Question

Difficulty: MediumSecurity Audits, Assessments, and Attestations

A enterprise compliance team is conducting a vendor risk evaluation for a critical cloud-hosted database service. The vendor presents a security document confirming that their security control design was evaluated and validated as of a specific date last month, but it contains no testing results regarding control performance over time. The enterprise requires formal verification that controls operated effectively over a minimum six-month observation window. Which assessment deliverable should the compliance team request from the vendor?

  1. A SOC 2 Type II reportAnswer
  2. B
    A SOC 2 Type I report
  3. C
    A SOC 3 report
  4. D
    An external vulnerability assessment report

Answer

The enterprise compliance team should request a SOC 2 Type II report.
A SOC 2 Type II report is specifically designed to audit both the design and operational effectiveness of security controls across an extended period, typically between 6 and 12 months. This satisfies the requirement to prove controls operated consistently over time.

Step-by-Step Solution

1
Analyze the compliance requirement
The organization requires proof of operational effectiveness over a historical period of at least six months.
Point-in-time assessments do not prove that security controls functioned continuously without failure over time.
2
Evaluate the difference between SOC report types
SOC 2 Type I covers control design at a single point in time, while SOC 2 Type II assesses control design and tests operational effectiveness over a defined time window.
Auditing operational effectiveness requires auditors to sample evidence across a declared testing timeframe.
3
Select the appropriate attestation deliverable
The SOC 2 Type II report fulfills the enterprise's vendor risk requirement.
It provides independent third-party verification of control operation throughout the required multi-month period.

Key Concept

Distinction between SOC 2 Type I (point-in-time design) and SOC 2 Type II (historical period operational effectiveness) security attestations.
Rate this question