Soru

Zorluk: KolaySecurity Audits, Assessments, and Attestations

A software-as-a-service (SaaS) provider needs to give prospective clients a high-level summary of its security and compliance posture. The document must be suitable for general public distribution without requiring a Non-Disclosure Agreement (NDA). Which attestation report is specifically designed for this purpose?

  1. SOC 3 reportCevap
  2. B
    SOC 2 Type II report
  3. C
    SOC 1 Type I report
  4. D
    Internal vulnerability assessment report

Cevap

SOC 3 report
The SOC 3 report is an executive-level attestation covering security, availability, processing integrity, confidentiality, or privacy. It provides a seal or summary that organizations can publicly display or freely distribute to prospective customers without enforcing a Non-Disclosure Agreement.

Adım Adım Çözüm

1
Identify the primary requirement in the scenario.
The document must serve as a high-level summary suitable for general public release without an NDA.
Prospective clients need general proof of security controls, but internal detailed operational logs should remain confidential.
2
Evaluate Service Organization Control (SOC) report types against distribution restrictions.
SOC 1 and SOC 2 reports are restricted-use documents intended for management, current clients, and auditors under confidentiality. SOC 3 reports are designed specifically for general public distribution.
SOC 3 reports summarize the SOC 2 evaluation using the Trust Services Criteria without releasing sensitive technical system architecture details.

Anahtar Kavram

SOC 3 Attestation Reports and Public Distribution
Bu soruyu puanla