Question

Difficulty: MediumSecurity Audits, Assessments, and Attestations

A global logistics organization is evaluating a cloud-based warehouse management platform to manage critical supply chain operations. The security team requires verification that the vendor's security controls addressing system availability and data confidentiality are not only properly designed, but have also been evaluated for operational effectiveness over a six-month monitoring window. Which of the following audit reports or attestations should the organization request from the vendor?

  1. A SOC 2 Type II reportAnswer
  2. B
    A SOC 2 Type I report
  3. C
    A SOC 1 Type II report
  4. D
    A SOC 3 report

Answer

A SOC 2 Type II report
A SOC 2 Type II report specifically evaluates the design and operating effectiveness of security controls categorized under the Trust Services Criteria (such as availability, confidentiality, and security) over a defined period (such as six months).

Step-by-Step Solution

1
Identify the criteria domain required by the organization.
The requirement specifies system availability and data confidentiality, which fall under the Trust Services Criteria (SOC 2), not financial reporting controls (SOC 1).
SOC 1 reports address financial controls, whereas SOC 2 addresses operational trust criteria such as security, availability, and confidentiality.
2
Determine the time scope requirement for the audit.
The organization specifies evaluating operational effectiveness over a six-month period, which necessitates a Type II report.
Type I reports evaluate design at a specific point in time, whereas Type II reports test the operating effectiveness of controls over a designated testing period (typically 6 to 12 months).

Key Concept

SOC Report Types and Attestation Scopes
Rate this question