A enterprise healthcare technology organization is preparing for a mandatory annual compliance review by an independent external auditing firm. The compliance officer must supply an independent attestation document that proves internal data security controls over sensitive electronic protected health information (ePHI) were not only appropriately designed and implemented, but also maintained and operated effectively over a continuous 12-month evaluation window. Which of the following audit reports or attestations fulfills both the time-horizon and operational testing criteria required by the auditors?
- A SOC 2 Type II report assessing security and confidentiality trust services criteriaAnswer
- BA SOC 2 Type I report covering the relevant trust services criteria and system boundaries
- CA SOC 3 attestation report covering security and availability principles
- DAn external penetration testing report with executive attestation of remediation
Answer
A SOC 2 Type II report assessing security and confidentiality trust services criteria is the required attestation because it evaluates both control design suitability and operational effectiveness over a specified testing window (e.g., 12 months).
The option specifying a SOC 2 Type II report is correct because Service Organization Control (SOC) 2 Type II reports evaluate both the design suitability and the operational effectiveness of security controls over an extended testing period (typically 6 to 12 months). This directly satisfies the requirement for proof of continuous control operation across a 12-month window.
Step-by-Step Solution
Key Concept
Distinction between SOC report types (SOC 1 vs SOC 2 vs SOC 3) and report coverage (Type I point-in-time vs Type II operational period effectiveness).
Estimated Time:2m 0s