Question

Difficulty: MediumThird-Party Risk Management and Supply Chain Oversight

An enterprise is preparing to onboard a third-party Software-as-a-Service (SaaS) provider to process customer payment data. To comply with regulatory requirements, the security team must verify not only that the vendor has implemented required security controls, but also that these controls operated effectively over a continuous six-month period. Which of the following vendor artifacts should the security team request to validate this operational effectiveness?

  1. SOC 2 Type II reportAnswer
  2. B
    SOC 2 Type I report
  3. C
    Service Level Agreement (SLA)
  4. D
    Memorandum of Understanding (MOU)

Answer

The organization should request a SOC 2 Type II report to verify the operational effectiveness of vendor security controls over a continuous timeframe.
A SOC 2 Type II report provides independent assurance regarding both the design suitability and operational effectiveness of a vendor's security controls across a designated period (such as 6 to 12 months). This matches the enterprise requirement for continuous operational verification.

Step-by-Step Solution

1
Identify the core assessment requirement in the scenario.
The requirement demands proof that security controls operated effectively over an extended period (six months), rather than just being configured at a single instant.
Third-party risk management frameworks distinguish between design suitability at a point in time and continuous operational effectiveness.
2
Evaluate third-party audit reports against the specific requirement.
A SOC 2 Type II report specifically tests and reports on control performance across a historical audit window (6–12 months).
Type II audits involve independent testing over time to ensure controls remain active and effective during standard business operations.

Key Concept

SOC Report Types in Third-Party Risk Assessment
Rate this question