TrustCloud launches Application Assurance: AI-native continuous control monitoring for enterprises. Read more →

Getting Started

Estimated reading: 5 minutes 4761 views

Introduction

TrustCloud offers an effortless and personalized approach to setting up a comprehensive compliance program. Using the onboarding assistant, Kira, users can create an account, begin the onboarding process, and customize their program to align with multiple compliance standards. Once onboarding is complete, TrustCloud enables automation of your compliance program through integrations and automated tests.

For more details, explore our GRC Launchpad article: SOC 2 Overview and Guides.

Setting Up Your Program

TrustOps simplifies the process of creating a personalized compliance program. By default, it starts with a SOC 2 program, but additional controls and policies can be added later to meet other compliance standards. The onboarding assistant, Kira, will guide you through every step.

Onboarding

The first step is to sign up for a TrustCloud account. Enter your details and click on “Verify My Email.” TrustCloud will send a “Verify Email” action link. Verify your email to proceed to the onboarding process.

Step-by-Step Guide to Creating an Account

  1. Answer Initial Questions: Share your compliance goals to help TrustCloud tailor its support:
    Onboarding 01 1

    1. How soon do you want to be SOC 2 compliant?
      1. Next 2-3 months
      2. This year (not in a rush)
      3. Exploring, unsure of timeline
  2. Select other standards if you are interested in and click on “Proceed.”
    TC OB 01
  3. The next screen shows the onboarding steps. Click on “Proceed.”
    TC OB 02
  4. Onboarding has two steps:
    1. Step 1: Answer a few simple questions about your business practices and create your compliance baseline. These answers will satisfy a few tests for SOC 2. Click on “Your Tech Stack.”
      TC OB 03
    2. Step 2: Set up for automation and craft personalized controls by cataloging your cloud infrastructure services most relevant for SOC 2. Click on “Select Cloud Infrastructure Services.”
      TC OB 04
    3. Describe the AWS, Azure and GCP services that you use. Select from the common list of tools. Click on ”I’ve selected my Cloud Services.”
      TC OB 05
    4. Select all other services from the catalog and click on “I’ve described my Tech Stack.”
      TC OB 06

Completion

  1. Click on “See Your TrustCloud” to access your program.
    TC OB 07
  2. Click on “Begin My SOC 2 Prep” to start your preparation.

TrustCloud offers an effortless and personalized approach to setting up a comprehensive compliance program. With the help of the onboarding assistant, Kira, users can easily create an account and begin the onboarding process. TrustOps provides a step-by-step guide for onboarding, allowing users to customize their program and map it to various compliance standards. Once the onboarding is complete, users can automate their program and take advantage of TrustCloud’s integrations and automated tests.

Video: A step-by-step guide for TrustOps onboarding

Post-Onboarding Tasks

Completing post-onboarding tasks maximizes the use of TrustCloud and strengthens your program. Here are a few things to know before you start with post-onboarding tasks.

TC OB 08

Step-by-Step Guide to Post-Onboarding Tasks

  1. Step 1: Complete your tasks. Go to “My TrustCloud” and select “Tasks.”
    TC POB Tasks
    Complete each task by clicking on “Complete Now.”
  2. Step 2: Set up integrations on the Integrations page to unlock automated tests.
    TrustCloud provides you with the necessary integrations for your SOC 2 journey. Read more on how to set up integrations from here.
    TC POB Automate Control Testing
    Click on “Manage Integrations” to do the needful.
    TC POB Setup Integration
    Click on “Setup Integration.”
    Note: Without integrations, only self-assessments (manual tests) will be available.
  3. Step 3: Review systems for completeness and data sensitivity classifications. Add systems that are required and recommended for the audit by clicking on “Add System.”
    TC POB Review Systems
  4. Step 4: Satisfy non-automated controls by answering self-assessments and providing evidence. You can add evidence from the three-dot menu in front of the assessment and mark it with “Yes,” “No,” or “Not Sure.”
    TC POB Non Automated Controls
  5. Step 5: Review and approve policies. TrustCloud auto-generates policies based on your program. Approve them or assign ownership for further review. Click on “Review Policy” to approve.
    TrustOps
  6. Step 6: Add documents that are required for the audit to help automate controls that depend on them. TrustCloud gives you necessary documents.
    TrustOps
  7. Preview and customize your TrustShare portal:
    1. Add branding, a contact email, and publish your TrustShare.
    2. Invite users to view your TrustShare.

Preparing for a Successful Audit

TrustCloud’s 8-week program ensures you are ready for your audit. Below is an overview of weekly tasks:

Week 1:

  1. Get onboarded to the platform
  2. Invite collaborators and assign Groups
  3. Finalize the System Register
  4. Set up integrations
  5. Add branding and turn on notifications
  6. Determine ownership of Tasks, Controls, Systems, and Policies

Week 2:

  1. Control Adoption
  2. Run automated tests & triage failing tests
  3. Finalize assignment of Tasks, Controls, Systems, and Policies

Week 3:

  1. Engineering tasks
  2. DevOps tasks

Week 4:

  1. Security and Compliance tasks

Week 5:

  1. IT tasks

Week 6:

  1. HR tasks
  2. Legal tasks

Week 7:

  1. Leadership tasks
  2. Sales & Marketing tasks

Week 8:

  1. Internal Assessment* (available as a Professional Service by TrustCloud)

An internal assessment is a review of your compliance program prior to your external audit. It is recommended that you do this once you have collected 80% or more of the evidence required for your controls.

For an internal assessment, contact our experts at kira@trustcloud.ai or use the Contact Support option in TrustCloud.

Read more about overall platform capabilities and overview from here.

Have a question? Join our TrustCommunity to learn about security, privacy, governance, risk and compliance, collaborate with your peers, and share and review the trust posture of companies that value trust and transparency!

Join the conversation

You might also be interested in

Custom Frameworks

TrustCloud supports several standards and frameworks out of the box, including SOC 2, CMMC,...

Hybrid Data Fabric

Rather than chasing fragmented spreadsheets or outdated lists, hybrid data fabric gives you a...

Systems

A system is a piece of software, either built by the organization or purchased...

Groups in Controls

TrustCloud provides you with a comprehensive set of controls to get certified against several...

Mapping a Control

TrustCloud’s common controls framework maps a comprehensive set of certified standards controls and your...

Sharing Controls with customers

The TrustShare application in TrustCloud makes it easy for startups, SMBs, and enterprises to...

Excluding a control, test or attestation

The exclusion allows you to remove certain resources, controls or tests from your program...

Control Attributes

Every control has many attributes that help us understand it better for mapping and...
OR

TrustCommunity

Instant support with our AI chatbot

Please login with your TrustCloud credentials to continue