A security analyst at a financial institution is conducting a vendor risk assessment for a prospective software-as-a-service (SaaS) human resources platform. The vendor provides a SOC 1 Type II report to demonstrate financial reporting integrity. However, the analyst must verify the operational effectiveness of the vendor's data encryption, system availability, and confidentiality controls over the past 12 months. Which attestation deliverable should the analyst request from the vendor?
- SOC 2 Type II reportAnswer
- BSOC 1 Type I report
- CSOC 2 Type I report
- DSOC 3 report
Answer
The analyst should request a SOC 2 Type II report.
A SOC 2 Type II report assesses a service organization's controls based on the AICPA Trust Services Criteria (security, availability, processing integrity, confidentiality, and privacy) and verifies their operational effectiveness over a sustained period of time (typically 6 to 12 months).
Step-by-Step Solution
Key Concept
SOC 2 Type II Attestation Reports