An enterprise is preparing to onboard a third-party Software-as-a-Service (SaaS) provider to process customer payment data. To comply with regulatory requirements, the security team must verify not only that the vendor has implemented required security controls, but also that these controls operated effectively over a continuous six-month period. Which of the following vendor artifacts should the security team request to validate this operational effectiveness?
- SOC 2 Type II reportAnswer
- BSOC 2 Type I report
- CService Level Agreement (SLA)
- DMemorandum of Understanding (MOU)
Answer
The organization should request a SOC 2 Type II report to verify the operational effectiveness of vendor security controls over a continuous timeframe.
A SOC 2 Type II report provides independent assurance regarding both the design suitability and operational effectiveness of a vendor's security controls across a designated period (such as 6 to 12 months). This matches the enterprise requirement for continuous operational verification.
Step-by-Step Solution
Key Concept
SOC Report Types in Third-Party Risk Assessment