An enterprise software company is evaluating an independent third-party attestation for a cloud hosting vendor that processes non-financial sensitive customer data. The enterprise compliance manager mandates that the assessment must verify the operational effectiveness of security, confidentiality, and availability controls over a continuous six-month observation window, while excluding internal controls over financial reporting (ICFR). Which TWO of the following statements correctly describe the attestation report types or evaluation criteria that satisfy these requirements? (Select TWO.)
- A SOC 2 Type II report must be specified because it evaluates the operational effectiveness of controls over a designated testing period.Cevap
- The audit scope must be aligned with the Trust Services Criteria rather than Internal Control over Financial Reporting (ICFR).Cevap
- CA SOC 1 Type II report should be requested because SOC 1 is the standard attestation framework for non-financial operational security controls over an extended period.
- DA SOC 2 Type I report should be requested because Type I reports provide empirical audit evidence of control performance across a minimum six-month timeframe.
Cevap
The organization must request a SOC 2 Type II report aligned with the Trust Services Criteria. A SOC 2 Type II report assesses operational control effectiveness over a continuous observation period, while Trust Services Criteria evaluate non-financial security, confidentiality, and availability principles.
Selecting a SOC 2 Type II report fulfills the requirement because Type II reports evaluate operational control effectiveness over a designated time period (such as six months). Furthermore, aligning the evaluation with the Trust Services Criteria ensures focus on security, availability, and confidentiality rather than financial reporting controls.
Adım Adım Çözüm
Anahtar Kavram
Distinction between SOC report types (SOC 1 vs. SOC 2) and report options (Type I vs. Type II)