Soru

Zorluk: OrtaSecurity Audits, Assessments, and Attestations

A regional hospital network is evaluating a software provider to host patient portal data in a public cloud deployment. The hospital's compliance policy mandates independent verification that the cloud vendor's security, confidentiality, and availability controls operate effectively over a continuous 12-month monitoring period. Which of the following attestation reports should the hospital request from the vendor?

  1. SOC 2 Type II reportCevap
  2. B
    SOC 2 Type I report
  3. C
    SOC 1 Type II report
  4. D
    SOC 3 report

Cevap

The hospital network should request a SOC 2 Type II report.
The SOC 2 Type II report aligns with the Trust Services Criteria (security, availability, confidentiality) and assesses whether controls were operating effectively throughout a specified testing window (such as 12 months).

Adım Adım Çözüm

1
Determine the subject domain of the controls required.
The requirement focuses on security, confidentiality, and availability controls for patient data rather than financial reporting controls.
SOC 2 reports directly evaluate security and privacy under the Trust Services Criteria, whereas SOC 1 reports evaluate internal controls over financial reporting.
2
Evaluate the required time scope of auditor verification.
The hospital requires verification of operational effectiveness over a continuous 12-month period.
Type II reports test and verify control execution over a sustained period, whereas Type I reports assess control design at a single point in time.

Anahtar Kavram

Distinguishing SOC Report Scope and Attestation Types
Bu soruyu puanla