A global logistics organization is establishing vendor risk requirements for a third-party managed database service provider that will store customer personal data. The organization's risk management policy mandates independent third-party attestation confirming that operational security, availability, and confidentiality controls were actively tested and proven effective over a minimum six-month observation window. Which of the following audit attestation reports should the security manager request to meet this requirement?
- SOC 2 Type II reportAnswer
- BSOC 2 Type I report
- CSOC 1 Type II report
- DSOC 3 report
Answer
SOC 2 Type II report
A SOC 2 Type II report is designed to evaluate a service organization's controls based on the AICPA Trust Services Criteria (including Security, Availability, and Confidentiality). The Type II designation specifically confirms that an independent auditor tested both the suitability of control design and its operating effectiveness over a specified testing period (minimum 6 months).
Step-by-Step Solution
Key Concept
SOC Report Types and Attestations
Estimated Time:2m 0s