A healthcare enterprise is reviewing security documentation from a third-party Cloud Software as a Service (SaaS) vendor that stores Protected Health Information (PHI). The enterprise's compliance framework requires independent third-party verification that the vendor's Security, Confidentiality, and Availability controls were appropriately designed and operated effectively throughout a continuous nine-month observation period. Which of the following independent attestations best satisfies this requirement?
- A SOC 2 Type II reportAnswer
- BA SOC 2 Type I report
- CA SOC 1 Type II report
- DA SOC 3 report
Answer
A SOC 2 Type II report best satisfies the requirement because it evaluates both control design and operational effectiveness over a continuous observation period for Trust Services Criteria.
A SOC 2 Type II report specifically measures the suitability of design and the operational effectiveness of controls related to the Trust Services Criteria (Security, Availability, Processing Integrity, Confidentiality, and Privacy) over a specified period of time. Because the enterprise requires proof of effective operation over a continuous nine-month window, a SOC 2 Type II report is the exact matching attestation standard.
Step-by-Step Solution
Key Concept
SOC 2 Type II vs. Type I and SOC 1 Attestation Scope
Estimated Time:1m 30s