system configuration @it_admin !Medium [Due + 29d]
[#subtask] Audit visitor access procedures @it_admin !Low [Due + 30d]
[#subtask] Review environmental controls (HVAC, fire, flood) @it_admin !Medium [Due + 31d]
[#task] Network Security Controls !High @security_engineer [Due + 35d]
[#subtask] Review firewall rules and configurations @devops !High [Due + 33d]
[#subtask] Verify network segmentation between environments @devops !High [Due + 34d]
[#subtask] Audit VPN access configuration and logs @security_engineer !High [Due + 35d]
[#subtask] Review IDS/IPS system configuration @security_engineer !High [Due + 36d]
[#subtask] Verify WAF rules and configuration @devops !High [Due + 35d]
[#task] Encryption Controls !High @security_engineer [Due + 38d]
[#subtask] Verify encryption at rest for all databases @devops !Highest [Due + 36d]
[#subtask] Verify TLS configuration for data in transit @devops !High [Due + 37d]
[#subtask] Audit encryption key management procedures @security_engineer !High [Due + 38d]
[#subtask] Review certificate management and expiry tracking @devops !Medium [Due + 39d]
[#task] Cloud Infrastructure Security !High @devops [Due + 40d]
[#subtask] Review cloud IAM policies and roles @devops !High [Due + 38d]
[#subtask] Audit security groups and network ACLs @devops !High [Due + 39d]
[#subtask] Verify cloud audit logging enabled @devops !High [Due + 40d]
[#subtask] Review cloud storage bucket permissions @devops !Highest [Due + 38d]
[#subtask] Validate infrastructure-as-code security scanning @devops !Medium [Due + 41d]
[#task] Secure Development Lifecycle (CC8) !High @eng_lead [Due + 42d]
[#subtask] Review SDLC policy documentation @eng_lead !High [Due + 40d]
[#subtask] Verify mandatory code review process @eng_lead !High [Due + 41d]
[#subtask] Audit branch protection rules @devops !High [Due + 41d]
[#subtask] Review SAST tool configuration and results @security_engineer !High [Due + 42d]
[#subtask] Verify dependency vulnerability scanning @devops !High [Due + 42d]
[#subtask] Review secure coding training records @eng_lead !Medium [Due + 43d]
[#task] Change Management Controls !Highest @eng_lead [Due + 46d]
[#subtask] Review change approval workflow documentation @eng_lead !High [Due + 44d]
[#subtask] Audit sample change tickets for proper approval @compliance_lead !Highest [Due + 45d]
[#subtask] Verify separation of duties (dev vs deploy) @devops !High [Due + 45d]
[#subtask] Review emergency change procedures @eng_lead !High [Due + 46d]
[#subtask] Validate rollback procedures and testing @devops !Medium [Due + 47d]
[#task] Release & Deployment Controls !High @devops [Due + 49d]
[#subtask] Review CI/CD pipeline security controls @devops !High [Due + 47d]
[#subtask] Verify production deployment approval gates @devops !High [Due + 48d]
[#subtask] Audit deployment logs for unauthorized changes @security_engineer !High [Due + 49d]
[#subtask] Review environment separation (dev/staging/prod) @devops !High [Due + 48d]
[#task] Logging & Monitoring (CC7) !Highest @devops [Due + 49d]
[#subtask] Verify centralized log aggregation system @devops !High [Due + 47d]
[#subtask] Review log retention policy compliance @compliance_lead !High [Due + 48d]
[#subtask] Audit alerting rules for security events @security_engineer !High [Due + 49d]
[#subtask] Verify application-level audit logging @eng_lead !High [Due + 50d]
[#subtask] Review monitoring dashboards for system health @devops !Medium [Due + 49d]
[#subtask] Test log tamper-protection mechanisms @security_engineer !High [Due + 51d]
[#task] Vulnerability Management !Highest @security_engineer [Due + 53d]
[#subtask] Review vulnerability scanning tools and schedule @security_engineer !High [Due + 50d]
[#subtask] Audit vulnerability remediation SLAs @security_engineer !High [Due + 51d]
[#subtask] Verify critical patching within SLA @devops !Highest [Due + 52d]
