Question

Difficulty: MediumSecurity Audits, Assessments, and Attestations

An enterprise organization is evaluating a cloud service provider during initial procurement screening. The organization requires verification that the provider's security controls operate effectively over a continuous period. However, the provider refuses to share confidential architectural blueprints or detailed technical test procedures prior to contract execution. Which of the following audit reports should the provider furnish to satisfy this request?

  1. SOC 3 reportAnswer
  2. B
    SOC 2 Type I report
  3. C
    SOC 1 Type II report
  4. D
    Internal vulnerability assessment report

Answer

The correct report is a SOC 3 report, as it provides a public, high-level third-party attestation of security control operational effectiveness over a period of time without disclosing sensitive operational details.
A SOC 3 report is an executive-level, general-use document that attests to the security controls of a service organization over a specified period. It is based on the same audit rigor as a SOC 2 Type II evaluation but omits sensitive architectural diagrams, system descriptions, and detailed auditor testing results, making it ideal for public sharing during early vendor evaluations.

Step-by-Step Solution

1
Identify the audit criteria needed.
The requirement focuses on security controls rather than internal controls over financial reporting.
This rules out SOC 1 reports.
2
Determine the required audit evaluation timeframe.
The scenario requires proof of continuous operational effectiveness over a period of time.
This rules out Type I reports, which evaluate design at a single point in time.
3
Evaluate confidentiality and distribution constraints.
The report must be suitable for general/public distribution without releasing confidential test procedures.
SOC 2 Type II reports contain detailed testing procedures restricted to existing customers/auditors, whereas SOC 3 reports are designed for public distribution.

Key Concept

SOC Attestation Report Types and Scopes
Estimated Time:1m 0s
Rate this question