Readiness statement
Wesley Institute of Technology is developing and documenting controls aligned with the AICPA Trust Services Criteria used in SOC 2 examinations and with relevant ISO management-system and security standards. This is a readiness and continuous-improvement statement, not a representation that a SOC 2 examination has been completed or that an ISO certification has been issued.
Relevant framework alignment
The program is designed with reference to SOC 2 Security, Availability, Processing Integrity, Confidentiality, and Privacy criteria; ISO/IEC 27001 information-security management; ISO/IEC 27701 privacy information management; ISO 22301 business continuity; and ISO 21001 educational-organization management, as relevant to scope and risk.
Governance and risk
The Institute is establishing defined ownership, security and privacy policies, periodic risk assessment, asset and data classification, vendor review, change control, exception handling, and documented management review.
Identity and access
Authentication uses an approved identity provider. Administrative access is restricted, role-based, and intended to follow least-privilege principles. Access changes and sensitive administrative actions are designed to be reviewable.
Data protection
Controls are designed around data minimization, secure transmission, protected hosting, separation of public verification data from private learner records, defined retention, and secure disposal. Sensitive information should be collected only when necessary.
Secure operations
The readiness program includes change management, secure development review, dependency and vulnerability management, logging, monitoring, backups where applicable, incident response, recovery, and post-incident learning.
Availability and continuity
Critical learning and verification functions are identified for resilience planning. Service providers, recovery objectives, backups, communications, and continuity procedures are to be tested and improved according to risk.
Evidence and independent assurance
Policies alone do not establish compliance. Readiness requires operating evidence, periodic control testing, remediation tracking, scoped management approval, and, when pursued, assessment by qualified independent auditors or accredited certification bodies.
Report a concern
Security concerns may be reported privately to gp2@gp2.biz. Please provide enough detail to reproduce the issue and avoid accessing, altering, or retaining data that is not yours.