[#subtask] Review penetration test reports and remediation @security_engineer !High [Due + 53d]
[#subtask] Document risk acceptances with justification @ciso !Medium [Due + 54d]
[#task] Incident Response Procedures !Highest @security_engineer [Due + 56d]
[#subtask] Review incident response plan documentation @security_engineer !High [Due + 53d]
[#subtask] Verify incident classification and severity matrix @security_engineer !High [Due + 54d]
[#subtask] Audit IR team roles and escalation contacts @compliance_lead !High [Due + 55d]
[#subtask] Review incident communication templates @compliance_lead !Medium [Due + 55d]
[#subtask] Conduct tabletop incident response exercise @security_engineer !High [Due + 56d]
[#subtask] Review post-incident review process @security_engineer !Medium [Due + 57d]
[#task] Employee Lifecycle Security (CC1) !High @hr_director [Due + 35d]
[#subtask] Review background check policy and records @hr_director !High [Due + 33d]
[#subtask] Verify employment agreement security clauses @legal !High [Due + 34d]
[#subtask] Review NDA and confidentiality agreement coverage @legal !High [Due + 35d]
[#subtask] Audit new hire security training completion @hr_director !High [Due + 36d]
[#subtask] Verify offboarding checklist and access revocation @hr_director !Highest [Due + 36d]
[#task] Security Awareness Training !High @compliance_lead [Due + 42d]
[#subtask] Review annual security awareness training program @compliance_lead !High [Due + 38d]
[#subtask] Verify training completion rates @hr_director !High [Due + 39d]
[#subtask] Review phishing simulation results and trends @security_engineer !Medium [Due + 40d]
[#subtask] Audit role-specific security training records @hr_director !Medium [Due + 41d]
[#subtask] Document training exceptions and remediation @compliance_lead !Medium [Due + 42d]
[#task] Vendor Inventory & Classification (CC9) !High @vendor_manager [Due + 42d]
[#subtask] Update inventory of all third-party vendors @vendor_manager !High [Due + 40d]
[#subtask] Classify vendors by data access and criticality @vendor_manager !High [Due + 41d]
[#subtask] Verify vendor SOC2/ISO reports are current @compliance_lead !Highest [Due + 42d]
[#subtask] Flag vendors without compliance certifications @compliance_lead !High [Due + 43d]
[#task] Vendor Risk Assessment !High @vendor_manager [Due + 49d]
[#subtask] Complete risk assessments for critical vendors @vendor_manager !High [Due + 45d]
[#subtask] Review vendor security questionnaire responses @security_engineer !High [Due + 46d]
[#subtask] Assess vendor incident notification procedures @compliance_lead !Medium [Due + 47d]
[#subtask] Document vendor risk acceptance decisions @ciso !Medium [Due + 48d]
[#task] Vendor Contract Review !High @legal [Due + 52d]
[#subtask] Review data processing agreements (DPAs) @legal !High [Due + 49d]
[#subtask] Verify breach notification clauses @legal !High [Due + 50d]
[#subtask] Audit vendor SLA compliance @vendor_manager !Medium [Due + 51d]
[#task] Business Continuity Planning (A1) !High @ciso [Due + 56d]
[#subtask] Review BCP documentation @ciso !High [Due + 54d]
[#subtask] Verify RTO for critical systems @devops !High [Due + 55d]
[#subtask] Verify RPO configuration @devops !High [Due + 55d]
[#subtask] Conduct BCP tabletop exercise @ciso !High [Due + 56d]
[#subtask] Document BCP test results and lessons learned @compliance_lead !Medium [Due + 58d]
[#task] Backup & Disaster Recovery !High @devops [Due + 60d]
[#subtask] Verify automated backup schedules for all databases @devops !High [Due + 57d]
[#subtask] Test backup restoration procedure @devops !Highest [Due + 58d]
[#subtask] Review disaster recovery runbooks @devops !High [Due + 59d]
[#subtask] Verify cross-region replication @devops !High [Due + 59d]
[#subtask] Conduct failover test to DR environment @devops !High [Due + 60d]
[#task] Data Classification & Handling (C1) !High @compliance_lead [Due + 56d]
