Question

Difficulty: MediumSecurity Audits, Assessments, and Attestations

A healthcare technology company hosts its multi-tenant application on a cloud service provider's infrastructure. To satisfy client enterprise compliance requirements, the company must provide an independent auditor's report verifying that its security controls protecting customer data were appropriately designed and operated effectively throughout the preceding 12-month period. Which of the following compliance deliverables best satisfies this requirement?

  1. SOC 2 Type II reportAnswer
  2. B
    SOC 2 Type I report
  3. C
    SOC 1 Type II report
  4. D
    Vulnerability assessment report

Answer

SOC 2 Type II report
A SOC 2 Type II report provides independent attestation that an organization's security controls are properly designed and operated effectively over a defined evaluation timeframe (such as 6 to 12 months). This fulfills both the scope (security/confidentiality) and operational duration requirements.

Step-by-Step Solution

1
Determine the subject area required for the compliance report.
The requirement calls for evaluating data protection and security controls, pointing toward a SOC 2 audit focusing on Trust Services Criteria (Security, Confidentiality) rather than financial reporting controls evaluated under SOC 1.
SOC 2 reports specifically cover security, availability, processing integrity, confidentiality, and privacy controls.
2
Evaluate the timeframe requirement specified in the scenario.
The client requires proof of operational effectiveness over a continuous 12-month period.
Type II reports test and verify operational effectiveness across a defined monitoring period (e.g., 6 to 12 months), whereas Type I reports only verify control design at a single point in time.

Key Concept

SOC 2 Type II Attestation Reports
Estimated Time:1m 15s
Rate this question