Reviewing Vendor SOC Complementary User Entity Controls (CUECs)
Many of us are likely familiar with the information security risk that comes from working with vendors. When vendors have access to your organization or customers’ data, it’s critical to ensure that they have controls in place to protect it. A vendor’s SOC report will provide details on these controls and will also describe what your organization needs to do for the controls to be effective. SOC complementary user entity controls (CUECs) are essentially used to help achieve the vendor’s control objectives.