A software-as-a-service (SaaS) provider needs to give prospective clients a high-level summary of its security and compliance posture. The document must be suitable for general public distribution without requiring a Non-Disclosure Agreement (NDA). Which attestation report is specifically designed for this purpose?
- SOC 3 reportAnswer
- BSOC 2 Type II report
- CSOC 1 Type I report
- DInternal vulnerability assessment report
Answer
SOC 3 report
The SOC 3 report is an executive-level attestation covering security, availability, processing integrity, confidentiality, or privacy. It provides a seal or summary that organizations can publicly display or freely distribute to prospective customers without enforcing a Non-Disclosure Agreement.
Step-by-Step Solution
Key Concept
SOC 3 Attestation Reports and Public Distribution