ISSA Sacramento Valley Chapter Meeting – 11/20/2026 – Audit Strategy
Speaker: Nelly Spieler, Partner, Frank, Rimerman + Co.
Topic: “Combined SOC 2 & ISO 27001 Audits”
Synopsis: Practical strategies to reduce audit fatigue, improve efficiency, and align two of the industry’s most common assurance frameworks. This presentation addresses the critical need for a unified cybersecurity strategy by integrating SOC 2 and ISO 27001. Managing them separately causes inefficiency and heightens cybersecurity risk. The session shows how this integration delivers a stronger, more defensible security posture. Key Takeaways:
* Combine the granular security rigor of SOC 2 with the systematic, continuous improvement of ISO 27001 for true resilience against threats.
* Learn practical steps for control mapping and unified risk management to eliminate security gaps and policy redundancies.
* Master the shared audit approach (using dual-proficient auditors and strategic evidence timing) to drastically reduce audit fatigue and resource strain on security teams.
* Transform compliance from a burden into a cybersecurity asset that meets both rigorous U.S. and global standards.
Speaker Bio: Nelly Spieler has nearly 20 years of auditing, consulting and management experience working with companies worldwide. She currently leads the firm’s Technology Assurance and Risk Management practice which includes all service areas involving Cybersecurity, Privacy, System and Organization Controls (SOC). The team is accredited by ANAB to perform ISO/IEC 27001, 27701, 27017, 27018 and ISO 42001 audits, and frequently delivers integrated audits—either conducting both the ISO and SOC 2 engagements in-house or leading the ISO portion while another firm that is not ISO-accredited performs the SOC 2. Nelly is also an ISO Lead Auditor. Nelly leverages her expertise in cloud security, information systems and controls into an array of topics in the Governance, Risk and Compliance field. Nelly works with a range of clients, including privately held, pre-IPO, and public companies. Nelly’s experience includes serving as both an internal and external auditor for her clients. Prior to working in the professional services field, Nelly worked in both high tech start-ups and large corporations within IT and Engineering departments.
Meeting Details: This will be a hybrid meeting (both in-person and on-line). You may attend remotely via Zoom (see the meeting ID below) or attend in person at Capsity, 3808 Broadway, Sacramento CA. Lunch will be provided to in-person attendees.
Please register for the meeting below.
You don’t have to be a member of ISSA to attend our meetings (but we encourage you to join us!). Please share information about this meeting with your friends and colleagues who have an interest in information security.
Zoom link:
https://us06web.zoom.us/j/84186623031?pwd=EtHkuqg0it61fhLsaZIpC8aCHldHG9.1
Meeting ID: 841 8662 3031
Passcode: 668146
