Question

Difficulty: HardSecurity Audits, Assessments, and Attestations

A global logistics organization is establishing vendor risk requirements for a third-party managed database service provider that will store customer personal data. The organization's risk management policy mandates independent third-party attestation confirming that operational security, availability, and confidentiality controls were actively tested and proven effective over a minimum six-month observation window. Which of the following audit attestation reports should the security manager request to meet this requirement?

  1. SOC 2 Type II reportAnswer
  2. B
    SOC 2 Type I report
  3. C
    SOC 1 Type II report
  4. D
    SOC 3 report

Answer

SOC 2 Type II report
A SOC 2 Type II report is designed to evaluate a service organization's controls based on the AICPA Trust Services Criteria (including Security, Availability, and Confidentiality). The Type II designation specifically confirms that an independent auditor tested both the suitability of control design and its operating effectiveness over a specified testing period (minimum 6 months).

Step-by-Step Solution

1
Analyze the scope requirement in the scenario.
The scenario requires assessing security, availability, and confidentiality controls for data protection rather than financial reporting controls.
This establishes that a SOC 2 report (Trust Services Criteria) is required instead of a SOC 1 report (Financial Reporting).
2
Analyze the timeframe and assessment depth requirement.
The requirement specifies testing operational effectiveness over a six-month period rather than a single point in time.
Type II reports assess control execution and effectiveness over a duration of time (e.g., 6–12 months), whereas Type I reports only verify control design as of a specific date.
3
Select the appropriate attestation report based on audience and detail level.
A SOC 2 Type II report provides the necessary detailed technical evidence of control testing over time for vendor risk assessment.
A SOC 3 report lacks the detailed evidence required for institutional vendor evaluation.

Key Concept

SOC Report Types and Attestations
Estimated Time:2m 0s
Rate this question