Question

Difficulty: HardSecurity Audits, Assessments, and Attestations

A biomedical research firm is contracting an offshore software development organization to build a proprietary genomic sequencing portal. The research firm's chief information security officer (CISO) must verify that the vendor's security controls protecting data confidentiality, system availability, and processing integrity were actively operating and independently validated throughout the preceding 12-month period. Which of the following audit reports or attestations should the CISO require from the vendor to satisfy these requirements?

  1. A SOC 2 Type II reportAnswer
  2. B
    A SOC 2 Type I report
  3. C
    A SOC 1 Type II report
  4. D
    A SOC 3 report

Answer

A SOC 2 Type II report provides an independent evaluation of the operational effectiveness of security, availability, and confidentiality controls over a specified testing window (such as 12 months).
The requirement specifies verifying the operational effectiveness of security, confidentiality, and integrity controls over an extended continuous timeframe (12 months). A Service Organization Control (SOC) 2 Type II report evaluates vendor controls mapped to the Trust Services Criteria and includes testing details of how effectively those controls operated throughout a designated period.

Step-by-Step Solution

1
Analyze the scenario requirements
Identified requirements for evaluating IT security controls (confidentiality, availability, processing integrity) tested continuously over a 12-month duration.
Determining the scope (IT security vs financial) and time frame (historical period vs point-in-time) dictates the appropriate attestation type.
2
Distinguish between SOC report categories
Eliminated SOC 1 options because SOC 1 focuses specifically on financial reporting controls (ICFR), whereas SOC 2 covers Trust Services Criteria.
The organization requires validation of data confidentiality and portal integrity, which aligns with SOC 2 Trust Services Criteria.
3
Differentiate Type I, Type II, and SOC 3 reporting structures
Selected Type II over Type I and SOC 3.
Type I reports only verify control design at a single point in time. SOC 3 reports omit detailed test results needed for risk auditing. Only a SOC 2 Type II report satisfies both the Trust Services scope and the multi-month operational effectiveness evaluation.

Key Concept

SOC 2 Type II Attestation Reports
Estimated Time:2m 0s
Rate this question