A software-as-a-service (SaaS) provider needs to give prospective clients a high-level summary of its security and compliance posture. The document must be suitable for general public distribution without requiring a Non-Disclosure Agreement (NDA). Which attestation report is specifically designed for this purpose?
- SOC 3 reportCevap
- BSOC 2 Type II report
- CSOC 1 Type I report
- DInternal vulnerability assessment report
Cevap
SOC 3 report
The SOC 3 report is an executive-level attestation covering security, availability, processing integrity, confidentiality, or privacy. It provides a seal or summary that organizations can publicly display or freely distribute to prospective customers without enforcing a Non-Disclosure Agreement.
Adım Adım Çözüm
Anahtar Kavram
SOC 3 Attestation Reports and Public Distribution