| 1 minute read

Avalon Achieves SOC 2 Type 1 Compliance

compliance graphic

Avalon is proud to announce that we have successfully completed the SOC 2 Type 1 information security audit as of July 2021. The scope of the audit included our cybersecurity, eDiscovery, and secure print and mail services.

A system and organization controls (SOC) 2 report is administered by an independent accounting and auditing firm and is based on the AICPA’s Trust Services Criteria. The resulting report verifies whether a third-party service provider that holds, stores, and/or processes private data – such as Avalon – complies with a variety of requirements, including security and availability. In short, it indicates that a vendor is a trustworthy partner with rigorous policies and procedures in place.

SOC 2 Logo 21972-312_SOC_NonCPAThere are two types of audits, SOC 2 Type 1, which assesses the design of security processes at a specific point in time, and SOC 2 Type 2, which evaluates how effective security processes are by observing a company’s operations over a period of time. Avalon is currently preparing for a SOC 2 Type 2 audit.

While Avalon has been a trusted vendor to tens of thousands of clients since 2000, achieving SOC 2 Type 1 compliance is a significant achievement that demonstrates our dedication to the highest standards of security and service.

“Avalon has always made the confidentiality, integrity, and availability of our systems and client data a paramount priority for our entire team,” says Kyle Cavalieri, president of Avalon Cyber. “Every day, we work hard building and maintaining resilient systems and applications that allow us to provide the very best professional service possible for our clients. We are proud to have completed the SOC 2 audit to validate that our company’s policies, procedures, and technical controls meet the expectations of the relevant trust principles."

Contact our team if you need assistance or have any questions about our cybersecurity services. CONTACT US

Blog Articles

New York Department of Financial Services (NYDFS) Amendments Effective November 2024

As covered in our previous article, the New York Department of Financial Services (NYDFS) updated its Cybersecurity Regulation in 2023. To help entities roll out the changes and new requirements, they have provided phased timelines for when these items must be implemented by.

Risks Lurking in the “Shadows”: Shadow IT and Shadow AI

You may have heard the saying: “Change is the only constant in life.” This is certainly true of the information technology industry, which in turn, has a ripple effect on the technology, services, risk, and regulatory requirements that impact your organization and its environment.

Focusing In On the New “Govern” Function in NIST CSF 2.0

In February 2024, the National Institute of Standards and Technology (NIST) released Version 2.0 of the Cybersecurity Framework (CSF or the Framework) which is the first significant update to the Framework since 2014 when it was first created.

Vector

About Us

Curabitur tincidunt eros sed magna dignissim semper. Sed bibendum tincidunt mauris, at auctor nisi. Mauris sed urna orci. Sed posuere justo odio, vel rhoncus neque sodales sed. Etiam ornare iaculis leo, et tincidunt neque vulputate at.