Soru

Zorluk: ZorSecurity Audits, Assessments, and Attestations

A global logistics organization is establishing vendor risk requirements for a third-party managed database service provider that will store customer personal data. The organization's risk management policy mandates independent third-party attestation confirming that operational security, availability, and confidentiality controls were actively tested and proven effective over a minimum six-month observation window. Which of the following audit attestation reports should the security manager request to meet this requirement?

  1. SOC 2 Type II reportCevap
  2. B
    SOC 2 Type I report
  3. C
    SOC 1 Type II report
  4. D
    SOC 3 report

Cevap

SOC 2 Type II report
A SOC 2 Type II report is designed to evaluate a service organization's controls based on the AICPA Trust Services Criteria (including Security, Availability, and Confidentiality). The Type II designation specifically confirms that an independent auditor tested both the suitability of control design and its operating effectiveness over a specified testing period (minimum 6 months).

Adım Adım Çözüm

1
Analyze the scope requirement in the scenario.
The scenario requires assessing security, availability, and confidentiality controls for data protection rather than financial reporting controls.
This establishes that a SOC 2 report (Trust Services Criteria) is required instead of a SOC 1 report (Financial Reporting).
2
Analyze the timeframe and assessment depth requirement.
The requirement specifies testing operational effectiveness over a six-month period rather than a single point in time.
Type II reports assess control execution and effectiveness over a duration of time (e.g., 6–12 months), whereas Type I reports only verify control design as of a specific date.
3
Select the appropriate attestation report based on audience and detail level.
A SOC 2 Type II report provides the necessary detailed technical evidence of control testing over time for vendor risk assessment.
A SOC 3 report lacks the detailed evidence required for institutional vendor evaluation.

Anahtar Kavram

SOC Report Types and Attestations
Tahmini Süre:2m 0s
Bu soruyu puanla