This is a live, read-only demo. You’re exploring a fictional company, “Tailwind Systems.” Nothing here can be edited, and the data resets nightly. Create a free workspace to build your own program.
Overview
Program overview
Tailwind Systems · compliance, risk, and vendor posture at a glance
Audit readiness
SOC 2 (Trust Services Criteria)
20 of 61 requirements covered
Requirement status · SOC 2 (Trust Services Criteria)
How the applicable requirements break down right now.
Covered20
In progress2
Gap0
Unaddressed39
SOC 2 (Trust Services Criteria) readiness
33%
20 of 61 requirements covered
Open risks
10
1 high unmitigated · 12 total
Vendors
15
1 review due · 3 critical
Vendors by criticality
15 vendors · 1 review due.
Critical3
High5
Medium4
Low3
Framework readiness
Collect evidence once. The same controls satisfy clauses across frameworks.
SOC 2 (Trust Services Criteria)33% · 20/61
ISO/IEC 27001:202221% · 24/116
Risk heat map
Effective (residual where assessed) likelihood × impact. Closed risks are excluded.
| Almost certain | · | · | · | · | · |
| Likely | · | · | · | 1 | · |
| Possible | · | · | · | 2 | · |
| Unlikely | · | 1 | 2 | 3 | 1 |
| Rare | · | · | · | · | 1 |
| Insignificant | Minor | Moderate | Major | Severe |
Low (1-3)Guarded (4-7)Elevated (8-14)High (15-25)Rows = likelihood · Columns = impact
Mapped requirements · SOC 2 (Trust Services Criteria)
| Clause | Requirement | Controls | Status |
|---|---|---|---|
CC1.4 | Commitment to competence | security-awareness-training, hr-security | Covered |
CC3.1 | Objectives specified | risk-assessment | Covered |
CC3.2 | Risk identification & analysis | risk-assessment | Covered |
CC4.1 | Ongoing & separate evaluations | internal-audit-program, management-review | Covered |
CC5.3 | Policies & procedures | information-security-policy, document-control | Covered |
CC6.1 | Logical access security | access-control-policy, mfa, asset-inventory | Covered |
CC6.2 | User registration & authorization | user-lifecycle | Covered |
CC6.3 | Access based on roles & least privilege | access-control-policy, user-lifecycle | Covered |
CC6.4 | Physical access | physical-security | Covered |
CC6.6 | External threat protection | network-security | Covered |
CC6.7 | Transmission & endpoints | encryption | Covered |
CC6.8 | Unauthorized/malicious software | malware-protection | In progress |
CC7.1 | Vulnerability & configuration detection | vulnerability-management | Covered |
CC7.2 | Security monitoring | logging-monitoring | In progress |
CC7.3 | Incident evaluation | incident-response | Covered |
CC7.4 | Incident response | incident-response | Covered |
CC8.1 | Change management | change-management, secure-development | Covered |
CC9.2 | Vendor & partner risk | vendor-management | Covered |
A1.2 | Environmental protection & backup | backups, business-continuity | Covered |
A1.3 | Recovery testing | business-continuity | Covered |
C1.1 | Identify & protect confidential information | data-classification | Covered |
C1.2 | Dispose of confidential information | data-retention-disposal | Covered |