Policy, Program and Procedures

 View Only
  • 1.  CUEC Department Procedures

    Posted 06-20-2024 08:46 AM


    Does anyone have a procedure that assists Vendor Owners with filling out their own CUECs?  For example, for each line item in the CUEC's generally the responses refer to a policy or a procedure.  I am struggling with assistance from Vendor Owners on this.  I do have a procedure in place listing the purpose/importance of answering the CUECs along with answering via policy/procedure and if not, determine where it needs to be added or created.. 

    What are others doing to assist with this issue?



  • 2.  RE: CUEC Department Procedures

    Posted 06-20-2024 08:57 AM

    I am interested in this topic as well, we are struggling with the same issue. We are building a "mapping library" as we go, but would be interested in how others are handling this process as well. 



  • 3.  RE: CUEC Department Procedures

    Posted 06-20-2024 08:58 AM
      |   view attached
    Good morning,
    This is a template that I have used as an auditor for the mapping of a SOC 2, in this example the sub-service organization is Workday.  The CUEC tab I map to Company ABC internal controls to the CUECs in Workday's listing of CUECs seen in the report.
    Hope this helps!
    Donna Wilson | Security and Compliance Manager
    Navigate Wellbeing Solutions   |  
    CONFIDENTIALITY NOTICE: This e-mail message, including any attachments, is for the sole use of the intended recipient(s) and may contain confidential and privileged information or may otherwise be protected by law. Any unauthorized review, use, disclosure, or distribution is prohibited. If you
are not the intended recipient, please contact the sender by reply e-mail and destroy all copies of the original message and any attachment thereto.


  • 4.  RE: CUEC Department Procedures

    Posted 06-20-2024 10:08 AM

    Thank you!


    Kelli Shoup | Technology Support Lead/Information Security Specialist

    The Farmers Bank

  • 5.  RE: CUEC Department Procedures

    Posted 06-20-2024 11:22 AM

    Thanks all


    USAA Classification: Internal