An enterprise organization is evaluating a cloud service provider during initial procurement screening. The organization requires verification that the provider's security controls operate effectively over a continuous period. However, the provider refuses to share confidential architectural blueprints or detailed technical test procedures prior to contract execution. Which of the following audit reports should the provider furnish to satisfy this request?
- SOC 3 reportAnswer
- BSOC 2 Type I report
- CSOC 1 Type II report
- DInternal vulnerability assessment report
Answer
The correct report is a SOC 3 report, as it provides a public, high-level third-party attestation of security control operational effectiveness over a period of time without disclosing sensitive operational details.
A SOC 3 report is an executive-level, general-use document that attests to the security controls of a service organization over a specified period. It is based on the same audit rigor as a SOC 2 Type II evaluation but omits sensitive architectural diagrams, system descriptions, and detailed auditor testing results, making it ideal for public sharing during early vendor evaluations.
Step-by-Step Solution
Key Concept
SOC Attestation Report Types and Scopes
Estimated Time:1m 0s