A global logistics organization is evaluating a cloud-based warehouse management platform to manage critical supply chain operations. The security team requires verification that the vendor's security controls addressing system availability and data confidentiality are not only properly designed, but have also been evaluated for operational effectiveness over a six-month monitoring window. Which of the following audit reports or attestations should the organization request from the vendor?
- A SOC 2 Type II reportAnswer
- BA SOC 2 Type I report
- CA SOC 1 Type II report
- DA SOC 3 report
Answer
A SOC 2 Type II report
A SOC 2 Type II report specifically evaluates the design and operating effectiveness of security controls categorized under the Trust Services Criteria (such as availability, confidentiality, and security) over a defined period (such as six months).
Step-by-Step Solution
Key Concept
SOC Report Types and Attestation Scopes