Audit and compliance
System description
Also called: SOC 2 system description, description of the system
The system description is the section of a SOC 2 report where management describes the system being reported on: its boundaries, components, the services delivered, and the controls in place. It defines what the report covers.
It is also the reference point for testing scope. A penetration test whose scope does not match the system description is evidence about a different system.
See also
Testing, with the report an auditor can actually use
A fixed price, a date, and a report that states scope, method and closure. No discovery call required to get a number.