This series examines the common criteria used to evaluate the Security category in a SOC 2 Type 2 examination. A Type 2 examination assesses the suitability of control design and operating effectiveness over a specified period. Each article will explain an individual criterion through practical examples of controls and supporting evidence for organizations with 5, 100, and 1,000 people. The examples will illustrate how organizations can address the same objective through approaches appropriate to their risks, structure, and resources. Links will be added below as articles are published.