A cloud service provider needs to publish a high-level attestation document on its public website to demonstrate compliance with security best practices to prospective clients, without disclosing detailed control design or confidential testing procedures. Which report fulfills this requirement?
- SOC 3 reportAnswer
- BSOC 2 Type II report
- CSOC 1 Type II report
- DSOC 2 Type I report
Answer
A SOC 3 report provides a general-use, publicly shareable summary of security attestations without exposing confidential system design details.
A SOC 3 report is specifically created for general public distribution. It provides an executive summary of an organization's compliance with Trust Services Criteria without revealing sensitive details regarding system architecture or specific control testing results.
Step-by-Step Solution
Key Concept
SOC 3 Public Attestation Reports