A biomedical research firm is contracting an offshore software development organization to build a proprietary genomic sequencing portal. The research firm's chief information security officer (CISO) must verify that the vendor's security controls protecting data confidentiality, system availability, and processing integrity were actively operating and independently validated throughout the preceding 12-month period. Which of the following audit reports or attestations should the CISO require from the vendor to satisfy these requirements?
- A SOC 2 Type II reportAnswer
- BA SOC 2 Type I report
- CA SOC 1 Type II report
- DA SOC 3 report
Answer
A SOC 2 Type II report provides an independent evaluation of the operational effectiveness of security, availability, and confidentiality controls over a specified testing window (such as 12 months).
The requirement specifies verifying the operational effectiveness of security, confidentiality, and integrity controls over an extended continuous timeframe (12 months). A Service Organization Control (SOC) 2 Type II report evaluates vendor controls mapped to the Trust Services Criteria and includes testing details of how effectively those controls operated throughout a designated period.
Step-by-Step Solution
Key Concept
SOC 2 Type II Attestation Reports
Estimated Time:2m 0s