A chief information security officer (CISO) is preparing an online retail company for an annual regulatory oversight evaluation. To satisfy compliance mandates, the CISO must obtain an independent auditor's report that evaluates whether security controls were properly designed and operated effectively throughout a continuous six-month observation period, specifically addressing security, availability, and confidentiality trust services criteria. Which of the following independent attestations best fulfills this requirement?
- Service Organization Control (SOC) 2 Type II reportAnswer
- BService Organization Control (SOC) 2 Type I report
- CService Organization Control (SOC) 1 Type II report
- DNetwork Vulnerability Assessment report
Answer
Service Organization Control (SOC) 2 Type II report
The Service Organization Control (SOC) 2 Type II report is specifically designed to provide independent assurance regarding controls relevant to security, availability, and confidentiality. Furthermore, a Type II report tests the operating effectiveness of these controls over a designated testing period (such as six months or a year), matching all specified organizational requirements.
Step-by-Step Solution
Key Concept
SOC 2 Type II Attestation vs SOC 1 / Type I Reports