Scope of Services
Define monitoring sources, coverage hours, threat detection capabilities, vulnerability scanning frequency, and any exclusions such as proprietary applications or cloud-native telemetry not provided by the vendor.
A well-drafted SOC Agreement reduces ambiguity about responsibilities, helps meet regulatory and contractual obligations, and clarifies incident response expectations. It establishes measurable service levels, preserves evidence chain-of-custody, and sets limits on liability and data use.
Organizations that delegate 24/7 threat monitoring or outsource incident response should use a SOC Agreement to document roles and protections.
The agreement benefits both customers and providers by defining expectations, compliance obligations, and evidence retention for investigations or audits.
The CISO signs or approves the SOC Agreement on behalf of the customer to confirm acceptance of monitoring scope, SLAs, and data-sharing terms. The CISO also documents required technical integrations, access controls, and acceptable incident response timelines.
A senior vendor representative (COO/VP of Services) signs to bind the managed SOC provider to service levels, confidentiality, breach notification timelines, and indemnities; the signer must have authority to commit to audits and data-handling constraints.
Define monitoring sources, coverage hours, threat detection capabilities, vulnerability scanning frequency, and any exclusions such as proprietary applications or cloud-native telemetry not provided by the vendor.
Specify SLA metrics such as alert acknowledgement times, initial triage windows, containment targets, and scheduled reporting frequency along with remedies for missed SLAs.
List required technical privileges, log sources, API integrations, on-premise agent installation, and responsibilities for maintaining connectivity and credentials.
Address log storage, encryption standards, data segregation, retention periods, evidence preservation, and ownership of telemetry data generated during monitoring.
Detail incident classification, escalation paths, forensic support, communication templates, legal hold procedures, and third-party coordination roles.
Include regulatory obligations (HIPAA, PCI DSS, 21 CFR Part 11 as applicable), indemnities, limitation of liability, cyber insurance requirements, and audit rights.
| Field | Configuration |
|---|---|
| Alert Priority | High/Medium/Low mapping to SLA windows |
| Escalation Chain | Email, SMS, phone escalation levels |
| Evidence Retention | Tamper-evident storage, defined retention |
| Access Controls | Role-based access for vendor personnel |
Ensure the platform supports required integrations and security controls before accepting electronic execution.
Confirm that the chosen eSignature provider meets your encryption and audit requirements and can produce an immutable audit trail for compliance reviews.
| signNow | DocuSign | Adobe Sign | PandaDoc | HelloSign | |
|---|---|---|---|---|---|
| Starting Price | $8/user/mo | $15/user/mo | $14/user/mo | $19/user/mo | $15/user/mo |
| Free Trial | Yes, 7-day trial | Yes, trial available | Yes, trial available | Yes, trial available | Yes, trial available |
| Bulk Send | Yes | Yes | Yes | Yes | No |
| Audit Trail | Yes | Yes | Yes | Yes | Yes |
| HIPAA Compliant | Yes | Yes | Yes | No | No |
Optica standardized its monitoring scope across portfolio companies to reduce ambiguities during incidents.
BIS required SOC 2 alignment and explicit forensic access clauses in its SOC Agreement.