CyberDefenders is an independently funded nonprofit project.. Donate
Security compliance and audit readiness
2026 Summer Cohort — Capstone Project

Trust but Verify: SOC 2 Audit Readiness

Sponsored by Interlaced

Project Brief

Compliance Support for a Live SOC 2 Program

Interlaced is an IT consulting and managed services firm with a formal security practice and a target of achieving SOC 2 Type II certification. This internship placed a student inside that live effort, working alongside the Head of Security to prepare evidence, improve documentation, and help close gaps before audit — not a simulated compliance exercise, but work that fed a live readiness program, including audit-ready evidence packages, remediation tracking, control mapping, and internal risk documentation.

Capstone Team

Project Workstreams

Control Mapping

Mapped current security controls to SOC 2 Trust Services Criteria across Security, Availability, Confidentiality, Privacy, and Processing Integrity.

Policy Remediation

Supported updates to access control, change management, incident response, vendor management, and backup/recovery policies so documentation matched operating reality.

Evidence Collection & Risk Tracking

Built organized, audit-ready evidence packages and contributed to the internal risk register and remediation tracker, documenting risks, owners, and closure timelines.

Track Scope: Expected Deliverables

  • SOC 2 Trust Services Criteria control mapping notes for current security controls.
  • Updated or remediated policy documentation for audit-relevant process areas.
  • Organized evidence packages for selected controls, including screenshots, logs, and export artifacts.
  • Risk register entries and risk treatment documentation tied to observed gaps.
  • Remediation tracker updates with clear owners, timelines, and closure status.

Skills Demonstrated

SOC 2 Compliance Controls Mapping Risk Registers Audit Evidence Collection GRC Policy Development