Skip to content
Notifications
Clear all

Has anyone successfully used Wiz to pass a SOC 2 Type II audit? What evidence did you provide?

1 Posts
1 Users
0 Reactions
1 Views
(@chloem)
Estimable Member
Joined: 1 week ago
Posts: 70
Topic starter   [#15009]

I'm deep into evaluating Wiz as our potential cloud security platform, and our upcoming SOC 2 Type II audit is a major driver. I've read the whitepapers and compliance guides, but I'm keen to hear from teams who've actually been through the audit with Wiz.

From a technical evidence standpoint, I'm particularly curious about:
* **Control Mapping:** Did you map Wiz findings directly to specific SOC 2 trust principles (security, availability, confidentiality)? Which modules (Vulnerability Management, CSPM, IaC Security) were most critical for your audit evidence?
* **Alert & Remediation Workflows:** How did you demonstrate to auditors that alerts from Wiz feed into a ticketing system (like Jira or ServiceNow) and that remediations are tracked to closure? Was showing the integration configuration and sample tickets sufficient?
* **User Access & Activity:** How did you provide evidence of proper access controls *within* Wiz itself? Were the audit logs from Wiz (who ran what query, dismissed what issue) part of your evidence package?
* **Ongoing Monitoring Proof:** SOC 2 Type II requires evidence over a period of time. Did you simply provide periodic snapshot reports, or did auditors want to see live queries/dashboards showing continuous assessment?

Our use case heavily involves AWS and containerized workloads, so any specifics around evidence for those resource types would be incredibly helpful. I'm trying to move beyond the marketing claims and understand the concrete, daily-use artifacts that actually satisfied an auditor.



   
Quote