During a vendor risk assessment, an enterprise security auditor evaluates an offshore development provider managing sensitive software repositories. The vendor provides a SOC 2 Type I report dated six months prior and an internal vulnerability scan report. The auditor concludes these documents do not verify that security controls operated effectively over time or that technical safeguards resist exploitation. Which of the following independent attestations or assessments should the auditor require from the vendor to address these deficiencies? (Select TWO.)
- Obtain a SOC 2 Type II report covering an operational evaluation period of at least six months.Answer
- Request an independent third-party penetration testing assessment validating technical security control resilience.Answer
- CAccept a SOC 3 attestation report to analyze the auditor's detailed test procedures and individual control results.
- DRequest a SOC 1 Type I report to verify the operational effectiveness of IT security safeguards over the preceding year.
Answer
The auditor must require a SOC 2 Type II report covering an operational testing period of at least six months and an independent third-party penetration testing assessment.
To verify that security controls operate effectively over time, an organization requires a SOC 2 Type II report, which evaluates control execution across a sustained testing window (typically 6–12 months). Additionally, to validate technical defense mechanics beyond automated internal scans, an independent third-party penetration test is necessary to simulate real-world attacks and confirm safeguard resilience.
Step-by-Step Solution
Key Concept
Distinguishing SOC report types (SOC 1 vs SOC 2 vs SOC 3 and Type I vs Type II) and independent technical assessments in vendor risk management.