[#subtask] Review data classification schema and labels @compliance_lead !High [Due + 54d]
[#subtask] Audit data handling procedures by classification @compliance_lead !High [Due + 55d]
[#subtask] Verify data retention and disposal schedules @legal !High [Due + 56d]
[#subtask] Review DLP tool configuration and alerts @security_engineer !High [Due + 57d]
[#subtask] Audit data access request and approval process @compliance_lead !Medium [Due + 57d]
[#task] Privacy Controls (P1) !High @legal [Due + 60d]
[#subtask] Review privacy policy and notice accuracy @legal !High [Due + 58d]
[#subtask] Verify consent management mechanisms @eng_lead !High [Due + 59d]
[#subtask] Audit DSAR process @legal !High [Due + 60d]
[#subtask] Review PII inventory and data mapping @compliance_lead !High [Due + 60d]
[#subtask] Verify data anonymization controls @eng_lead !Medium [Due + 61d]
[#task] Critical Gap Remediation !Highest @compliance_lead [Due + 77d]
[#subtask] Remediate access control findings @it_admin !Highest [Due + 80d]
[#subtask] Remediate policy documentation gaps @compliance_lead !High [Due + 82d]
[#subtask] Remediate monitoring and alerting gaps @devops !High [Due + 84d]
[#subtask] Implement missing vendor risk assessments @vendor_manager !High [Due + 84d]
[#subtask] Remediate change management findings @eng_lead !High [Due + 86d]
[#subtask] Verify all remediation items resolved @compliance_lead !Highest [Due + 90d]
[#task] Evidence Package Finalization !Highest @compliance_lead [Due + 95d]
[#subtask] Compile evidence artifacts per control objective @compliance_lead !High [Due + 88d]
[#subtask] Cross-reference evidence to Trust Service Criteria @compliance_lead !High [Due + 90d]
[#subtask] Review evidence completeness with control owners @compliance_lead !High [Due + 92d]
[#subtask] Prepare management assertion letter draft @ciso !High [Due + 93d]
[#subtask] Quality review of full evidence package @compliance_lead !Highest [Due + 95d]
[#task] Auditor Fieldwork Support !Highest @compliance_lead [Due + 98d]
[#subtask] Host auditor kickoff and walkthrough sessions @compliance_lead !High [Due + 98d]
[#subtask] Respond to auditor evidence requests within SLA @compliance_lead !Highest [Due + 105d]
[#subtask] Coordinate auditor interviews with control owners @compliance_lead !High [Due + 103d]
[#subtask] Track and resolve auditor inquiries @compliance_lead !High [Due + 108d]
[#task] Report Review & Closeout !Highest @ciso [Due + 115d]
[#subtask] Review draft SOC2 report for accuracy @compliance_lead !Highest [Due + 110d]
[#subtask] Address reported exceptions with auditor @compliance_lead !High [Due + 112d]
[#subtask] Obtain management sign-off on final report @ciso !Highest [Due + 114d]
[#subtask] Distribute SOC2 report to stakeholders @compliance_lead !High [Due + 116d]
[#subtask] Create remediation plan for any exceptions @compliance_lead !High [Due + 118d]
[#subtask] Schedule lessons-learned retrospective @compliance_lead !Medium [Due + 120d]How to use this template in Jira
- Install SuperTemplates from the Atlassian Marketplace (free 14-day trial) and open the editor in any Jira project.
- Copy the tree above, paste it into the editor, and run Smart Replace — assignees, priorities, and date offsets resolve against your live Jira data.
- Preview the whole batch and create everything in Jira in one click. Nothing is created until you confirm.
Related templates
- Incident Response — SEV1 Production Outage — Structured incident response from detection through post-mortem. Every task a real on-call engineer performs during a production incident.
- Monthly Patch Deployment — ITIL-aligned patch management cycle with testing, approval, and phased production deployment. Every task a real IT ops engineer performs.
- ITIL Change Management — Standard change request workflow from submission through CAB approval, implementation, and post-implementation review. Every task maps to real ITIL processes.